Penetration Tester Journeyman

OneZero Solutions

$95K — $115K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in penetration testing and red team tasks.
  • Proficient in conducting phishing campaigns and social engineering techniques.
  • Hands-on expertise with network security frameworks and tools.
  • Familiar with malware development and techniques to bypass security measures.
  • Skilled in programming languages such as PowerShell, C, C++, or Python.
  • Experienced in using Command and Control (C2) frameworks like Cobalt Strike and Sliver.
  • Relevant certifications such as IAT II or IAT III, GPEN or RTAC.

Responsibilities

  • Deploy and manage offensive security tools for adversary simulation.
  • Execute vulnerability assessments on internal and external systems.
  • Conduct phishing and social engineering assessments.
  • Monitor cloud and on-premise infrastructure during testing.
  • Assess the security posture of networks through targeted emulation.
  • Develop detailed reports and briefs on security findings and recommendations.
  • Conduct cyber threat emulation exercises for training purposes.

Benefits

  • Hybrid work environment in Alexandria, VA.
  • Focus on advanced cybersecurity techniques and adversary emulation.
  • Opportunity for professional growth through hands-on experience with cutting-edge tools.
  • Engagement in high-impact security assessments for federal clients.
  • Contributions towards strengthening the cyber defense of critical infrastructure.
Full Job Description
Position Title: Penetration Tester Journeyman

Location: Alexandria, VA Hybrid

Clearance: Active Top Secret with SCI eligibility security clearance

Position Summary

Adversary Simulation:
  • Deploy, configure, and operate C2 frameworks such as Cobalt Strike, Havoc, Mythic, and Sliver.
  • Apply TTPs for initial access, lateral movement, privilege escalation, persistence and data exfiltration.
  • Leverage proprietary and open-source offensive security tool sets effectively to achieve engagement objectives.
  • Execute phishing assessments.

Infrastructure:
  • Monitor, manage, and maintain cloud and on-premise infrastructure used during assessments.
  • Understanding the use of Git Repositories for maintaining operational tools and scripts.

Penetration Testing:
  • Internal and external penetration testing.
  • Network mapping and enumeration.
  • Assess web and mobile applications.
  • Perform database scans.
  • Assess Active Directory attack paths using tools such as BloodHound.

Security Assessments:
  • Assessing Coast Guard's cyber security posture of operational networks through adversary emulation.
  • Develop reports and briefs detailing findings and recommendations for all assessments completed.
  • Perform cyber threat emulation during scripted exercises, to train DoD Cyber Protection Teams


Required Qualifications:
  • Relevant Years of Experience: 5+
  • Hands on experience with computers and network security.
  • Experience conducting phishing campaigns or social engineering.
  • Hands on experience with red team tasks and pen testing.
  • Familiarity with malware development and EDR/AV bypass strategies.
  • Experience with PowerShell, C, C++, or Python.
  • Hands on experience utilizing Command and Control (C2) Frameworks such as Cobalt Strike, Sliver, Havoc, etc.

Certifications:
  • IAT II or IAT III
  • GPEN, Red Team Apprentice Course (RTAC), or equivalent

Education: BA/BS or equivalent years of relevant experience

Similar Jobs

More Jobs at OneZero Solutions

More Information Technology Jobs

Find similar Penetration Tester Journeyman jobs: