> Markdown version of [/jobs/ext/2419242-penetration-tester-journeyman](https://www.wearedevelopers.com/jobs/ext/2419242-penetration-tester-journeyman). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Penetration Tester Journeyman - **Company:** OneZero Solutions - **Location:** Alexandria, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** C (Programming Language), Active Directory, Software System Penetration Testing, C++ (Programming Language), Cyber Security, Databases, Desktop Computing, Mobile Application Software, Python (Programming Language), Network Security, Open Source Technology, Windows PowerShell, Phishing, Red Team (Cyber Security), Software Repository, Malware, Hardware Infrastructure - **Published:** August 3, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9119572/penetration-tester-journeyman ## About the Role Relevant Years of Experience: 5+ Hands on experience with computers and network security. Experience conducting phishing campaigns or social engineering. Hands on experience with red team tasks and pen testing. Familiarity with malware development and EDR/AV bypass strategies. Experience with PowerShell, C, C++, or Python. Hands on experience utilizing Command and Control (C2) Frameworks such as Cobalt Strike, Sliver, Havoc, etc. Certifications: IAT II or IAT III GPEN, Red Team Apprentice Course (RTAC), or equivalent Education: BA/BS or equivalent years of relevant experience ## Description Adversary Simulation: Deploy, configure, and operate C2 frameworks such as Cobalt Strike, Havoc, Mythic, and Sliver. Apply TTPs for initial access, lateral movement, privilege escalation, persistence and data exfiltration. Leverage proprietary and open-source offensive security tool sets effectively to achieve engagement objectives. Execute phishing assessments. Infrastructure: Monitor, manage, and maintain cloud and on-premise infrastructure used during assessments. Understanding the use of Git Repositories for maintaining operational tools and scripts. Penetration Testing: Internal and external penetration testing. Network mapping and enumeration. Assess web and mobile applications. Perform database scans. Assess Active Directory attack paths using tools such as BloodHound. Security Assessments: Assessing Coast Guard's cyber security posture of operational networks through adversary emulation. Develop reports and briefs detailing findings and recommendations for all assessments completed. Perform cyber threat emulation during scripted exercises, to train DoD Cyber Protection Teams ## Related Videos - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 182: GPT5 Prompts, MCP Vulnerabilities, Code Traps](https://www.wearedevelopers.com/magazine/622-dev-digest-182-gpt5-prompts-mcp-vulnerabilities-code-traps)