Penetration Tester
OCH Technologies LLC
Penetration Tester
OCH Technologies is seeking a Penetration Tester to execute network, system, application, and specialized penetration tests against FAA infrastructure under the direction of the Penetration Testing Lead. The candidate will work within formal Rules of Engagement, operate FAA-approved tools, and produce technically detailed test reports. You will also participate in red team and blue team exercises in simulated environments.
This position supports a proposal effort and is contingent upon award, customer approval, and successful onboarding requirements.
Location: Hybrid- FAA Air Traffic Control System Command Center (ATCSCC)- Washington, DC. This position has the potential to travel up to 40% to other FAA facilities nationwide.
Core Responsibilities & Duties:
- Execute penetration tests against NAS and Mission Support systems, networks, and applications following approved Rules of Engagement and test plans.
- Identify and exploit vulnerabilities in network infrastructure, operating systems, web applications, and databases.
- Participate in red team and blue team exercises in simulated environments. Execute attack scenarios and document findings.
- Document all testing activities, findings, and exploitation paths in Penetration Test Reports (PTRs).
- Perform regression penetration tests to validate remediation of previously identified vulnerabilities.
- Support aircraft cyber testing activities including avionics and flight system security assessments when directed.
- Support specialized assessments of edge devices, firewalls, load balancers, and other network infrastructure components.
- Assess and document the potential for lateral movement when access is gained during testing. Report high-risk findings immediately.
- Maintain and update penetration testing tools and lab environments. All tools must be FAA-approved prior to use.
- Support the Penetration Testing Lead in developing Rules of Engagement and test plans for upcoming engagements.
Responsibilities may evolve over time to support team and organizational goals but will remain consistent with the overall scope of the role.
Requirements:
Minimum Qualifications:
Education: Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Mathematics, or Physics from an accredited institution
Experience:
- A minimum of five (5)+ years of hands-on penetration testing experience, including network, system, and web application testing. At least 2 years of relevant experience must be recent (performed within the last 3 years).
- Proficiency with Metasploit, Burp Suite, nMap, and related penetration testing frameworks.
- Experience working within formal Rules of Engagement and producing structured penetration test reports.
- Understanding of network protocols, routing, switching, firewall configurations, and common misconfigurations.
- Experience with web application testing following OWASP methodology.
Security Clearance Requirement:
Candidate must have the ability to obtain and maintain a Public Trust
Certifications:
- At least one Red Teaming certification: OSCP, OSCE, OSWP, OSWE, CEH, ECSA, CEH Practical, ECSA Practical, LPT Master, GCIH, GPEN, GWAPT, GXPN, or GAWN.
- Blue Teaming certifications are also accepted: CND, CNDA, GCIH, GCIA, GDAT, GDSA, GCED, or GCFA.
- OSCP or GPEN preferred.
Preferred Qualifications:
- Experience testing ICS/OT environments or critical infrastructure systems.
- Experience with wireless security testing or satellite communication systems.
- Experience with cloud penetration testing (AWS, Azure).
- Familiarity with aircraft systems, avionics, or aviation communication protocols.
- Prior red team experience in a government or military context.
- C2 frameworks (Cobalt Strike, Sliver, Mythic) for adversary simulation beyond Metasploit.
- BloodHound and Impacket for Active Directory attack path analysis and lateral movement.
- Nuclei for automated vulnerability detection at scale.
- Cloud pen testing tools (Pacu, AzureHound) for cloud-hosted environments.
- SDR/HackRF tools for wireless and RF communications testing.
- AI-assisted fuzzing tools for expanding exploit discovery on complex systems.
Other Required Skills and Abilities:
- Willingness to travel to FAA facilities and WJHTC for on-site testing engagements.
- Discipline to operate within strict testing constraints in safety-critical environments.
- Ability to conduct manual testing beyond automated tool output. Ability to develop custom scripts and payloads as needed.
About Us: At OCH, we are more than just a government contracting firm; we are innovators and leaders in providing cutting-edge IT services and cybersecurity solutions. Driven by a set of fundamental values, we excel in creating secure, efficient, and forward-thinking solutions that empower the government agencies we work with. Our commitment to maintaining the highest standards of integrity, adapting swiftly to new challenges, and focusing on the people we serve ensures that we consistently exceed expectations and lead the industry in innovation and reliability.
What Defines Us:
- Integrity - We act with unwavering honesty, ensuring every decision is rooted ethically.
- Adaptable - We swiftly adapt to changes, seizing opportunities to innovate and lead.
- People-Focused - We prioritize relationships, championing growth and mutual success.
- Accountable - We own our outcomes, striving for excellence through continuous improvement.
- Collaborative - We cultivate teamwork, harnessing diverse talents to forge groundbreaking solutions.
Why Join Us?
Step into a role at OCH where your contributions make a tangible impact. Join a team that values creativity and initiative, offering a platform to transform the landscape of government IT services. Here, your work is not just a career—it's a mission. Embrace the opportunity to grow, innovate, and excel alongside industry leaders who are as passionate about technology as they are about making a difference. Plus, we offer a comprehensive benefits package designed to support your wellbeing and work-life balance, including:
- Paid time off and Holidays
- Medical, Dental, and Vision Insurance
- Paid Parental Leave
- Short-term disability, long-term disability, and life insurance - Employer Paid!
- 401(k)
- Additional Voluntary Life Insurance
- Tuition Reimbursement
& More!
E-Verify Participation: OCH Technologies, LLC is a participant of E-Verify to verify the identity and employment eligibility of newly hired employees.
Veteran's Preference and Accessibility Statement: At OCH Technologies, we deeply respect and appreciate the unique skills and experiences that veterans bring to our team. As a federal contractor, we encourage qualified veterans to apply and provide preference where permitted by law. Your service and dedication are valued here.
We are committed to creating a workplace that is open, welcoming, and accessible to everyone. In accordance with the Americans with Disabilities Act (ADA) and Section 503 of the Rehabilitation Act, we provide reasonable accommodations throughout the hiring process to ensure individuals with disabilities can apply without barriers. If you need assistance or an accommodation, please contact us at View email address on click.appcast.io.
OCH Technologies, LLC is proud to be an equal opportunity employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, disability, gender identity, or any other protected characteristic as outlined by federal, state, or local laws.
- ...tested leadership, and trusted results to enable national security missions worldwide.Job DescriptionOverviewSOSi is seeking a Penetration Tester III to support proactive cyber defense activities in alignment with our customer. This role is responsible for conducting...SuggestedContract workWork at officeWorldwideMonday to FridayWeekend workAfternoon shift
- DescriptionSAIC is seeking a highly motivated Penetration Tester. The successful candidate will provide support to the Cybersecurity Integrity Center (CIC) in the Department of State Bureau of Information Resource Management (IRM). Duties are in the Washington, D.C. metropolitan...SuggestedWork at officeLocal areaShift work3 days per week
$90k - $130k
...Full-Time Clearance Requirement: TS/SCI Clearance Required Position Overview:Praescient Analytics is seeking a highly motivated Penetration Tester to join our cybersecurity team in Arlington, VA, supporting the Department of War (DoW) Chief Digital and Artificial...SuggestedFull timeWork at office$86k - $138k
ResponsibilitiesPeraton is seeking an experienced Cyber Penetration Tester to become part of Peratons’ Federal Strategic Cyber programs. Location: Northern VA; Hybrid - flex as long as person can come on-site as/when needed. In this role, you will: Support the Red Cell...SuggestedContract workFlexible hoursShift work- ASRC Federal Technology Solutions is seeking an experienced Penetration Testerto lead advanced security assessments and contribute to the... ....Manage and mentor a small team of junior penetration testers; provide technical guidance and training.Build and lead a Purple...Suggested3 days per week
$104k - $166k
ResponsibilitiesPeraton is currently seeking to hire an experienced Penetration Tester for its Federal Strategic Cyber Group. Location: Chandler, AZ and Washington DC.Role and Responsibilities: We are seeking to hire an experienced and highly skilled Penetration Tester...Contract workCurrently hiringShift work$124.54k - $180k
GovCIO is currently hiring for a Senior Pentration Tester with an active TS/SCI clearance to support DHS onsite in Washington, DC.ResponsibilitiesThe Senior Penetration Tester serves as Key Personnel responsible for leading advanced penetration testing and vulnerability...Currently hiring- ...in Alexandria, VA. The first 30 days of work will be full-time on-site. in Alexandria, VA Our client seeks an experienced penetration testing professional to plan and execute comprehensive security assessments across applications, systems, and infrastructure in alignment...Hourly payFull timeContract workTemporary workLocal area2 days per week3 days per week
- Job Summary: The Penetration Testing Specialist / Information Security Analyst Journeyman is responsible for conducting thorough penetration... ...Testing) certification. GPEN (GIAC Penetration Tester) certification. Special Considerations: May require handling...Flexible hours
- ...Application Penetration Tester We are seeking a highly skilled and experienced Application Penetration Tester to join our dynamic team. This role is ideal for someone with a passion for cybersecurity, a deep understanding of application security, and the ability to...
- ...identifying candidates for the following position. Requisition Type:Full Time Position Status: Contingent Position Title: Penetration Tester Location:Arlington, VA Security Clearance:Secret Duties and Responsibilities The Penetration Testersupports...Full timeFor contractors
- ...Description Penetration Tester Xcelerate Solutions is seeking a Penetration Tester to support CyberPRIMES cybersecurity, privacy, records and information management, and related enterprise support for DHRA, including DMDC and OUSD(P&R). Come join our award-winning...
- ...Penetration Tester Locations: Los Angeles (CA), Dallas (TX), Washington DC. Responsibilities: Assist in project scoping and SOW creation Perform offensive engagements including red teaming and penetration testing Perform penetration tests against external...Work experience placement
- ...The Judge Group is currently seeking a Penetration Tester with an active secret clearance to support a classified customer in Beltsville, MD. This position is onsite five days per week. Core Requirements Active Security Clearance Federal Contracting...
$126.3k - $243.1k
..., industry training and more. Join us to drive positive, lasting change that moves missions and the government forward! Penetration Tester Overview We are seeking a Penetration Tester to design, coordinate, and execute a modern, scalable penetration‑testing...For contractorsLive inWork at officeLocal area$126.3k - $243.1k
...Penetration Tester At Accenture Federal Services, nothing matters more than helping the US federal government make the nation stronger and safer and life better for people. Our 13,000+ people are united in a shared purpose to pursue the limitless potential of technology...For contractors- ...Penetration Tester Alexandria, VA GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and...For contractorsRemote workFlexible hours
$95.86k - $208.27k
...expand your capabilities, then consider a career in Advisory. KPMG is currently seeking a Senior Specialist, MAST Application Penetration Tester to join our Managed Services practice. Responsibilities: Conduct manual application penetration testing against API'...H1bLocal area$115k - $203k
...Senior Penetration Tester Job Description Overview CoStar Group is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces. Included in the S&P 500 Index, CoStar Group is on a mission to digitize the...Hourly payFull timeWork at officeWork from homeMonday to Thursday- ...Description Tharros is seeking a Senior Penetration Testing, Software Assurance and Vulnerability Assessment Engineer to support a DHS Intelligence and Analysis cybersecurity program in the National Capital Region. This role will support advanced penetration...
- ...primary responsibility will be to plan, execute, and report on penetration tests targeting high-impact applications, platforms, services,... ...peer reviews of penetration test reports and mentoring junior testers. ~ Continuous learner who keeps up with the latest offensive...Remote work
$66k - $106k
...Jr. Cyber Penetration Tester Job Locations US-VA-Arlington Requisition ID 2026-169099 Position Category Cyber Security Clearance Secret Responsibilities Peraton is currently seeking a Jr Cyber Penetration Tester...Contract workLocal areaRemote workShift work$139.78k
...Koniag Data Solutions, LLC, a Koniag Government Services company , is seeking a Penetration Testers - Senior (Lead) to support KDS and our government customer in Washington, DC. This position requires the candidate to be able to obtain a Public Trust. We offer competitive...Local areaFlexible hours$117k - $147.7k
...findings, discuss remediation concepts, develop PoCs for vulnerabilities, use scripting/coding techniques, proficiently execute common penetration testing tools, triage, and support incidents, and produce high value findingsExperience performing manual web application...Full timeWork at officeShift workDay shift- DescriptionSAIC is seeking a highly skilled Senior Vulnerability Analyst with a strong technical background to join our team in support of a critical US government agency in the National Capital Region. This is an exciting opportunity to work with a team responsible for...2 days per week
$104.8k - $192.2k
...wherever you want it to go. Join EY and help to build a better working world.Government and Public Sector - Cybersecurity - Penetration Tester - Senior ConsultantFrom strategy to execution, the Government & Public Sector practice (“GPS”) of Ernst & Young provides a full...For contractorsSummer holidayWork at officeLocal areaFlexible hours- ...solutions to government entities to deliver predictable, measurable impact for the American taxpayer and consumer. The Integration Tester is responsible for validating and testing integrations across Amazon Connect, AWS Bedrock, Amazon Kinesis, Salesforce, Verint, and...Local area
- ...Integration Tester The Integration Tester plays a critical role in ensuring the stability, accuracy, and reliability of Navy Mutual's enterprise applications and system integrations. This position is responsible for designing, executing, and continuously improving...
- ...Penetration Tester We are seeking a highly skilled and proactive Penetration Tester to join our cybersecurity team. In this role, you will identify vulnerabilities and test the security of networks, applications, and systems by simulating real-world attacks. You will...Temporary workFor contractorsImmediate startFlexible hours
$70k - $90k
Vulnerability Analyst Job Locations US-MD-Bethesda ID 2026-4752 Category Information Technology Type Full Time Overview **Due to certain contracts and nature of the work, US Citizenship is required." We are seeking...Full timeInternshipRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Penetration Tester. Be the first to apply!


