Position Title: Penetration Tester Journeyman
Location: Alexandria, VA Hybrid
Clearance: Active Top Secret with SCI eligibility security clearance
Position SummaryAdversary Simulation:
- Deploy, configure, and operate C2 frameworks such as Cobalt Strike, Havoc, Mythic, and Sliver.
- Apply TTPs for initial access, lateral movement, privilege escalation, persistence and data exfiltration.
- Leverage proprietary and open-source offensive security tool sets effectively to achieve engagement objectives.
- Execute phishing assessments.
Infrastructure:
- Monitor, manage, and maintain cloud and on-premise infrastructure used during assessments.
- Understanding the use of Git Repositories for maintaining operational tools and scripts.
Penetration Testing:
- Internal and external penetration testing.
- Network mapping and enumeration.
- Assess web and mobile applications.
- Perform database scans.
- Assess Active Directory attack paths using tools such as BloodHound.
Security Assessments:
- Assessing Coast Guard's cyber security posture of operational networks through adversary emulation.
- Develop reports and briefs detailing findings and recommendations for all assessments completed.
- Perform cyber threat emulation during scripted exercises, to train DoD Cyber Protection Teams
Required Qualifications:- Relevant Years of Experience: 5+
- Hands on experience with computers and network security.
- Experience conducting phishing campaigns or social engineering.
- Hands on experience with red team tasks and pen testing.
- Familiarity with malware development and EDR/AV bypass strategies.
- Experience with PowerShell, C, C++, or Python.
- Hands on experience utilizing Command and Control (C2) Frameworks such as Cobalt Strike, Sliver, Havoc, etc.
Certifications:- IAT II or IAT III
- GPEN, Red Team Apprentice Course (RTAC), or equivalent
Education: BA/BS or equivalent years of relevant experience