Penetration Tester Journeyman

OneZero Solutions
Alexandria, VA, United States
about 1 month ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

C (Programming Language) Active Directory Software System Penetration Testing C++ (Programming Language) Cyber Security Databases Desktop Computing Mobile Application Software Python (Programming Language) Network Security Open Source Technology Windows PowerShell
+5 more
Phishing Red Team (Cyber Security) Software Repository Malware Hardware Infrastructure

Job description

Adversary Simulation:

Deploy, configure, and operate C2 frameworks such as Cobalt Strike, Havoc, Mythic, and Sliver. Apply TTPs for initial access, lateral movement, privilege escalation, persistence and data exfiltration. Leverage proprietary and open-source offensive security tool sets effectively to achieve engagement objectives. Execute phishing assessments. Infrastructure:

Monitor, manage, and maintain cloud and on-premise infrastructure used during assessments. Understanding the use of Git Repositories for maintaining operational tools and scripts. Penetration Testing:

Internal and external penetration testing. Network mapping and enumeration. Assess web and mobile applications. Perform database scans. Assess Active Directory attack paths using tools such as BloodHound. Security Assessments:

Assessing Coast Guard’s cyber security posture of operational networks through adversary emulation. Develop reports and briefs detailing findings and recommendations for all assessments completed. Perform cyber threat emulation during scripted exercises, to train DoD Cyber Protection Teams

Requirements

Relevant Years of Experience: 5+ Hands on experience with computers and network security. Experience conducting phishing campaigns or social engineering. Hands on experience with red team tasks and pen testing. Familiarity with malware development and EDR/AV bypass strategies. Experience with PowerShell, C, C++, or Python. Hands on experience utilizing Command and Control (C2) Frameworks such as Cobalt Strike, Sliver, Havoc, etc. Certifications:

IAT II or IAT III GPEN, Red Team Apprentice Course (RTAC), or equivalent Education: BA/BS or equivalent years of relevant experience

Benefits & conditions

We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. OneZero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance. Additional details are available on our website: https://www.onezerollc.com/careers

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

51 sec

Exploring offensive security with red team tooling

Stefania Chaplin · World Congress 2022

6:01 min

Handling container constraints and fileless malware

Dimitrij Klesev +1 · LIVE

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · World Congress 2023

6:18 min

Architecting asynchronous malware scanning for uploaded file contents

Austin Gil · LIVE

Videos

See all

Related articles

See all