Senior Penetration Tester in at Crest Security Assurance
Explore Related Opportunities
Job Description
PENETRATION TESTER (Must be a US Citizen)
Crest Security Assurance is seeking an experienced Penetration Tester to support a federal cybersecurity program. This individual will serve as Key Personnel and lead the planning, coordination, execution, and reporting of enterprise penetration tests across agency systems, applications, and infrastructure.
The Penetration Tester will conduct sophisticated offensive security assessments, adversary emulation, red and purple team exercises, and breach-and-attack simulations designed to identify exploitable vulnerabilities and strengthen the agency's defensive capabilities. The ideal candidate combines deep hands-on technical expertise with strong documentation, communication, and stakeholder coordination skills.
Key Responsibilities
- Plan, coordinate, and execute adversarial-based internal, external, and web application penetration testing across enterprise networks, systems, applications, APIs, and cloud environments.
- Develop and maintain penetration testing CONOPS, SOPs, methodologies, test plans, Rules of Engagement (ROE), and supporting documentation aligned with NIST SP 800-115, MITRE ATT&CK, and OWASP standards.
- Coordinate with stakeholders to define assessment scope, objectives, target technologies, testing constraints, authorized TTPs, and success criteria.
- Conduct internal penetration testing using Nmap, Metasploit, Impacket, BloodHound, NetExec, and other tools to assess Active Directory, network segmentation, credential security, privilege escalation, and lateral movement.
- Perform external penetration testing using Nmap, Nessus, Nuclei, Metasploit, and reconnaissance techniques to identify exploitable vulnerabilities, exposed services, and potential attack paths.
- Execute web application and API penetration testing using Burp Suite, OWASP ZAP, SQLmap, and other tools to identify authentication, authorization, injection, session management, and OWASP Top 10 vulnerabilities.
- Conduct red team, blue team, and purple team exercises, adversary emulation, and breach-and-attack simulations using MITRE ATT&CK-aligned TTPs and tools such as MITRE CALDERA and Atomic Red Team.
- Execute authorized reconnaissance, enumeration, exploitation, credential attacks, privilege escalation, lateral movement, persistence simulation, and post-exploitation analysis to assess enterprise security resilience.
- Assess security controls, EDR, IDS/IPS, SIEM detection capabilities, SOC monitoring, and incident response effectiveness against simulated adversarial activity.
- Validate vulnerabilities through manual and automated testing, controlled exploitation, attack-path analysis, and proof-of-concept demonstrations.
- Document findings, technical evidence, exploitability, severity, mission impact, and recommended remediation; immediately escalate critical vulnerabilities.
- Conduct remediation verification, exploit retesting, patch validation, and post-engagement reviews to identify control gaps and improve defensive capabilities.
- Maintain penetration testing records, findings, remediation tracking, and deliverables while integrating results with vulnerability management, RMF, threat intelligence, and continuous monitoring.
- Prepare comprehensive technical and executive reports and present attack paths, risk implications, and corrective actions to Government stakeholders and leadership.
Minimum Qualifications
- U.S. citizenship and the ability to satisfy personnel-security requirements for a Non-Sensitive/High-Risk position.
- Bachelor of Science in Computer Science, Information Technology, Information Security, Cybersecurity, or a related field.
- Minimum of five years of experience conducting, supporting, or leading penetration tests.
- ·Demonstrated experience assessing enterprise networks, systems, applications, and security controls.
- Strong knowledge of Windows and Linux operating systems, network architecture, and common networking protocols.
- Demonstrated ability to identify, validate, and safely exploit security vulnerabilities.
- Knowledge of web application technologies, common attack methods, and application-security testing practices.
- Proficiency with industry-standard penetration-testing, vulnerability-assessment, and exploitation tools.
- Proficiency with one or more scripting or programming languages used to automate testing, analyze results, or develop custom assessment capabilities.
- Experience conducting adversary emulation, red team, or purple team exercises using threat-informed tactics, techniques, and procedures.
- Experience developing Rules of Engagement, test plans, assessment documentation, and technical penetration-testing reports.
- Ability to translate complex technical findings into clear, risk-based recommendations for technical and nontechnical stakeholders.
- Strong analytical, problem-solving, technical writing, and verbal communication skills
Preferred Qualifications
- Offensive Security Certified Professional (OSCP), Certified Ethical Hacker (CEH), or a comparable penetration-testing certification.
- Advanced offensive security certifications such as OSCE, OSEP, OSWE, GPEN, GWAPT, GXPN, or equivalent.
- Experience conducting penetration tests within federal government or other highly regulated environments.
- Experience applying NIST guidance and federal cybersecurity requirements to penetration-testing activities and reporting.
- Experience with APT simulation and threat-informed testing based on frameworks such as MITRE ATT&CK.
- Experience evaluating SOC detection and response capabilities in coordination with blue teams.
- Experience testing cloud, identity, web application, endpoint, and network environments.
- Experience presenting findings and remediation priorities to C-suite, executive, or senior government leadership.