Find Jobs
Find Jobs Near You – Available Work in Your Location
Red Team Penetration Tester
Career Insights for Vulnerability Analyst / Penetration Tester
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Virginia data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Vulnerability Analyst or Penetration Tester probes for and exploits security vulnerabilities in web-based applications, networks and systems. Penetration Tests are designed to achieve a specific, attacker-simulated goal and should be requested by customers who are already at their desired security posture. A typical goal could be to access the contents of the prized customer database on the internal network, or to modify a record in an HR system. Vulnerability Assessments are designed to yield a prioritized list of vulnerabilities and are generally for clients who already understand they are not where they want to be in terms of security. The customer already knows they have issues and simply need help identifying and prioritizing them.
$121,440 / year median in Virginia
+4% projected growth
Job Description
- Application and hardware penetration testing
- Automating repetitive tasks with scripting languages
- Mentoring and leading engineers through complex penetration tests and vulnerability assessments
- Advancing penetration testing capabilities through automation and tooling, and creating threat mitigation plans. Required Skills
- Must be US Citizen due to government requirement
- Must have an active DoD Top Secret/SCI
- Bachelor's degree in Cybersecurity, Cyber Operations, Cyber Engineering, Information Systems, Information Technology, Computer Engineering, Electrical Engineering, Electronics Engineering, Software Engineering, Computer Science, Mathematics with a concentration in Computer Science, or an equivalent discipline.
- DoD 8570.
DFARS 252.239-7001
Baseline Certification:
minimum CSSP Auditor.- One of the following certifications: Offensive Security Certified Professional (OSCP), Offensive Security Certified Expert (OSCE), Offensive Security Exploitation Expert (OSEE), or Offensive Security Wireless Professional (OSWP).
- Seven (7) years of full-time professional experience conducting penetration testing or offensive cyber operations in the following areas:
- Developing and using penetration testing tools such as Metasploit, NMAP, Kali Linux, and Cobalt Strike.
- Mimicking threat behavior.
- Using multiple operating systems, including Linux, Windows, macOS, and related platforms.
- Using Active Directory.
- Performing exploit development.
- Identifying gaps in tools and development techniques.
- Developing with at least two scripting or programming languages, such as Python, C++, Java, Rust, Assembly, or C#.