> Markdown version of [/jobs/ext/3041319-penetration-tester](https://www.wearedevelopers.com/jobs/ext/3041319-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Penetration Tester - **Company:** vTech Solution Inc - **Location:** Richmond, VA, United States - **Experience:** Expert - **Contract:** Temporary to permanent - **Skills:** Software System Penetration Testing, Monitoring of Systems, Mitre Att&ck - **Published:** September 23, 2026 - **Apply:** https://www.careerjet.com/jobad/us844d56b343c6a0b51043b8ea494790ae ## About the Role * Ethical hacking expertise. * Experience with OT security testing. * Proficiency in internal and external penetration testing. * Adversary simulation capabilities. * Vulnerability exploitation and assessment skills. * Certifications such as CEH, OSCP, and Security+. * Minimum of 5 years of relevant experience. Preferred Skills & Certifications: * Familiarity with MITRE ATT&CK framework for ICS. * Experience with SOC validation and monitoring tools. ## Description The Lead Penetration Tester will spearhead both external and internal penetration testing initiatives, focusing on operational technology (OT) infrastructure and adversary simulation exercises. This role involves assessing security postures, validating exploit techniques, and enhancing detection and response capabilities within hybrid environments. Responsibilities: * Lead external and internal penetration testing activities. * Perform gray-box security assessments of OT infrastructure. * Execute adversary simulations and exploit validation. * Assess externally exposed services, authentication mechanisms, and attack paths. * Perform lateral movement and privilege escalation testing. * Validate SOC detection, monitoring, and response capabilities. * Document findings, proof-of-concepts, attack paths, and remediation recommendations. * Map findings to MITRE ATT&CK for ICS and industry security frameworks. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Hacking Kubernetes: Live Demo Marathon](https://www.wearedevelopers.com/videos/488-hacking-kubernetes-live-demo-marathon) - [APItoolkit: Using Merkle Trees and LLMs to Detect the UnDetectable in Software Monitoring](https://www.wearedevelopers.com/videos/1639-apitoolkit-using-merkle-trees-and-llms-to-detect-the-undetectable-in-software-monitoring) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [It's a (testing) trap! - Common testing pitfalls and how to solve them](https://www.wearedevelopers.com/videos/1193-it-s-a-testing-trap-common-testing-pitfalls-and-how-to-solve-them) - [System Resilience: Surviving the Software Storm](https://www.wearedevelopers.com/videos/874-system-resilience-surviving-the-software-storm) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)