CybersecurityJobs.io
← Back to all jobs

Job Description

OneZero Solutions is hiring a Journeyman-level Cyber Security Engineer focused on penetration testing and adversary emulation in a hybrid role based in Washington, DC, supporting the U.S. Coast Guard in Alexandria, VA. You will help strengthen operational cyber defenses through hands-on offensive testing, threat emulation, and clear reporting that drives actionable recommendations.

What you will do

  • Assess the cyber security posture of Coast Guard operational networks through adversary emulation.
  • Conduct red team operations, internal and external penetration testing, and phishing assessments.
  • Perform cyber threat emulation during scripted exercises to train DoD Cyber Protection Teams.
  • Deploy, configure, and operate Command and Control (C2) frameworks such as Cobalt Strike, Havoc, Mythic, and Sliver.
  • Apply TTPs for initial access, lateral movement, privilege escalation, persistence, and data exfiltration.
  • Leverage proprietary and open-source offensive security tool sets to achieve engagement objectives.
  • Monitor, manage, and maintain cloud and on-premise infrastructure used during assessments.
  • Use Git repositories to maintain operational tools and scripts.
  • Perform network mapping and enumeration, including Active Directory attack path analysis using tools such as BloodHound.
  • Assess web and mobile applications and perform database scans.
  • Develop reports and briefs that document findings and recommendations for completed assessments.

Clearance and security requirements

  • Maintain an active Top Secret security clearance with SCI eligibility.

Required skills and experience

  • 2 to 3 years of relevant experience (or a Bachelor’s degree in BA/BS or equivalent years of relevant experience).
  • Hands-on experience with computers and network security.
  • Experience conducting phishing campaigns or social engineering.
  • Hands-on experience with red team tasks and penetration testing.
  • Familiarity with malware development and EDR/AV bypass strategies.
  • Experience with PowerShell, C, C++, or Python.
  • Hands-on experience using C2 frameworks such as Cobalt Strike, Sliver, Havoc, or similar.

Benefits and support

  • Health insurance
  • Dental insurance
  • Vision insurance
  • Life insurance
  • 401(k) with company matching
  • Paid time off and holidays
  • Employee referral program
  • Educational assistance

Tools and technologies you may use

  • Cobalt Strike, Havoc, Mythic, Sliver
  • Git, BloodHound
  • PowerShell, C, C++, Python
  • EDR/AV

Certifications

  • Must hold a DoD 8570/8140-compliant Information Assurance Technical (IAT) Level II or Level III certification, along with an offensive security certification.
  • Offensive Security Certification (any one): GIAC Penetration Tester (GPEN); Red Team Apprentice Course (RTAC); or equivalent.
  • IAT Level II options: CompTIA Security+ CE; CompTIA CySA+ ; CCNA Security; GICSP; GSEC; SSCP.
  • IAT Level III options: CompTIA CASP+ CE (SecurityX); CISSP (or Associate); CISA; CCNP Security; GCED; GCIH.

Preferred qualifications

  • Experience supporting Red Team or offensive cybersecurity operations.
  • Experience with web application, network, wireless, cloud, or infrastructure penetration testing.
  • Familiarity with tools such as Nmap, Burp Suite, Metasploit, BloodHound, Wireshark, or similar security testing tools.
  • Knowledge of common attack frameworks and methodologies, including MITRE ATT&CK.
  • Experience developing penetration testing reports and presenting technical findings.
  • Active industry-recognized cybersecurity certifications such as OSCP, CEH, PenTest+, GPEN, or comparable certifications.

Similar Jobs