Position SummaryOneZero Solutions is seeking a Journeyman-level Cyber Security Engineer - Penetration Tester to support the U.S. Coast Guard in Alexandria, VA. The selected candidate will assess the cyber security posture of Coast Guard operational networks through adversary emulation, conducting red team operations, penetration tests, and phishing assessments. This role also performs cyber threat emulation during scripted exercises to train DoD Cyber Protection Teams and delivers clear reports and briefs that turn technical findings into actionable recommendations.
Position Title: Cyber Security Engineer - Penetration Tester (Journeyman)
Location: Hybrid Alexandria, VA
Clearance: Top Secret
Adversary Simulation- Deploy, configure, and operate Command and Control (C2) frameworks such as Cobalt Strike, Havoc, Mythic, and Sliver.
- Apply tactics, techniques, and procedures (TTPs) for initial access, lateral movement, privilege escalation, persistence, and data exfiltration.
- Leverage proprietary and open-source offensive security tool sets effectively to achieve engagement objectives.
- Execute phishing assessments.
Infrastructure- Monitor, manage, and maintain cloud and on-premise infrastructure used during assessments.
- Use Git repositories to maintain operational tools and scripts.
Penetration Testing- Conduct internal and external penetration testing.
- Perform network mapping and enumeration.
- Assess web and mobile applications.
- Perform database scans.
- Assess Active Directory attack paths using tools such as BloodHound.
Security Assessments- Assess the cyber security posture of Coast Guard operational networks through adversary emulation.
- Develop reports and briefs detailing findings and recommendations for all completed assessments.
- Perform cyber threat emulation during scripted exercises to train DoD Cyber Protection Teams.
Required Qualifications- 2 to 3 years of relevant experience.
- Active Top Secret security clearance with SCI eligibility.
- Hands-on experience with computers and network security.
- Experience conducting phishing campaigns or social engineering.
- Hands-on experience with red team tasks and penetration testing.
- Familiarity with malware development and EDR/AV bypass strategies.
- Experience with PowerShell, C, C++, or Python.
- Hands-on experience using C2 frameworks such as Cobalt Strike, Sliver, Havoc, or similar.
Preferred Qualifications- Experience supporting Red Team or offensive cybersecurity operations.
- Experience with web application, network, wireless, cloud, or infrastructure penetration testing.
- Familiarity with tools such as Nmap, Burp Suite, Metasploit, BloodHound, Wireshark, or similar security testing tools.
- Knowledge of common attack frameworks and methodologies, including MITRE ATT&CK.
- Experience developing penetration testing reports and presenting technical findings.
- Active industry-recognized cybersecurity certifications such as OSCP, CEH, PenTest+, GPEN, or comparable certifications.
CertificationsCandidates must hold a DoD 8570/8140-compliant Information Assurance Technical (IAT) Level II or Level III certification, along with an offensive security certification.
Offensive Security Certification (any one of the following)- GIAC Penetration Tester (GPEN)
- Red Team Apprentice Course (RTAC)
- Or equivalent
IAT Level II (any one of the following, or one of the IAT Level III certifications noted below)- CompTIA Security+ CE
- CompTIA CySA+
- CCNA Security
- GICSP
- GSEC
- SSCP
IAT Level III (any one of the following)- CompTIA CASP+ CE (SecurityX)
- CISSP (or Associate)
- CISA
- CCNP Security
- GCED
- GCIH
EducationBachelor's degree (BA/BS) or equivalent years of relevant experience.