Enterprise Cybersecurity Penetration Tester
Job Description
Booz Allen Hamilton offers a hands-on role with its internal Red Team, combining enterprise penetration testing with opportunities to share knowledge and support real-world remediation. You will work onsite in McLean, VA, helping evaluate security posture across enterprise networks, applications, endpoints, and cloud environments while partnering with offensive security reporting and consulting teams.
Compensation: The projected annual salary range is USD 62,000 - 141,000. Final offers are based on location, education, skills, competencies, experience, and contract or organizational requirements.
What you’ll do
- Execute enterprise and system-focused network and penetration assessments.
- Identify security risks across applications, controls, and infrastructure.
- Collaborate with offensive security reporting teams on findings and analysis.
- Partner with consulting teams to deliver security solutions and support enterprise cybersecurity efforts.
- Evaluate established rules of engagement and system penetration testing requirements.
- Document findings, support remediation efforts, and help promote an environment of innovation and knowledge sharing.
- Communicate technical security concepts to both technical and non-technical stakeholders.
- Contribute to security research and promote knowledge sharing across the team.
This is a fast-paced, technical role focused on evaluating security posture, producing high-quality documentation, and collaborating closely with offensive security reporting and consulting partners to deliver actionable security analysis.
What you bring
- Experience with vulnerability enumeration and exploitation frameworks, including Burp Suite Pro and Metasploit.
- Knowledge of foundational techniques for vulnerability discovery, enumeration, exploitation, and post-exploitation.
- Ability to write technical findings into high-quality assessment reports.
- Ability to effectively communicate with clients, teammates, and senior leadership.
- Bachelor’s degree.
- One or more offensive security certifications: OSCP, OSWA, OSEP, OSEE, PNPT, CRTO, GPEN, GWAPT, GCPN, GXPN, or Offensive Security Certification.
Tools and environments
- Burp Suite Pro, Metasploit
- Python, Golang
- Active Directory, Azure, Amazon Web Services
Benefits
- Health, life, disability, financial, and retirement benefits
- Paid leave
- Professional development
- Tuition assistance
- Work-life programs
- Dependent care
- Recognition awards program
Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs.
Additional details
- Work model: Onsite (primarily full-time at a customer facility with direct collaboration as required).
- Citizenship requirement: Due to the nature of work performed within this facility, U.S. citizenship is required.
- Closing timeline: This posting will close within 90 days from the posting date.
Identity and interview policy
- During the hiring process, you will be asked to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud.
- You are expected to be on camera during interviews and assessments; Booz Allen reserves the right to take your picture to verify your identity and prevent fraud.
- Candidate AI usage policy: The use of AI or other tools to assist with responses during interviews is prohibited unless permission is explicitly provided.
Non-discrimination
All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran, or any other status protected by applicable federal, state, local, or international law.