Penetration Tester
ANALYGENCE Inc
Description Tharros has an immediate opportunity to support the US Navy with operational test and evaluation support. The Penetration Tester will assist in the development of cyber test plans, execute cyber tests, and report cyber test results. In this role you will conduct cyber tests on operational systems, in laboratory environments, or in cyber range environments. Testing may be against physical, virtualized, or cloud-based systems. This position shall leverage all authorized resources and analytic techniques to penetrate/access targeted networks and systems under test in support of OPTEVFOR's cyber OT&E mission. Team member will perform these duties under the supervision of the 01D Cyber Operations Officer.
- Review and become proficient in OPTEVFOR cyber T&E concept of operations, SOPs, policies and guidance.
- Maintain and participate in the development of 01D SOPs and documentation for DCAT authorization established in DoDI 8585.01.
- Research, review, prioritize, and submit operational requirements for acquisition of equipment or cyber capabilities, following the 01D tool approval process.
- Support development and execution of TTPs for penetration testing or Red Teaming.
- Research adversary cyber actors' TTPs, organizational structures, capabilities, personas, and environments, and integrate findings into cyber survivability test planning and execution.
- Participate in OPTEVFOR Cyber Test planning:
- Conduct open-source research and system under test documentation review to familiarize with the system's mission, architecture and interfaces including critical components to identify its attack surface and threat vectors
- Participate in check point meetings
- Support development of test plan objectives
- Review test plans, ensuring that test plans objectives are feasible
- Participate in test planning site visits
- Participate in test preparation:
- Participate in site pre-test coordination visits. Support in-brief to the test site.
- Support red team test plan review
- Add relevant system technical information to test reference library
- Organize and support research presentations for advanced capability development in support of future tests
- Prepare OPTEV-RT test assets (Government Furnished)
- Execute test events, including Cooperative Vulnerability Penetration Assessments, Adversarial assessments, and Cyber Tabletops, in support of Operational Testing, Developmental Testing, risk reduction events, or other events, as assigned.
- Use OPTEVFOR provided and NAO approved commercial and open-source network cyber assessment tools (e.g. Core Impact, Nmap, Burp, Metasploit, and Nessus).
- Employee ethical hacking knowledge to exploit discovered vulnerabilities and misconfigurations associated with but not limited to operating systems (Windows, Linux, etc.), protocols ( FTP, etc.), and network security services (PKI, etc.) to accomplish test objectives
- Be able to accomplish testing independently
- Ensure tests are conducted safely, in accordance with the test plan, and OPTEVFOR policies are adhered to
- Follow Joint Forces Headquarters (JFHQ)-DODIN deconfliction procedures
- Verify collected data for accuracy and completeness
- Participate in the post-test iterative process, including generation of documents (e.g. deficiency/risk sheets).
- Document lessons learned.
- Participate in capture the flag events, cyber off sites, external engagements such as red team huddles and red team technical exchange meetings; develop required products and materials in support of these events.
- Attend OPTEVFOR required meetings in support of OT&E.
- Generate and update documentation to maintain DCAT authorization compliance per DoDI 8585.0.
- Process exfiltrated data for analysis and/or dissemination to customers.
- Test and evaluate locally developed tools for operational use and implementation.
- Minimum 3 years' experience performing any combination of: penetration testing, red teaming, or exploitation development.
- Minimum 3 years' with proficiency in leading red team operators in penetration testing/red teaming to accomplish assigned test objectives.
- Offensive Security Certified Professional (OSCP), OSCE, GX-PT, GXPM, PNPT, or HTB CPTS required.
- Proficient in multiple offensive tools, including:
- Metasploit, Cobalt Strike, Core Impact, Burp Suite, Nessus, SharpHoundBloodHound
- Ability to validate functionality and safety of offensive tools (e.g. exploits) given the source code and document the results.
- Ability to detect malicious activity of a program using dynamic analysis techniques and document the results.
- Independently operate to conduct penetration testing/red teaming to accomplish assigned test objectives.
- Skill in assessing current tools to identify needed improvements.
- Skill in knowledge management, including technical documentation techniques (e.g., Wiki page).
- Knowledge of current software and methodologies for active defense and system hardening.
- Knowledge of encryption algorithms and cyber capabilities/tools (e.g., Transport Layer Security, Pretty Good Privacy).
- Knowledge of evasion strategies and techniques.
- Knowledge of forensic implications of operating system structure and operations.
- Knowledge of host-based security products and how they affect exploitation and vulnerability.
- Knowledge of network administration.
- Knowledge of network construction and topology.
- Knowledge of security hardware and software options, including the network artifacts they induce and their effects on exploitation.
- Knowledge of security implications of software configurations.
- Knowledge of the fundamentals of digital forensics in order to extract actionable intelligence.
- Knowledge of cryptologic capabilities, limitations, and contributions to cyber operations.
- Knowledge of Unix/Linux and Windows operating systems structures and internals (e.g., process management, directory structure, installed applications).
- Knowledge of network collection procedures to include decryption capabilities/tools, techniques, and procedures.
- Process exfiltrated data for analysis and/or dissemination to customers.
- Test and evaluate locally developed tools for operational use.
- Skill in testing and evaluating tools for implementation.
- Proficient in Microsoft Office Suite to include Teams or similar workplace chat and videoconferencing tools.
- Excellent written and verbal communication skills.
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Penetration Tester in Norfolk, VA vacancy
$500 per month
...Become a Professional Game Tester We're looking for passionate gamers to join our elite team of mobile game testers. Get paid to play and test the latest games before they launch. $500+ Avg Monthly Pay 5-10 Hours/Week 100% Remote Position Requirements:...SuggestedRemote work10 hours per week$75.2k - $158.1k
Job Title: TMIP-Maritime Software Tester Job Category: Engineering Time Type: Full time Minimum Clearance Required to Start: Secret Employee Type: Regular Percentage of Travel Required: Up to 10% Type of Travel: Continental US * * * The Opportunity...SuggestedFull timeContract workWork experience placementWork at officeFlexible hours$75.2k - $158.1k
Job Title: Cyber AnalystJob Category: Information TechnologyTime Type: Full timeMinimum Clearance Required to Start: SecretEmployee Type: RegularPercentage of Travel Required: Up to 10%Type of Travel: Local* * *The Opportunity:CACI is looking for a Cybersecurity Analyst...SuggestedContract workWork experience placementLocal areaRemote workFlexible hours- ...Information System Security Officer to work with application leads, system administrators, database administrators, developers, and testers to ensure assigned systems are security compliant and achieve or maintain Authority to Operate (ATO). The role includes following...Suggested
$107k - $115k
Overview VTG seeks to hire an Information Systems Security Officer (ISSO) in Los Angeles, CA to monitor and maintain systems security on operational systems such as malicious code eradication, configuration management, assessment and authorization of current and future...SuggestedCivilian ContractorWork experience placementWork at office$106.08k - $176.82k
City/State Norfolk, VA Work Shift First (Days) Overview: Sentara is hiring a ServiceNow Principal Domain Architect! This position is fully remote! Overview The domain architect proactively and holistically leads and supports EA activities that ...Full timeTemporary workWork experience placementRemote workShift work$75.2k - $158.1k
Job Title: Information Systems Security Engineer (ISSE) - Navy Key Management InfrastructureJob Category: Information TechnologyTime Type: Full timeMinimum Clearance Required to Start: SecretEmployee Type: RegularPercentage of Travel Required: Up to 10%Type of Travel: Continental...Contract workWork experience placementFlexible hours$87.1k - $157.45k
Leidos is seeking an Information System Security Engineer (ISSE) to support cybersecurity authorization related efforts for SMIT. SMIT is the largest IT services program for the Navy. Under the Service Management, Integration, and Transport (SMIT) program, the Leidos team...Full timeInterim roleLocal areaShift work$122.21k - $211.32k
Overview Location: Remote with occasional travel to Norfolk, VA.Overview: The Information Systems Security Engineer (ISSE) - Navywill promote an integrated, team-oriented culture while delivering strong individual contribution while advocating through action, robust ...Full timeContract workLocal areaRemote work- Computer Systems Analyst - Portsmouth, VAPredicate Logic is seeking a motivated Computer Systems Analyst to join our team at the Naval Information Warfare Center - Atlantic (NIWC-A) in Portsmouth, VA.Founded in 1992, Predicate Logic is a woman-owned, employee-owned, high...Remote work
- Computer Systems Analyst III SEACORP is seeking a well-qualified Computer Systems Analyst III. Primary Duties and Responsibilities: Job Summary: SEACORP is seeking a Computer Systems Analyst III for our Hardware Solutions Business Area. They will be responsible...Full timeTemporary workWork at officeLocal area
- Job Title: Call Center Systems Analyst – Genesys Cloud & Amazon Connect Location: Hybrid – Atlanta, GA / Richmond, VA / Connecticut / Norfolk, VA Job Summary Seeking experienced Call Center Systems Analysts with expertise in Genesys Cloud, Amazon Connect, and ...
$102.17k
...APTs, data breaches), including forensic analysis and root cause determination. Design and execute vulnerability assessments, penetration tests, and simulated attack scenarios across infrastructure and applications. Partner with IT and software development teams to...Work experience placementH1b- Position: Electronic Security Systems Engineer (Job ID: 4450) Location: Norfolk, VARemote Status: Hybrid Job Id: 4450 # of Openings: 1 Electronic Security Systems EngineerPurpose:Valkyrie Enterprises...Contract workWork at officeImmediate start
$55k - $58k
...Validation.RELOCATION IS A MUST AND 4 WEEKS MANDATORY IN-PERSON TRAINING IN RESTON, VATitle: Jr. Validation Engineer/QA Analyst/Jr. QA Tester/Business Analyst/BADescription: WE ARE LOOKING FOR FRESH GRADUATES FOR QA AND VALIDATION POSITIONS.Employment Benefits:Competitive...Full timeRelocationRelocation package$89.1k - $148.2k
Information Systems Security Engineer (ISSE) Shape the future of defense with MANTECH! Join a team dedicated to safeguarding our nation through advanced tech and innovative solutions. Since 1968, we've been a trusted partner to the Department of Defense, delivering ...Hourly payContract workTemporary workWork experience placementWork at officeLocal areaRemote work- Titan America LLC (NYSE: TTAM), a TITAN Group Company, is one of the premier producers of cement and building materials in the eastern United States and the North American subsidiary of the TITAN Group. With a history spanning over 100 years, Titan America has consistently...For contractorsWork at office
- Job Title: Call Center Systems Analyst - Genesys Cloud & Amazon Connect Location: Remote Job Summary Seeking experienced Call Center Systems Analysts with expertise in Genesys Cloud, Amazon Connect, and IVR technologies to support contact center migration and digital...Remote work
- Job Description Job Description Predicate Logic is looking for a motivated Computer Systems Analyst to join our team in Norfolk, VA.Founded in 1992, Predicate Logic is a woman-owned, employee-owned, high technology engineering service company. Predicate Logic's employees...
- Job Description Job Description Job Title: Tactical System Analyst Senior Location: USFF Norfolk, Virginia at a Government facility/site (100% on-site) Clearance: TS/SCI Program: USFF Certifications: IAT II Certification (Typically CompTIA SEC+) Company...
- Duties You will receive complex logistics requests from worldwide customers and resolve customer's mission essential support requests via telephone, emails, naval messages and faxed information. You will analyze, evaluate and provide technical supply support assistance...Temporary workRemote workWorldwide
$125k - $150k
About INIT INIT Innovations in Transportation, Inc. is a leading provider of hardware, software, service, support, and operations management solutions for public transportation companies across North America. As a turnkey supplier, INIT develops, produces, installs...Temporary workRemote workFlexible hours$86.8k - $198k
Cyber Automation EngineerThe Opportunity:Maintain responsibility for the successful installation, configuration, and integration of the Cyber Asset Attack Surface Management (CAASM) platform within complex client environments. Leverage an understanding of IT infrastructure...Full timeContract workPart timeWork at officeLocal areaRemote work- About Elizabeth River Crossings (ERC) Elizabeth River Crossings (ERC) operates and maintains critical transportation infrastructure serving Hampton Roads. Technology and cybersecurity are essential to our mission of providing safe, reliable, and secure transportation...For contractors
- U.S. Citizenship and an Active Secret Security Clearance is required. This job is onsite in Portsmouth, VA. Position Overview We are seeking a driven and detail-oriented Software Engineer to support a shipyard-focused program. This role involves building and...Full time
$86.8k - $198k
Cybersecurity ArchitectThe Opportunity:Everyone knows security needs to be “baked in” to system architecture, but you actually know how to bake it in. You can identify and implement ways to harden systems and reduce their attack surface.As a Cybersecurity Architect on our...Full timeContract workPart timeWork at officeLocal areaRemote work$160k - $185k
Moffatt & Nichol in collaboration with Waggonner & Ball, a Moffatt & Nichol Studio, are actively seeking a Senior Architect with 15+ years of experience to help expand our footprint into the Mid-Atlantic! This is an amazing opportunity with high visibility working directly...For contractorsWork at officeLocal areaWorldwide$96.06k - $174.43k
Systems Analyst Advisor Location: Norfolk, VA; Atlanta, GA; Richmond, VA Hybrid 1 : This role requires associates to be in-office 1 - 2 days per week, fostering collaboration and connectivity, while providing flexibility to support productivity and work-life balance...Temporary workWork experience placementWork at officeLocal area2 days per week1 day per week- DescriptionBurns & McDonnell provides wide-ranging A-E services for the Department of Defense (DOD), Department of Energy (DOE), and other federal agencies. Our global portfolio of federal work includes projects and programs completed for the U.S. Army Corps of Engineers...Contract workFor contractorsWork at office
$99k - $225k
Cloud Security Engineer, SeniorThe Opportunity:Everyone is trying to “harness the cloud”, but not everyone knows how to secure it. As a security engineer, you know how to assess and implement requirements that ensure the safety of information systems and protect them against...Full timeContract workPart timeWork at officeLocal areaRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Penetration Tester. Be the first to apply!




