> Markdown version of [/jobs/ext/3278985-enterprise-cybersecurity-penetration-tester](https://www.wearedevelopers.com/jobs/ext/3278985-enterprise-cybersecurity-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Enterprise Cybersecurity Penetration Tester - **Company:** Booz Allen Hamilton Inc. - **Location:** McLean, VA, United States - **Experience:** Experienced - **Salary:** $86,800.0 - $198,000.0 - **Contract:** Permanent contract - **Skills:** Active Directory, Application Programming Interfaces (APIs), Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Burp Suite, Cyber Security, Computer Networks, Data Security, Emulators, Network Architecture, Red Team (Cyber Security), Web Applications, Scripting, Cloud Platform System, GWAPT, Metasploit - **Published:** September 30, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88481536/1 ## About the Role * 2+ years of experience with penetration testing and red teaming * Experience with vulnerability enumeration and exploitation frameworks, including Burp Suite Pro, Metasploit, Cobalt Strike, Armitage, or PowerSploit * Knowledge of vulnerability discovery, enumeration, exploitation, and post-exploitation foundational techniques * Ability to write technical findings into high-quality assessment reports and effectively communicate with clients and teammates * Ability to lead organized security testing engagements on a team * Bachelor's degree * OSCP, OSWA, OSEP, OSEE, PNPT, CRTO, GPEN, GWAPT, GCPN, GXPN, or Offensive Security Certification Nice If You Have: * Experience with covert computer network exploitation or adversary emulation * Experience exploiting Active Directory, Azure, and Amazon Web Services * Knowledge of scripting languages, API functionality, and data access methodologies * Ability to operate in a fast-paced work environment, multitask, and handle delivery deadlines * Ability to clearly communicate technical details and vulnerability data to non-technical teammates and clients * Bachelor's degree in Information Security, Cybersecurity, or CS ## Description As a member of the Booz Allen internal Red Team, you'll lead enterprise and system-focused network and penetration assessments to identify security risks across applications, security controls, network infrastructure, applications, endpoints, cloud environments, identity services, IoT devices, and web applications. This role is responsible for conducting targeted security assessments within a fast-paced environment, collaborating with offensive security reporting teams, and partnering with consulting teams to deliver security analysis and solutions to Booz Allen's enterprise cybersecurity team. This is a hands-on technical role focused on evaluating security posture, documenting findings, supporting remediation efforts, and helping promote an environment of innovation and knowledge sharing.Due to the nature of work performed within this facility, U.S. citizenship is required. What You'll Work On: * Lead and execute enterprise and system-focused network and penetration assessments. * Identify security risks across applications, controls, and infrastructure. * Collaborate with offensive security reporting teams on findings and analysis. * Partner with consulting teams to deliver security solutions. * Evaluate established rules of engagement and system penetration testing requirements. * Communicate technical security concepts to both technical and non-technical stakeholders. * Contribute to security research and promote knowledge sharing across the team. ## Related Videos - [ The attacker's footprint](https://www.wearedevelopers.com/videos/375-the-attacker-s-footprint) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [WeAreDevelopers LIVE – Web Scraping, Agents, Actors and more](https://www.wearedevelopers.com/videos/1764-wearedevelopers-live-web-scraping-agents-actors-and-more) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)