Red Team Penetration Tester
SimVentions · King George, VA · 3 days ago
Information Technology$110k–$150k/yrFull-time
SimVentions, consistently voted one of Virginia's Best Places to Work, is seeking an experienced Red Team Penetration Tester to conduct offensive cybersecurity operations for U.S. Government and DoD systems. Collaborate with Blue Team and Cybersecurity professionals to enhance overall cyber posture.
At minimum, an ACTIVE Secret Clearance is required; an ACTIVE Top Secret Clearance with SCI Eligibility is preferred. U.S. Citizenship is required to obtain a clearance.
Requirements
- Five (5) years' experience in software engineering applied to program development; modeling and simulation applied to DoD or Information Technology systems.
- Linux (firm grasp with demonstrated knowledge)
- Windows (foundational knowledge with good understanding of enterprise networks)
- Strong working knowledge of common penetration testing (PENTEST) tools:
- Kali
- Metasploit
- NMAP
- Cobalt Strike
- Documented experience in at least one of the following:
- Penetration Testing (PENTEST)
- Red Team Operations
- Tool/Software Development (exploits/malware, C2, reverse engineering, bug bounties)
- Programming/scripting languages: Python, C, C#, C++, Go, Perl, PowerShell
- Web development/web application development/web penetration testing
- Experience with:
- NSX, vCenter, vRealize Suite, Horizon View (VDI)
- PAN-OS
- FirePower, Nexus, IOS, ASA
- ONTAP, SnapMirror
- Active Directory, SSO, MFA, Azure application integration, Identity Federation
- Automation using PowerShell, PowerAutomate, Logic Apps, Graph API
- Palo Alto, Cisco, VMWare, NetApp, and Microsoft products
- Entra ID (Azure AD), including:
- Microsoft Entra ID and Microsoft 365 in a hybrid environment
- Extending or integrating on-premises AD with Entra ID
- Managing identity and access in Microsoft Entra ID
- Red Team operations in an MDE environment
- AWS, Cloud Audit, Serverless, and Microservice Architecture
- AWS services (EC2, S3, KMS, RDS) and security best practices
- Web Services penetration testing (RESTful and SOAP)
- Web Authentication protocols (e.g., OAuth2, SAML, LDAP)
- PHP, ASP, SQL databases, Java, HTML, NoSQL
- Minimum certification in one of the following:
- Security+
- CCNA Security
- CySA+
- GICSP
- SSCP
- Minimum certification as a penetration tester, possessing one of the following:
- Offensive Security Certs:
- Offensive Security Certified Professional (OSCP)
- Offensive Security Certified Expert (OSCE)
- Offensive Security Exploitation Expert (OSEE)
- Offensive Security Wireless Professional (OSWP)
- SANS Certs:
- SEC560 - Network Penetration Testing and Ethical Hacking (GPEN Certification)
- SEC542 - Web App Penetration Testing and Ethical Hacking (GWAPT Certification)
- SEC660 - Advanced Penetration Testing, Exploit Writing, and Ethical Hacking (GXPN Certification)
- SEC642 - Advanced Web App Penetration Testing and Ethical Hacking
- SEC564 - Red Team Operations and Threat Emulation
- OSD Sponsored Cyber Operation Academy Course (COAC) graduates
- Capture the Flag (CTF) participation (DEFCON, Over-The-Wire (OTW), Hack the Box, USS Secure CTFs)
- Security research resulting in a Common Vulnerabilities and Exposures (CVE)
- Offensive Security Certs:
Responsibilities
- Debug and reverse engineer software.
- Analyze Windows Events and Linux syslog's, boot logs, and dmesg logs.
- Program and debug Web 2.0, Java, Perl, Ada, C++, Tool Command Language (tcl/tk) scripts, and graphical user interfaces (GUIs) using Microsoft Visual Tel and Rational ClearCase for software configuration management.
- Recommend software modifications to systems to mitigate known vulnerabilities.
- Operate and administrate computer systems running HP-UX, UNIX, Solaris, Linux, and Microsoft Windows.
- Identify security flaws in compiled and human-readable source code.
- Understand code utilizing real-time VxWorks and Lynx OS operating systems, Common Object Resource Broker Architecture (CORBA), firewalls, and networking protocols.
- Understand how to implement NSA-approved encryption technologies and devices.
- Apply DISA Security Technical Implementation Guides (STIGs).
- Apply virtual hosting and server technology in system architectures.
- Understand and apply the concept of deceptive technology such as honeypots in system architectures.
- Participate in code reviews.
- Perform static source code analysis.
- Author recommendations for improving software and code design.
- Contribute to a System Security Administrator and Operators Manual (SSAOM).
Qualifications
High School Diploma or GED equivalent.
Pay
The projected annual compensation range for this position is $110,000–$150,000 (USD).
Benefits
- Medical, dental, vision, and prescription drug coverage
- Employee Stock Ownership Plan (ESOP)
- Competitive 401(k) programs
- Retirement and financial counselors
- Health Savings and Health Reimbursement Accounts
- Flexible Spending Accounts
- Life insurance, short- and long-term disability
- Continuing Education Assistance
- Paid Time Off, Paid Holidays, Paid Leave (e.g., Maternity, Paternity, Jury Duty, Bereavement, Military)
- Third-Party Employee Assistance Program offering emotional and lifestyle well-being services, including free counseling
- Supplemental Benefit Program
Why Work for SimVentions?
- Support Our Warfighters: Provide relevant, game-changing solutions to U.S. military personnel.
- Drive Customer Success: Deliver innovative products and solutions that go beyond expectations.
- Get Involved in Giving Back: Participate in diverse service opportunities throughout the year.
- Build Innovative Technology: Work on cutting-edge projects with direct impact on customer success.
- Work with Brilliant People: Collaborate with experienced, creative, and passionate individuals.
- Create Meaningful Solutions: Address challenging and impactful requirements as a trusted partner.
Additional perks include:
- Employee ownership opportunities
- Family-focused work environment
- Business casual dress code
- Excellent facilities, tools, and training opportunities
- Open communication and a collaborative culture
- Corporate fellowship opportunities (sports teams, interest groups)
- Employee appreciation events (Holiday Events, Company Picnic, Imagineering Day, etc.)
- FredNats Baseball team tickets from a private suite
- Frequent food availability in the workplace