Penetration Tester
Job Description
Northrop Grumman Mission Systems is seeking a cybersecurity professional to support cyber protection through penetration testing and security assessment activities in San Antonio, TX (onsite). The role focuses on evaluating system cybersecurity requirements and conducting cloud-oriented offensive security work.
Key Responsibilities
- Perform cloud-focused penetration testing and security assessments to identify vulnerabilities, attack paths, and potential threat vectors across cloud-native and hybrid environments.
- Support offensive security operations against cloud infrastructure, CI/CD pipelines, containerized workloads, applications, and enterprise services across AWS, Azure, and related platforms.
- Assist in developing attack methodologies, testing procedures, and technical analysis while collaborating with senior operators and engineers.
- Use cybersecurity expertise to evaluate cloud security posture, validate security controls, and contribute to technical reporting, operational recommendations, and remediation guidance.
Required Qualifications
- Education and experience: A Bachelor’s Degree with 2 years of related experience, or a Master’s degree with 0 years of related experience. 6 years of related experience may be considered in lieu of degree.
- US Citizenship is required.
- An Active US Government Top Secret Security Clearance is required, with the ability to obtain SCI.
- Ability to possess or obtain a DoD 8570 IAT Level II or higher certification prior to start (examples listed: Sec+, CCNA, CySA+, or CND).
- Experience conducting penetration testing, vulnerability analysis, or security assessments.
- Experience or familiarity with containerization and virtualization technologies such as Docker, Kubernetes, or VMware.
- Knowledge of Windows and Linux, networking fundamentals, and common enterprise architecture.
- Experience using scripting or automation languages such as Python, Bash, or PowerShell to support testing, analysis, or operational workflows.
- Familiarity with offensive security methodologies, vulnerability management processes, and common attacker TTPs.
Preferred Qualifications
- Experience with cloud platforms such as AWS and Azure, including familiarity with IAM, networking, storage, logging, and security services.
- Familiarity with CI/CD pipeline technologies and concepts, including GitHub Actions, GitLab CI/CD, Jenkins, Azure DevOps, or similar platforms.
- Ability to analyze technical findings and contribute to assessment reports, presentations, and client deliverables, including communicating findings to technical and non-technical stakeholders.
- Experience assessing cloud-native technologies, including Kubernetes, containers, serverless functions, or Infrastructure-as-Code deployments.
- Familiarity with cloud security assessment tools, vulnerability scanners, and offensive security frameworks.
- Familiarity with Infrastructure-as-Code tools such as Terraform, Ansible, ARM templates, or CloudFormation.
- Experience with logging, monitoring, and detection technologies such as Splunk, Sentinel, ELK, Defender, or CrowdStrike.
- Familiarity with RMF, A&A activities, STIGs, SCAP, ACAS, or cybersecurity compliance frameworks.
- Ability to rapidly learn emerging technologies, cloud attack methodologies, and evolving threat landscapes.
- Relevant certifications preferred, including AWS Security Specialty, Azure Security Engineer Associate, PenTest+, CySA+, CEH, AZ-500, SC-200, CRTO, GPEN, GXPN, OSCP, or similar cybersecurity certifications.
Technology Stack
- Cloud and platforms: AWS, Azure, AWS Security Specialty, Azure Security Engineer Associate
- Containers and virtualization: Docker, Kubernetes, VMware
- Operating systems: Windows, Linux
- Scripting and automation: Python, Bash, PowerShell
- CI/CD and tooling: CI/CD, GitHub Actions, GitLab CI/CD, Jenkins, Azure DevOps
- Infrastructure as Code: Terraform, Ansible, ARM templates, CloudFormation
- Security monitoring and detection: Splunk, Sentinel, ELK, Defender, CrowdStrike
- Compliance and assessment: RMF, STIGs, SCAP, ACAS
- Certifications referenced: Sec+, CCNA, CySA+, CND, PenTest+, CEH, AZ-500, SC-200, CRTO, GPEN, GXPN, OSCP
Compensation
Salary range: USD 83,400 - 125,200 per year.
Primary level salary range: $83,400.00 - $125,200.00.
Benefits
- Health insurance coverage
- Life and disability insurance
- Savings plan
- Company paid holidays
- Paid time off (PTO) for vacation and/or personal business
- Depending on the position, eligibility for overtime, shift differential, and a discretionary bonus in addition to base pay
- Annual bonuses
- Employees in Vice President or Director positions may be eligible for Long Term Incentives
Relocation, Travel, and Clearance
- Relocation assistance: may be available
- Travel: Yes, 10% of the time
- Clearance required for start: Yes
- Clearance type: Top Secret (with ability to obtain SCI)
Work Setting and Additional Details
- Location: San Antonio, TX (onsite)
- Minimum experience: 2 years
- Estimated application period: 20 days from the job posting date
- Equal Opportunity Employer: making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class.