Penetration Tester
Job Description
Dark Wolf Solutions is seeking an experienced Penetration Tester to help evaluate and improve the security posture of hardware, software, and embedded systems. This hybrid role supports assessment activities across the DC Metro area, covering web, wireless/RF, and network environments, along with hands-on vulnerability validation and reporting.
What you’ll do
- Run comprehensive penetration testing across hardware, software, and network components.
- Perform advanced vulnerability scanning and assessments across all relevant system components.
- Conduct cybersecurity evaluations of the product under test to identify weaknesses that could impact Confidentiality, Integrity, or Availability of data or system functionality.
- Analyze software, firmware, hardware, and/or RF elements to uncover security weaknesses.
- Assess potential impact and approximate effort required for exploitation, and provide a high-level remediation strategy.
- Develop and execute exploits and proof-of-concept (PoC) attacks to demonstrate vulnerability impact.
- Perform firmware and embedded system reverse engineering to identify security gaps.
- Test and assess secure boot processes and Trusted Execution Environments (TEE).
- Carry out web application security assessments, with focus on OWASP Top Ten and API security testing.
- Verify findings manually, including risk and exploitability evaluation.
- Lead wireless and RF security testing, including penetration testing on Wi-Fi, Bluetooth, and Zigbee networks.
- Use Software Defined Radio (SDR) for protocol reverse engineering and testing.
- Produce detailed reporting: document case details, provide actionable remediation recommendations, and summarize outcomes based on system analysis.
- Plan and execute cross-domain assessments that may include network penetration testing and phishing/social engineering campaigns.
What you bring
- A Bachelor’s degree in Cybersecurity, Information Technology, Computer Engineering, or a related field.
- 2+ years of experience in three or more areas such as intelligence analysis, network engineering, networking security, penetration testing, red team operations, hardware engineering, software engineering, exploit development, reverse engineering, vulnerability assessment, physical security assessments, or social engineering.
- Proficiency with cloud technology and deployments across AWS, Microsoft Azure, and Google Cloud Platform (GCP).
- Experience testing and assessing mobile operating systems, embedded systems, and/or IoT devices.
- Experience drafting reports, documenting case details, and summarizing findings and recommendations from system analysis.
- Experience conducting advanced vulnerability scanning and assessments across all components.
- Experience performing web application security assessments focused on OWASP Top Ten and API security testing.
- Demonstrated strong written and verbal communication skills.
- Strong understanding of NIST 800-53 frameworks.
- US Citizenship and an active security clearance at a minimum of the Secret level.
Technologies and focus areas
- Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (GCP)
- OWASP Top Ten and API security testing
- NIST 800-53, Secure boot, Trusted Execution Environments (TEE)
- Software Defined Radio (SDR), Wi-Fi, Bluetooth, Zigbee
Location and compensation
- Herndon, VA (hybrid)
- Salary range: USD 130,000 - 145,000 per year, commensurate with experience and technical skillset
- Potential for 1099 hourly opportunity
Additional desired qualifications
- Familiarity with NIST 800-171 Revision 2
- Proven ability to develop and execute complex exploits and PoC attacks
- Strong analytical skills and experience in firmware, binary exploitation, and embedded systems testing
- Advanced knowledge of SDR and protocol reverse engineering
- Active professional certifications such as CEH, OSCP, PNPT, GPEN, or similar security/pen testing certifications