Red Team Penetration Tester III (TS/SCI REQUIRED)
DirectViz Solutions, LLC · Virginia Beach, VA · 4 days ago
Information TechnologyFull-time
DirectViz Solutions (DVS) is a dynamic and rapidly growing government contractor committed to delivering innovative IT solutions that address the mission-critical needs of our government clients.
About the role
We are seeking a highly skilled and motivated Red Team Penetration Tester III to join our cybersecurity team. This individual will be responsible for conducting advanced penetration tests, simulating real-world cyber threats, and identifying security weaknesses across various systems and environments. The ideal candidate will possess a strong offensive cybersecurity background, expert-level knowledge of threat actor tactics, and deep technical expertise in penetration testing tools and methodologies. ACTIVE TS/SCI IS REQUIRED.
Responsibilities
- Plan, execute, and document sophisticated red team engagements and penetration tests.
- Emulate advanced persistent threat (APT) behaviors to evaluate enterprise-level defenses.
- Develop and utilize tools such as Metasploit, NMAP, Kali Linux, and Cobalt Strike.
- Perform exploit development and scripting to mimic threat actor capabilities.
- Identify gaps in existing security tools, processes, and defensive technologies.
- Work with various operating systems including Linux, Windows, and macOS.
- Utilize Active Directory to simulate lateral movement and privilege escalation scenarios.
- Apply programming or scripting in at least two languages (e.g., Python, C++, Java, Rust, Assembly, C#).
- Collaborate with Blue Teams and SOC personnel to provide findings and recommendations for remediation.
Requirements
- Bachelor's degree in Cybersecurity, Cyber Operations, Cyber Engineering, Information System, Information Technology, Computer, Electrical, or Electronics Engineering, Software Engineering, Computer Science, Mathematics with a concentration in Computer Science, or equivalent to above disciplines, OR an Associate's degree and 10 years of relevant experience.
- Required Certification: CSSP Auditor, Offensive Security Certified Professional (OSCP), Offensive Security Certified Expert (OSCE), Offensive Security Exploitation Expert (OSEE), or Offensive Security Wireless Professional (OSWP) certification.
- Seven (7) years of full-time professional experience conducting penetration testing or offensive Cyber operations in the following areas:
- Developing and utilizing penetration tools such as Metasploit, NMAP, Kali Linux, Cobalt Strike.
- Mimicking threat behavior.
- Utilizing various operating systems (e.g., Linux, Windows, macOS).
- Utilizing Active Directory.
- Performing exploit development.
- Identifying gaps in tools and development techniques.
- Performing development with at least two scripting or programming languages (e.g., Python, C++, Java, Rust, Assembly, C#).
- Active TS/SCI clearance.
Skills
- Maintain focus and awareness throughout scheduled working hours.
- Perform tasks requiring prolonged periods of sitting or standing at a desk, utilizing a computer, mouse, and keyboard.
- Lift and move objects weighing up to 15 pounds as needed.
- Exhibit excellent verbal and written communication skills, with a strong command of the English language.
- Demonstrate the ability to work independently while also collaborating effectively as part of a team.
- Quickly learn and retain routine tasks and processes.
- Possess strong organizational skills, attention to detail, business correspondence proficiency, and self-management capabilities.
- Perform the essential functions of the role satisfactorily; reasonable accommodation will be provided for employees with disabilities upon request.
- Accept and adapt to additional responsibilities or changes to assigned duties as determined by DirectViz Solutions (DVS).
Benefits
- Competitive compensation.
- Comprehensive medical benefits.
- 401(k) match.
- Generous PTO accrual.
- Professional development reimbursement.
- Corporate-funded technology certifications.
- Robust employee recognition and appreciation programs.