Network Security Specialist II (Penetration Tester / Red Team)
Role details
Job location
Tech stack
Job description
We are seeking a Network Security Specialist II (Penetration Tester / Red Team Operator) to support a secure Research, Development, Test & Evaluation (RDT&E) environment within a DoD network. This role focuses on offensive cybersecurity operations, vulnerability assessment, and penetration testing to strengthen enterprise network defense capabilities., * Conduct penetration testing against web applications, systems, and network infrastructure using tools such as Burp Suite
- Perform Red Team activities to identify vulnerabilities across enterprise environments
- Develop and execute proof-of-concept (POC) exploits to validate potential vulnerabilities
- Conduct vulnerability enumeration and support remediation efforts
- Ensure signature-based scanning tools and security assessment platforms are operational
- Draft and review Standard Operating Procedures (SOPs) and technical documentation
- Support compliance with DoD STIGs and cybersecurity best practices
- Analyze system configurations, network traffic, and infrastructure security posture
Requirements
The ideal candidate has hands-on experience with Red Team activities, vulnerability enumeration, Linux systems, scripting, and DoD security compliance frameworks (STIGs, ACAS)., * Active Secret clearance
- IAT Level II Certification (Security+, CySA+, GSEC, GICSP, CND, SSCP, or equivalent)
- MCSA, Linux+, or equivalent operating system certification (or equivalent training)
- 4+ years of relevant cybersecurity or network security experience
- Experience as a System Administrator or Network Administrator
- Knowledge of core Linux systems and command-line operations
- Experience with vulnerability scanning, enumeration, and remediation
- Familiarity with DoD STIG implementation and compliance
- Scripting experience (PowerShell, Bash, or Python preferred)
- Experience working with virtual machines (vSphere, VirtualBox, KVM, QEMU), * Experience with Burp Suite and related web application security tools
- ACAS suite management, installation, troubleshooting, and upkeep
- Experience with Kali Linux tools (nmap, tcpdump, Wireshark)
- Understanding of web technologies and HTML structure
- Knowledge of OSI model and network traffic flow analysis
- Experience with Windows Server (Active Directory, Domain Controllers, GPO, SCCM, DISM)
- Intermediate to advanced knowledge of network configuration (switches and routers)
- Basic vulnerability research and exploitation experience
- Exposure to cloud infrastructure security
- Penetration testing and Red Team engagement experience