Security Software Engineer - Red Team Penetration Tester

RPI Group, Inc.

$110K — $150K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years experience with Linux, demonstrating firm knowledge, plus relevant certifications like COMPTIA Linux+ or FedVTE Linux+
  • 5+ years experience with Windows and enterprise networks, with applicable training (MCSA or similar)
  • Strong expertise in penetration testing tools such as Kali, Metasploit, NMAP, and Cobalt Strike, along with ethical hacking certifications
  • Experience in red team operations or software development related to security, using languages like Python, C, and C++
  • Minimum IAT Level II certification as per DoD 8570.01 standards and an additional penetration testing certification

Responsibilities

  • Conduct penetration tests and red team operations for Navy clients
  • Analyze and document security vulnerabilities in systems
  • Develop and recommend mitigations for identified security risks
  • Collaborate with development teams to improve software security
  • Utilize various testing tools to simulate attacks and assess network security

Benefits

  • Comprehensive benefits package
  • Opportunities for professional development and training
  • Dynamic work environment with mission-focused projects
  • Work within a collaborative team
  • Flexible work schedules available
Full Job Description
Position Title: Security Software Engineer - Red Team Penetration Testers
Salary Range: $110,000 to $150,000 Annually
Location: Dahlgren, VAAbout the Role
RPI Group is seeking a skilled, driven Security Software Engineer to support Red Team penetration testing for a mission-focused Navy customer. If you are energized by complex technical challenges, enjoy finding and analyzing security weaknesses, and want your work to inform real-world defensive decisions, this role is for you.What We're Looking For
  • Five(5)Yearsexperiencein:
    • Linux - firm grasp/demonstrated knowledge
    • Associated Training: COMPTIA Linux+ or FedVTE Linux+
  • Five(5)Yearsexperiencein:
  • Windows - foundational knowledge with good understanding of enterprise networks
  • Associated Training: Microsoft course (MCSA; Various)
  • Strong workingknowledgeofcommonPenetrationTesting(PENTEST)tools:
    • Kali, Metasploit, NMAP, Cobalt Strike
    • Associated Training: Certified Ethical Hacker or Offensive Security Certified Professional and;
  • Documentedexperienceinatleastoneofthefollowing:
  • Penetration Testing (PENTEST) (government or contractor)
  • Red Team Operations (government or contractor)
  • Tool/Software Development (exploits/malware, C2, reverse engineering, bug bounties)
  • Python, C, C Sharp, C++, Go, Perl, Powershell

Web Dev/Web App Dev/Web Penetration testing
      • NSX, vCenter, vRealize Suite, Horizon View (VDI) and others
      • PAN-OS
      • FirePower, Nexus, IOS, ASA
      • ONTAP, SnapMirror
      • Active-Directory
      • Entra ID (Azure AD), Active Directory, SSO, MFA, Azure application integration, Identity Federation.
      • Automation using Powershell, PowerAutomate, Logic Apps, Graph API.
      • Microsoft Entra ID and Microsoft 365 in a hybrid environment.
      • Experience with Palo Alto, Cisco, VMWare, NetApp and Microsoft products.
      • Extending or integrating on premises AD with Entra ID.
      • Managing identity and access in Microsoft Entra ID.Experience conducting Red Team operations in an MDE environment.
      • Experience with AWS, Cloud Audit, Serverless and Microservice Architecture
      • Experience working with AWS services (such as EC2, S3, KMS, RDS) and security best practices relevant to those services
      • Experience with Web Services penetration testing (RESTful and SOAP) Web Authentication protocols (e.g. OAuth2, SAML, LDAP)
  • PHP, ASP, SQL db's, Java, HTML, No SQL
  • Minimum certification as IAT Level II per DoD 8570.01, or successor.
  • Minimum certification as penetration tester and possess one of the following certificates:
  • Offensive Security Certs: Offensive Security Certified Professional (OSCP), Offensive Security Certified Expert (OSCE), Offensive Security Exploitation Expert (OSEE), Offensive Security Wireless Professional (OSWP)
  • SANS Certs: SEC560 - Network Penetration testing and Ethical Hacking (GPEN Certification), SEC542 - Web App Penetration Testing and Ethical Hacking (GWAPT Certification), SEC660 - Advance Penetration Testing. Exploit Writing, and Ethical Hacking (GXPN Certification), SEC642 -Advanced Web App Penetration Testing and Ethical Hacking, SEC564 -
  • Red Team Operations and Threat Emulation
  • OSD Sponsored Cyber Operation Academy Course (COAC) graduates.
  • Capture the Flag (CTF) participation (DEFCON, Over-The-Wire (OTW), Hack the Box, USS Secure CTF's)
  • Security research resulting in a Common Vulnerabilities and Exposures (CVE)
  • Possess the ability to:
  • Debug and reverse engineer software.
  • Analyze Windows Events and Linux syslog's, boot logs and dmesg logs.
  • Program and debug Web 2.0, Java, Perl, Ada, C++, Tool Command Language (tcl/tk) scripts and graphical user interfaces (GUis) using Microsoft Visual tel and Rational ClearCase for software configuration management.
  • Program and debug Web 2.0, Java, Perl, Ada, C++, Tool Command Language (tcl/tk) scripts and graphical user interfaces (GUIs) using Microsoft Visual tel and Rational ClearCase for software configuration management.
  • Recommend software modifications to systems to mitigate known vulnerabilities. Operate and administrate computer systems running HP-UX, UNIX, Solaris, Linux and Microsoft Windows.
  • Identify security flaws in compiled and human readable source code. Understand code utilizing real-time VxWorks and Lynx OS operating systems, Common Object Resource Broker Architecture (CORBA), firewalls and networking protocols.
  • Understand how to implement NSA approved encryption technologies and devices. Apply DISA Security Technical Implementation Guides (STIGs).
  • Apply virtual hosting and server technology in system architectures. Understand and apply the concept of deceptive technology such as honey pots in system architectures.
  • Participate in Code Reviews. Perform Static Source Code Analysis. Author recommendations for improving software and code design.
  • Contribute to a System Security Administrator and Operators Manual (SSAOM)

Must be a U.S. Citizen and Possess an Active Security Clearance

Similar Jobs

More Jobs at RPI Group, Inc.

More Information Technology Jobs

Find similar Security Software Engineer - Red Team Penetration Tester jobs: