Red Team Penetration Tester IV
We are seeking a highly skilled and motivated Red Team Penetration Tester to join a cybersecurity team focused on advanced offensive security testing. In this role, you will conduct sophisticated penetration tests and red team engagements that simulate real-world threats to uncover security weaknesses across systems and environments.
About the role
You will emulate advanced persistent threat behaviors, develop and use industry-standard tooling, and deliver clear findings and remediation recommendations in partnership with defensive teams. This opportunity is well-suited for an experienced operator with deep technical expertise and a strong understanding of threat actor tactics and techniques.
Requirements
- A bachelor’s degree
- One of the following certifications: CSSP Auditor, Offensive Security Certified Professional (OSCP), Offensive Security Certified Expert (OSCE), Offensive Security Exploitation Expert (OSEE), or Offensive Security Wireless Professional (OSWP)
- Active Top Secret/SCI clearance (U.S. citizenship required)
- Ten years of full-time professional experience conducting penetration testing or offensive cyber operations in the following areas:
- Developing and utilizing penetration tools such as Metasploit, NMAP, Kali Linux, Cobalt Strike
- Mimicking threat behavior
- Utilizing various operating systems (Linux, Windows, macOS, etc.)
- Utilizing Active Directory
- Performing exploit development
- Identifying gaps in tools and development techniques
- Performing development with at least two scripting or programming languages (e.g., Python, C++, Java, Rust, Assembly, C#)
Responsibilities
- Plan, execute, and document sophisticated red team engagements and penetration tests
- Emulate advanced persistent threat (APT) behaviors to evaluate enterprise-level defenses
- Develop and utilize tools such as Metasploit, NMAP, Kali Linux, and Cobalt Strike
- Perform exploit development and scripting to mimic threat actor capabilities
- Identify gaps in existing security tools, processes, and defensive technologies
- Work with various operating systems including Linux, Windows, and macOS
- Utilize Active Directory to simulate lateral movement and privilege escalation scenarios
- Apply programming or scripting in at least two languages (e.g., Python, C++, Java, Rust, Assembly, C#)
- Collaborate with Blue Teams and SOC personnel to provide findings and recommendations for remediation
Schedule
On-site at Virginia Beach, VA.
Pay
Pay range: $170,000–$190,000 (annual), based on qualifications and experience, and assumes all role requirements are met.