CybersecurityJobs.io
← Back to all jobs

Job Description

Tharros is seeking a Penetration Tester to support the US Navy’s operational test and evaluation mission. This onsite role in Norfolk, VA focuses on building and executing cyber test plans across operational systems, lab environments, and cyber ranges, with reporting that feeds into the OPTEVFOR cyber OT&E mission. If you have hands-on offensive testing experience and enjoy structured, policy-driven test execution, this position offers a direct path to apply real-world penetration testing in support of operational evaluation.

Responsibilities

  • Review and build proficiency in OPTEVFOR cyber T&E concept of operations, SOPs, policies, and guidance.
  • Maintain and participate in the development of 01D SOPs and documentation for DCAT authorization established in DoDI 8585.01.
  • Research, review, prioritize, and submit operational requirements for acquisition of equipment or cyber capabilities using the 01D tool approval process.
  • Support development and execution of TTPs for penetration testing and Red Teaming.
  • Research adversary cyber actors’ TTPs, organizational structures, capabilities, personas, and environments, and integrate findings into cyber survivability test planning and execution.
  • Participate in OPTEVFOR cyber test planning, including:
    • Open-source research and system-under-test documentation review to identify attack surface and threat vectors.
    • Check point meetings, test plan objective development, and feasibility review of test plan objectives.
    • Test planning site visits and site pre-test coordination visits, including in-brief support.
  • Support test preparation activities, including red team test plan review and adding system technical information to the test reference library.
  • Organize and support research presentations for advanced capability development in support of future tests.
  • Prepare OPTEV-RT test assets (Government Furnished).
  • Execute test events as assigned, including Cooperative Vulnerability Penetration Assessments, adversarial assessments, and cyber tabletops.
  • Use OPTEVFOR-provided and NAO approved commercial and open-source network cyber assessment tools (e.g., Core Impact, Nmap, Burp, Metasploit, and Nessus).
  • Apply ethical hacking knowledge to exploit discovered vulnerabilities and misconfigurations across operating systems (Windows, Linux), protocols (HTTP, FTP), and network security services (PKI, HTTPS) aligned to test objectives.
  • Conduct testing independently while ensuring safe execution, adherence to the test plan, and compliance with OPTEVFOR policies.
  • Follow JFHQ-DODIN deconfliction procedures.
  • Verify collected data for accuracy and completeness.
  • Participate in post-test iterative documentation (including deficiency and risk sheets) and document lessons learned.
  • Support OPTEVFOR-required engagements, including capture the flag events, cyber off sites, external engagements (e.g., red team huddles and technical exchange meetings), and creation of required products and materials.
  • Generate and update documentation to maintain DCAT authorization compliance per DoDI 8585.0.
  • Process exfiltrated data for analysis and/or dissemination to customers.
  • Test and evaluate locally developed tools for operational use and implementation.
  • Perform duties under the supervision of the 01D Cyber Operations Officer.

Requirements

  • Minimum 3 years experience performing any combination of penetration testing, red teaming, or exploitation development.
  • Minimum 3 years proficiency in leading red team operators in penetration testing/red teaming to accomplish assigned test objectives.
  • OSCP (or equivalent certification).
  • Proficient with offensive tools including Metasploit, Cobalt Strike, Core Impact, Burp Suite, Nessus, and SharpHound/BloodHound.
  • Ability to validate functionality and safety of offensive tools (e.g., exploits) given source code and to document results.
  • Ability to detect malicious activity using dynamic analysis techniques and document results.
  • Ability to independently operate to conduct penetration testing/red teaming to accomplish assigned test objectives.
  • Skills in assessing current tools for needed improvements and in knowledge management (including technical documentation such as Wiki pages).
  • Knowledge of current software and methodologies for active defense and system hardening.
  • Knowledge of encryption algorithms and cyber capabilities/tools (e.g., TLS, PGP).
  • Knowledge of evasion strategies and techniques; forensic implications of operating system structure and operations; host-based security products and how they affect exploitation and vulnerability.
  • Knowledge of network administration, network construction and topology, and security hardware/software options and their effects on exploitation.
  • Knowledge of security implications of software configurations and fundamentals of digital forensics to extract actionable intelligence.
  • Knowledge of cryptologic capabilities, limitations, and contributions to cyber operations.
  • Knowledge of Unix/Linux and Windows operating systems structures and internals.
  • Knowledge of network collection procedures including decryption capabilities/tools, techniques, and procedures.
  • Ability to test and evaluate tools for implementation and proficiency with Microsoft Office Suite including Teams or similar workplace chat and videoconferencing tools.
  • Excellent written and verbal communication skills.

Technologies

  • Core Impact
  • Nmap
  • Burp
  • Metasploit
  • Nessus
  • Cobalt Strike
  • Burp Suite
  • SharpHound/BloodHound
  • Transport Layer Security
  • Pretty Good Privacy
  • Windows
  • Linux
  • HTTP
  • FTP
  • PKI
  • HTTPS
  • Microsoft Office Suite
  • Teams

Similar Jobs