Lead Penetration Tester
Work mode: Hybrid · Location: Virginia, United States · Schedule: Full Time.
Job Description
Job Title: Lead Penetration Tester
Duration: 3 Months
Location: Richmond, VA
Work Module: Hybrid
Position Summary
The Lead Penetration Tester will direct and perform the authorized gray-box penetration testing activities. The role covers targeted external exposure testing, internal assumed-breach testing, credential and access-path validation, TOC reachability testing, controlled adversarial scenarios, and attack-path analysis.
This individual will work closely with the Network Security Engineer and OT Security Specialist to ensure that testing is technically thorough without affecting traffic operations, OT availability, or public safety.
Job Description
- Support development of the technical testing methodology and Rules of Engagement.
- Confirm approved targets, test accounts, starting points, testing windows, prohibited techniques, and stop conditions before testing begins.
- Conduct targeted discovery and enumeration of approved external OT-associated IP addresses and Azure-facing endpoints.
- Identify externally exposed services, access points, authentication mechanisms, and potential attack paths.
- Perform controlled exploitation of approved public-facing systems and services.
- Conduct internal testing from -provided OT VDI, workstation, field-laptop, or equivalent approved starting points.
- Evaluate credential exposure, credential reuse, local protections, host hardening, trust relationships, and access controls.
- Assess whether an approved internal starting point can be used to reach in-scope TOC, DMZ, remote-access, or OT resources.
- Evaluate whether testing activities generate the expected logs, alerts, analyst actions, and escalation activities .
- Coordinate exploitation activity with the OT Security Specialist before interacting with operational systems.
- Avoid denial-of-service testing, credential spraying, persistence installation, PLC logic changes, firmware changes, and other prohibited actions.
- Stop testing immediately if operational instability, unsafe conditions, or unintended access is identified.
- Document affected assets, timestamps, tools used, proof of exploitation, attack paths, and reproducible validation steps.
- Assign CVSS scores and map relevant adversary behavior to MITRE ATT&CK or MITRE ATT&CK for ICS.
- Develop practical remediation recommendations and identify opportunities to improve detection, logging, triage, and escalation.
- Lead the preparation of external, internal, and consolidated penetration testing findings.
- Support the final debrief and retesting of remediated Critical and High findings.
Required Skills
- External and internal penetration testing
- Gray-box security assessment
- Ethical hacking and controlled exploitation
- Assumed-breach testing
- Attack-path development and validation
- Credential exposure and credential-reuse testing
- Host and application service enumeration
- Windows and Linux security assessment
- Active Directory security fundamentals
- Remote-access and VPN security testing
- Evidence collection and chain-of-custody practices
- Vulnerability validation and CVSS scoring
- MITRE ATT&CK and MITRE ATT&CK for ICS mapping
- Technical report writing and remediation development
- Safe penetration testing in operationally sensitive environments
Required Experience
- Minimum five years of penetration testing, ethical hacking, or offensive security experience
- Demonstrated experience performing external and internal penetration tests
- Experience validating multi-stage attack paths rather than relying only on automated vulnerability scans
- Experience conducting authenticated testing using approved accounts
- Experience working under formal Rules of Engagement and defined stop-work procedures
- Experience producing repeatable evidence and defensible technical findings
- Experience presenting technical findings to security teams, system owners, and leadership
Desired Experience
- OT or ICS penetration testing experience
- Experience testing segmented networks that follow the Purdue Model
- Experience working with SOC teams during controlled adversarial exercises
- Experience assessing Azure-hosted boundary or DMZ environments
- Experience supporting government or critical infrastructure clients
- Familiarity with NIST SP 800-82, NIST SP 800-53, CIS Controls, SEC530, SEC520, and SEC502
Desired Certifications
- Offensive Security Certified Professional, OSCP
- Certified Ethical Hacker, CEH
- CompTIA Security+
- Equivalent penetration testing certifications may be presented where they demonstrate comparable technical capability.