Penetration Tester
OCH Technologies LLC
Penetration Tester
OCH Technologies is seeking a Penetration Tester to execute network, system, application, and specialized penetration tests against FAA infrastructure under the direction of the Penetration Testing Lead. The candidate will work within formal Rules of Engagement, operate FAA-approved tools, and produce technically detailed test reports. You will also participate in red team and blue team exercises in simulated environments.
This position supports a proposal effort and is contingent upon award, customer approval, and successful onboarding requirements.
Location: Hybrid- FAA Air Traffic Control System Command Center (ATCSCC)- Washington, DC
This position has the potential to travel up to 40% to other FAA facilities nationwide
Core Responsibilities & Duties:
- Execute penetration tests against NAS and Mission Support systems, networks, and applications following approved Rules of Engagement and test plans.
- Identify and exploit vulnerabilities in network infrastructure, operating systems, web applications, and databases.
- Participate in red team and blue team exercises in simulated environments. Execute attack scenarios and document findings.
- Document all testing activities, findings, and exploitation paths in Penetration Test Reports (PTRs).
- Perform regression penetration tests to validate remediation of previously identified vulnerabilities.
- Support aircraft cyber testing activities including avionics and flight system security assessments when directed.
- Support specialized assessments of edge devices, firewalls, load balancers, and other network infrastructure components.
- Assess and document the potential for lateral movement when access is gained during testing. Report high-risk findings immediately.
- Maintain and update penetration testing tools and lab environments. All tools must be FAA-approved prior to use.
- Support the Penetration Testing Lead in developing Rules of Engagement and test plans for upcoming engagements.
Responsibilities may evolve over time to support team and organizational goals but will remain consistent with the overall scope of the role.
Requirements:
Minimum Qualifications:
Education: Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Mathematics, or Physics from an accredited institution
Experience:
- A minimum of five (5)+ years of hands-on penetration testing experience, including network, system, and web application testing. At least 2 years of relevant experience must be recent (performed within the last 3 years).
- Proficiency with Metasploit, Burp Suite, nMap, and related penetration testing frameworks.
- Experience working within formal Rules of Engagement and producing structured penetration test reports.
- Understanding of network protocols, routing, switching, firewall configurations, and common misconfigurations.
- Experience with web application testing following OWASP methodology.
Security Clearance Requirement:
Candidate must have the ability to obtain and maintain a Public Trust
Certifications:
- At least one Red Teaming certification: OSCP, OSCE, OSWP, OSWE, CEH, ECSA, CEH Practical, ECSA Practical, LPT Master, GCIH, GPEN, GWAPT, GXPN, or GAWN.
- Blue Teaming certifications are also accepted: CND, CNDA, GCIH, GCIA, GDAT, GDSA, GCED, or GCFA.
- OSCP or GPEN preferred.
Preferred Qualifications:
- Experience testing ICS/OT environments or critical infrastructure systems.
- Experience with wireless security testing or satellite communication systems.
- Experience with cloud penetration testing (AWS, Azure).
- Familiarity with aircraft systems, avionics, or aviation communication protocols.
- Prior red team experience in a government or military context.
- C2 frameworks (Cobalt Strike, Sliver, Mythic) for adversary simulation beyond Metasploit.
- BloodHound and Impacket for Active Directory attack path analysis and lateral movement.
- Nuclei for automated vulnerability detection at scale.
- Cloud pen testing tools (Pacu, AzureHound) for cloud-hosted environments.
- SDR/HackRF tools for wireless and RF communications testing.
- AI-assisted fuzzing tools for expanding exploit discovery on complex systems.
Other Required Skills and Abilities:
- Willingness to travel to FAA facilities and WJHTC for on-site testing engagements.
- Discipline to operate within strict testing constraints in safety-critical environments.
- Ability to conduct manual testing beyond automated tool output. Ability to develop custom scripts and payloads as needed.
About Us:
At OCH, we are more than just a government contracting firm; we are innovators and leaders in providing cutting-edge IT services and cybersecurity solutions. Driven by a set of fundamental values, we excel in creating secure, efficient, and forward-thinking solutions that empower the government agencies we work with. Our commitment to maintaining the highest standards of integrity, adapting swiftly to new challenges, and focusing on the people we serve ensures that we consistently exceed expectations and lead the industry in innovation and reliability.
What Defines Us:
- Integrity - We act with unwavering honesty, ensuring every decision is rooted ethically.
- Adaptable - We swiftly adapt to changes, seizing opportunities to innovate and lead.
- People-Focused - We prioritize relationships, championing growth and mutual success.
- Accountable - We own our outcomes, striving for excellence through continuous improvement.
- Collaborative - We cultivate teamwork, harnessing diverse talents to forge groundbreaking solutions.
Why Join Us?
Step into a role at OCH where your contributions make a tangible impact. Join a team that values creativity and initiative, offering a platform to transform the landscape of government IT services. Here, your work is not just a career—it's a mission. Embrace the opportunity to grow, innovate, and excel alongside industry leaders who are as passionate about technology as they are about making a difference. Plus, we offer a comprehensive benefits package designed to support your wellbeing and work-life balance, including:
- Paid time off and Holidays
- Medical, Dental, and Vision Insurance
- Paid Parental Leave
- Short-term disability, long-term disability, and life insurance - Employer Paid!
- 401(k)
- Additional Voluntary Life Insurance
- Tuition Reimbursement
& More!
E-Verify Participation: OCH Technologies, LLC is a participant of E-Verify to verify the identity and employment eligibility of newly hired employees.
Veteran's Preference and Accessibility Statement: At OCH Technologies, we deeply respect and appreciate the unique skills and experiences that veterans bring to our team. As a federal contractor, we encourage qualified veterans to apply and provide preference where permitted by law. Your service and dedication are valued here.
We are committed to creating a workplace that is open, welcoming, and accessible to everyone. In accordance with the Americans with Disabilities Act (ADA) and Section 503 of the Rehabilitation Act, we provide reasonable accommodations throughout the hiring process to ensure individuals with disabilities can apply without barriers. If you need assistance or an accommodation, please contact us at View email address on click.appcast.io.
OCH Technologies, LLC is proud to be an equal opportunity employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, disability, gender identity, or any other protected characteristic as outlined by federal, state, or local laws.
- DescriptionSAIC is seeking a highly motivated Penetration Tester. The successful candidate will provide support to the Cybersecurity Integrity Center (CIC) in the Department of State Bureau of Information Resource Management (IRM). Duties are in the Washington, D.C. metropolitan...SuggestedWork at officeLocal areaShift work3 days per week
- ...tested leadership, and trusted results to enable national security missions worldwide.Job DescriptionOverviewSOSi is seeking a Penetration Tester III to support proactive cyber defense activities in alignment with our customer. This role is responsible for conducting...SuggestedContract workWork at officeWorldwideMonday to FridayWeekend workAfternoon shift
$104k - $166k
ResponsibilitiesPeraton is currently seeking to hire an experienced Penetration Tester for its Federal Strategic Cyber Group. Location: Chandler, AZ and Washington DC.Role and Responsibilities: We are seeking to hire an experienced and highly skilled Penetration Tester...SuggestedContract workCurrently hiringShift work$86k - $138k
ResponsibilitiesPeraton is seeking an experienced Cyber Penetration Tester to become part of Peratons’ Federal Strategic Cyber programs. Location: Northern VA; Hybrid - flexible as long as person can come on-site as & when needed. In this role, you will: Support the Red...SuggestedContract workFlexible hoursShift work$87.1k - $157.45k
Leidos is seeking experienced Penetration Tester to support the Defense Manpower Data Center (DMDC) CyberPRIMES program. Leidos is a major partner on the contract and will provide a substantial portion of the cybersecurity workforce supporting the Defense Human Resources...SuggestedFull timeContract workWork at office$130k - $190k
...a legacy of protecting national interests and promoting peace and stability worldwide.Job SummaryWe are currently seeking a Penetration Tester. This position is a full-time opportunity located in Arlington, Virginia.Battelle's Mission Focused Tools Business Line is seeking...Full timeWork experience placementWork at officeLocal areaRemote workWorldwideFlexible hours$90k - $130k
...Full-Time Clearance Requirement: TS/SCI Clearance Required Position Overview:Praescient Analytics is seeking a highly motivated Penetration Tester to join our cybersecurity team in Arlington, VA, supporting the Department of War (DoW) Chief Digital and Artificial...Full timeWork at office- ...Description Penetration Tester Xcelerate Solutions is seeking a Penetration Tester to support CyberPRIMES cybersecurity, privacy, records and information management, and related enterprise support for DHRA, including DMDC and OUSD(P&R). Come join our award-winning...
- ...The Judge Group is currently seeking a Penetration Tester with an active secret clearance to support a classified customer in Beltsville, MD. This position is onsite five days per week. Core Requirements Active Security Clearance Federal Contracting...
- ...Federal Technology Solutions is seeking an experienced Senior Penetration Testerto lead advanced security assessments and contribute to... ...activities.Manage and mentor a small team of junior penetration testers; provide technical guidance and training.Build and lead a...3 days per week
- ...benefits package. Required Experience Minimum of 5 years' experience in the conduct of, supporting the conduct of, or leading penetration tests. Key skills include a strong understanding of operating systems and networking protocols, strong understanding of how...
$124.54k - $180k
GovCIO is currently hiring for a Senior Pentration Tester with an active TS/SCI clearance to support DHS onsite in Washington, DC.ResponsibilitiesThe Senior Penetration Tester serves as Key Personnel responsible for leading advanced penetration testing and vulnerability...Currently hiring$106.3k - $221.1k
...more. Join us to drive positive, lasting change that moves missions and the government forward! Job Description The Penetration Tester will conduct comprehensive penetration tests on applications, networks, and systems. Identify and exploit security vulnerabilities...Live inWork at officeLocal area- ...We value our clients, integrity and employees and believe a single person can make a difference! We are seeking a Senior Penetration Tester for a Part-time opportunity. This opportunity requires travel to throughout the DMV area. The Senior Penetration Tester serves...Part timeWork at office
$115k - $203k
...US-VA Arlington Full time R38903 Senior Penetration Tester Job Description Overview CoStar Group is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces. Included in the S&P 500 Index, CoStar...Hourly payFull timeWork at officeWork from homeMonday to Thursday- ...identifying candidates for the following position. Requisition Type:Full Time Position Status: Contingent Position Title: Penetration Tester Location:Arlington, VA Security Clearance:Secret Duties and Responsibilities The Penetration Testersupports...Full timeFor contractors
- Job Summary: The Penetration Tester is responsible for conducting hands-on security testing to assess vulnerabilities across cloud, network, and application layers. This part-time remote role focuses on ensuring the integrity of evidence, thorough documentation, and reproducible...Contract workPart timeRemote workFlexible hours
- ...holidays, an employee referral program, and educational assistance. Additional details are available on our website: Title: Penetration Tester JourneymanLocation: Alexandria, VA HybridClearance: Active Top Secret with SCI eligibility security clearancePosition SummaryAdversary...Full timeApprenticeshipLocal area
$116.35k - $210.33k
The Leidos Analysis Solutions Business Area is seeking engineers to support the characterization of undersea naval and multi-domain threats at both the subsystem and integrated networked combat-system levels. This position will also support the development and dissemination...Full timeWork at office- ...The Integration Tester plays a critical role in ensuring the stability, accuracy, and reliability of Navy Mutual's enterprise applications and system integrations. This position is responsible for designing, executing, and continuously improving testing strategies across...
$69.55k - $125.73k
We are currently seeking a Vulnerability Analyst to join the Compartmented Enterprise Services Office (CESO) effort. This program is establishing a modern secure web service (SWS) operation as part of a state-of-the-art, highly automated platform capable of supporting ...Work at office- ...Penetration Tester We are seeking a highly skilled and proactive Penetration Tester to join our cybersecurity team. In this role, you will identify vulnerabilities and test the security of networks, applications, and systems by simulating real-world attacks. You will...Temporary workFor contractorsImmediate startFlexible hours
- DescriptionSAIC is seeking a highly skilled Senior Vulnerability Analyst with a strong technical background to join our team in support of a critical US government agency in the National Capital Region. This is an exciting opportunity to work with a team responsible for...2 days per week
$104.8k - $192.2k
...wherever you want it to go. Join EY and help to build a better working world.Government and Public Sector - Cybersecurity - Penetration Tester - Senior ConsultantFrom strategy to execution, the Government & Public Sector practice (“GPS”) of Ernst & Young provides a full...For contractorsSummer holidayWork at officeLocal areaFlexible hours$146k - $234k
ResponsibilitiesJob Description:Peraton is seeking an Sr Information Systems Security Officer to support our Federal Strategic Cyber programs.Location: Washington, DC In this role, you will:Apply best practices for cybersecurity program standards, processes, procedures,...Contract workWork experience placementShift work- ...include managing the vulnerability remediation process to ensure weaknesses identified through vulnerability scanning and assessments/penetration tests along with any emergency concerns are assigned to owners and tracked to resolution. Responsible for analyzing...
- A leading cybersecurity consultancy is seeking a Cybersecurity Vulnerability Analyst based in Arlington, VA. The role requires an active Top Secret Security Clearance and 5+ years of experience, focusing on vulnerability analysis for federal clients. Candidates must exhibit...
- ...solutions to government entities to deliver predictable, measurable impact for the American taxpayer and consumer. The Integration Tester is responsible for validating and testing integrations across Amazon Connect, AWS Bedrock, Amazon Kinesis, Salesforce, Verint, and...Full time
$150k - $160k
Job DescriptionSUMMARY:Provides strategic leadership and operational oversight of the Bank's technology governance, risk management, and compliance (GRC) program. Serves as a primary liaison among Technology, Risk, Audit, and executive leadership to ensure the technology...Contract workTemporary workWork at officeFlexible hours- ...TITLE : Penetration Tester WORK LOCATION : Falls Church, VA (Remote) Local only CLEARANCE : Candidates should have at least a Public Trust Clearance ( Active or Inactive ) SKILLS : penetration testing, web application testing, Api testing, burp suite...Local areaRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Penetration Tester. Be the first to apply!


