Penetration Tester Journeyman

OneZero Solutions

• $80K — $95K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in penetration testing and red team tasks.
  • Proficient in conducting phishing campaigns and social engineering techniques.
  • Hands-on expertise with network security frameworks and tools.
  • Familiar with malware development and techniques to bypass security measures.
  • Skilled in programming languages such as PowerShell, C, C++, or Python.
  • Experienced in using Command and Control (C2) frameworks like Cobalt Strike and Sliver.
  • Relevant certifications such as IAT II or IAT III, GPEN or RTAC.

Responsibilities

  • Deploy and manage offensive security tools for adversary simulation.
  • Execute vulnerability assessments on internal and external systems.
  • Conduct phishing and social engineering assessments.
  • Monitor cloud and on-premise infrastructure during testing.
  • Assess the security posture of networks through targeted emulation.
  • Develop detailed reports and briefs on security findings and recommendations.
  • Conduct cyber threat emulation exercises for training purposes.

Benefits

  • Hybrid work environment in Alexandria, VA.
  • Focus on advanced cybersecurity techniques and adversary emulation.
  • Opportunity for professional growth through hands-on experience with cutting-edge tools.
  • Engagement in high-impact security assessments for federal clients.
  • Contributions towards strengthening the cyber defense of critical infrastructure.
Full Job Description
Position Title: Penetration Tester Journeyman

Location: Alexandria, VA Hybrid

Clearance: Active Top Secret with SCI eligibility security clearance

Position Summary

Adversary Simulation:
  • Deploy, configure, and operate C2 frameworks such as Cobalt Strike, Havoc, Mythic, and Sliver.
  • Apply TTPs for initial access, lateral movement, privilege escalation, persistence and data exfiltration.
  • Leverage proprietary and open-source offensive security tool sets effectively to achieve engagement objectives.
  • Execute phishing assessments.

Infrastructure:
  • Monitor, manage, and maintain cloud and on-premise infrastructure used during assessments.
  • Understanding the use of Git Repositories for maintaining operational tools and scripts.

Penetration Testing:
  • Internal and external penetration testing.
  • Network mapping and enumeration.
  • Assess web and mobile applications.
  • Perform database scans.
  • Assess Active Directory attack paths using tools such as BloodHound.

Security Assessments:
  • Assessing Coast Guard's cyber security posture of operational networks through adversary emulation.
  • Develop reports and briefs detailing findings and recommendations for all assessments completed.
  • Perform cyber threat emulation during scripted exercises, to train DoD Cyber Protection Teams

Required Qualifications:
  • Relevant Years of Experience: 2 to 3 years
  • Hands on experience with computers and network security.
  • Experience conducting phishing campaigns or social engineering.
  • Hands on experience with red team tasks and pen testing.
  • Familiarity with malware development and EDR/AV bypass strategies.
  • Experience with PowerShell, C, C++, or Python.
  • Hands on experience utilizing Command and Control (C2) Frameworks such as Cobalt Strike, Sliver, Havoc, etc.

Certifications: IAT II : Any one of the following
  • GPEN, Red Team Apprentice Course (RTAC), or equivalent
  • Examples or required certifications: IAT level II:
  • CompTIA Security+ CE
  • CompTIA CySA+
  • CCNA Security
  • GICSP
  • GSEC
  • SSCP

IAT level III: Any one of the following
  • CASP+ CE (also called SecurityX)
  • CISSP (or Associate)
  • CISA
  • CCNP Security
  • GCED
  • GCIH

Education: BA/BS or equivalent years of relevant experience

Similar Jobs

More Jobs at OneZero Solutions

More Information Technology Jobs

Find similar Penetration Tester Journeyman jobs: