- Company Name
- Peraton
- Job Title
- Penetration Tester
- Job Description
-
**Job Title:** Cyber Penetration Tester
**Role Summary:**
Lead and execute penetration tests for federal cybersecurity programs. Assess customer systems, identify security weaknesses, develop remediation recommendations, and report findings to stakeholders while maintaining the Red Cell testing environment.
**Expectations:**
- U.S. citizenship; active Secret clearance required with potential for Top Secret.
- Minimum 5 years of Cyber/IT experience (or 3 years with a Master’s; or 4 years with equivalent security/pen‑test experience).
- At least 2 years of dedicated penetration testing experience.
- Ability to obtain or hold relevant industry certifications before start.
**Key Responsibilities:**
- Plan, conduct, and lead penetration tests on customer networks and applications.
- Identify vulnerabilities and produce remediation plans aligned with NIST 800‑53 controls.
- Report findings to system owners and engineering teams, providing actionable guidance.
- Maintain and update Red Cell infrastructure and test tools.
- Develop or modify automation tools for discovery or exploitation tasks.
- Mentor and direct junior penetration testers.
- Conduct root‑cause analysis, vulnerability assessments, and detailed reporting using frameworks such as NIST SP 800‑115, PTES, ISSAF, and OWASP WSTG.
**Required Skills:**
- Proficient in Kali Linux, Kali‑based toolsets, and penetration testing methodologies.
- Hands‑on experience with Nmap, Burp Suite, Metasploit, and analogous tools.
- Strong scripting/programming in Bash, Python, PowerShell, and JavaScript.
- Deep understanding of networking concepts: IP routing, TCP/UDP, VPNs, firewalls, NAT, and protocols (SSH, FTP, HTTP, SMTP, SMB).
- Operating system security fundamentals, file systems, process and device management.
- Knowledge of web application security: XSS, SQLi, LFI, file upload, broken authentication, etc.
- Active Directory enumeration/attack techniques (kerberoasting, AS‑REP roasting, golden tickets).
- Public Key Infrastructure (PKI) fundamentals and common cryptographic concepts.
**Required Education & Certifications:**
- Bachelor of Science in Cyber/IT or equivalent, with 5+ years of experience; or
- Master of Science in Cyber/IT with 3+ years of relevant experience; or
- 4+ years of hands‑on IT security or penetration testing experience.
**Certifications (minimum one required):**
- CCNA Cyber Ops / CCNA‑Security
- CEH, CFR, Cloud+, CySA+, GCIA, GCIH, GICSP, SCYBER, Security+ CE, SSCP
**Preferred Certifications:**
- CompTIA CASP+
- CISSP, CCSP, ISSEP (ISC²)
- OSCP, CPTS, PNPT, GXPN, Zero Point Security Red Team Ops II
(Only the minimum certification list is mandatory; the preferred list is optional.)