Penetration Tester

vTech Solution Inc
Richmond, VA, United States
1 day ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Software System Penetration Testing Monitoring of Systems Mitre Att&ck

Job description

The Lead Penetration Tester will spearhead both external and internal penetration testing initiatives, focusing on operational technology (OT) infrastructure and adversary simulation exercises. This role involves assessing security postures, validating exploit techniques, and enhancing detection and response capabilities within hybrid environments. Responsibilities:

  • Lead external and internal penetration testing activities.
  • Perform gray-box security assessments of OT infrastructure.
  • Execute adversary simulations and exploit validation.
  • Assess externally exposed services, authentication mechanisms, and attack paths.
  • Perform lateral movement and privilege escalation testing.
  • Validate SOC detection, monitoring, and response capabilities.
  • Document findings, proof-of-concepts, attack paths, and remediation recommendations.
  • Map findings to MITRE ATT&CK for ICS and industry security frameworks.

Requirements

  • Ethical hacking expertise.
  • Experience with OT security testing.
  • Proficiency in internal and external penetration testing.
  • Adversary simulation capabilities.
  • Vulnerability exploitation and assessment skills.
  • Certifications such as CEH, OSCP, and Security+.
  • Minimum of 5 years of relevant experience.

Preferred Skills & Certifications:

  • Familiarity with MITRE ATT&CK framework for ICS.
  • Experience with SOC validation and monitoring tools.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

39 sec

Introducing Monoscope for intelligent post-deployment system monitoring

Anthony Alaribe Anthony Alaribe · World Congress 2025

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · World Congress 2023

1:51 min

Leveraging continuous penetration testing via red teams

Reto Kaeser · LIVE

2:59 min

Applying secure coding practices and proactive system monitoring

Mihaela-Roxana Ghidersa · LIVE

2:38 min

Tracking observability metrics to ensure healthy cluster performance

Kirill Kulikov · LIVE

Videos

See all

Related articles

See all