Penetration Tester

OCH Technologies LLC

$110K — $130K *
Aerospace & Defense
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in a relevant field (Cybersecurity, Computer Science, etc.).
  • 5+ years of hands-on penetration testing experience, including recent experience.
  • Proficient in Metasploit, Burp Suite, nMap, and similar tools.
  • Experience producing structured penetration test reports and working under formal Rules of Engagement.
  • Strong understanding of network protocols, firewall configurations, and web application vulnerabilities.

Responsibilities

  • Execute penetration tests on various FAA systems and networks.
  • Identify and exploit vulnerabilities across infrastructure and applications.
  • Participate in red and blue team exercises in controlled environments.
  • Document testing activities and findings in detailed reports.
  • Conduct regression tests to verify vulnerability remediation.
  • Support specialized cyber testing of avionics and flight systems as required.
  • Maintain and update FAA-approved penetration testing tools and environments.

Benefits

  • Hybrid work schedule with flexibility.
  • Opportunity to travel to FAA facilities nationwide.
  • Involvement in crucial national security projects.
  • Participation in advanced red team and blue team exercises.
Full Job Description
OCH Technologies is seeking a Penetration Tester to execute network, system, application, and specialized penetration tests against FAA infrastructure under the direction of the Penetration Testing Lead. The candidate will work within formal Rules of Engagement, operate FAA-approved tools, and produce technically detailed test reports. You will also participate in red team and blue team exercises in simulated environments.

This position supports a proposal effort and is contingent upon award, customer approval, and successful onboarding requirements.

Location

Hybrid- FAA Air Traffic Control System Command Center (ATCSCC)- Washington, DC

This position has the potential to travel up to 40% to other FAA facilities nationwide

Core Responsibilities & Duties
  • Execute penetration tests against NAS and Mission Support systems, networks, and applications following approved Rules of Engagement and test plans.
  • Identify and exploit vulnerabilities in network infrastructure, operating systems, web applications, and databases.
  • Participate in red team and blue team exercises in simulated environments. Execute attack scenarios and document findings.
  • Document all testing activities, findings, and exploitation paths in Penetration Test Reports (PTRs).
  • Perform regression penetration tests to validate remediation of previously identified vulnerabilities.
  • Support aircraft cyber testing activities including avionics and flight system security assessments when directed.
  • Support specialized assessments of edge devices, firewalls, load balancers, and other network infrastructure components.
  • Assess and document the potential for lateral movement when access is gained during testing. Report high-risk findings immediately.
  • Maintain and update penetration testing tools and lab environments. All tools must be FAA-approved prior to use.
  • Support the Penetration Testing Lead in developing Rules of Engagement and test plans for upcoming engagements.

Responsibilities may evolve over time to support team and organizational goals but will remain consistent with the overall scope of the role.

Requirements

Minimum Qualifications

Education

Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Mathematics, or Physics from an accredited institution

Experience
  • A minimum of five (5)+ years of hands-on penetration testing experience, including network, system, and web application testing. At least 2 years of relevant experience must be recent (performed within the last 3 years).
  • Proficiency with Metasploit, Burp Suite, nMap, and related penetration testing frameworks.
  • Experience working within formal Rules of Engagement and producing structured penetration test reports.
  • Understanding of network protocols, routing, switching, firewall configurations, and common misconfigurations.
  • Experience with web application testing following OWASP methodology.

Security Clearance Requirement

Candidate must have the ability to obtain and maintain a Public Trust

Certifications
  • At least one Red Teaming certification: OSCP, OSCE, OSWP, OSWE, CEH, ECSA, CEH Practical, ECSA Practical, LPT Master, GCIH, GPEN, GWAPT, GXPN, or GAWN.
  • Blue Teaming certifications are also accepted: CND, CNDA, GCIH, GCIA, GDAT, GDSA, GCED, or GCFA.
  • OSCP or GPEN preferred.

Preferred Qualifications
  • Experience testing ICS/OT environments or critical infrastructure systems.
  • Experience with wireless security testing or satellite communication systems.
  • Experience with cloud penetration testing (AWS, Azure).
  • Familiarity with aircraft systems, avionics, or aviation communication protocols.
  • Prior red team experience in a government or military context.
  • C2 frameworks (Cobalt Strike, Sliver, Mythic) for adversary simulation beyond Metasploit.
  • BloodHound and Impacket for Active Directory attack path analysis and lateral movement.
  • Nuclei for automated vulnerability detection at scale.
  • Cloud pen testing tools (Pacu, AzureHound) for cloud-hosted environments.
  • SDR/HackRF tools for wireless and RF communications testing.
  • AI-assisted fuzzing tools for expanding exploit discovery on complex systems.


Other Required Skills and Abilities
  • Willingness to travel to FAA facilities and WJHTC for on-site testing engagements.
  • Discipline to operate within strict testing constraints in safety-critical environments.
  • Ability to conduct manual testing beyond automated tool output. Ability to develop custom scripts and payloads as needed.


Similar Jobs

More Jobs at OCH Technologies LLC

More Aerospace & Defense Jobs

Find similar Penetration Tester jobs: