CybersecurityJobs.io
← Back to all jobs

Job Description

Dominion Energy is hiring a Senior Cyber Security Analyst to strengthen the security of critical infrastructure through penetration testing and offensive security assessments. This role is centered on finding exploitable weaknesses before real-world threats can use them, while clearly communicating risk, evidence, and remediation guidance.

Working in an established team of three penetration testers, you will support authorized testing across applications, systems, internal and external networks, and a range of technology domains including cloud, identity, and enterprise platforms. The position is based onsite in Cayce, SC, US and may also be based in Richmond, Virginia.

Role focus

  • Perform penetration testing and offensive security assessments rather than traditional cyber security analyst responsibilities.
  • Conduct testing across applications, systems, networks, and cloud/identity/enterprise technologies, including assessment of web and enterprise applications and APIs.
  • Support assessments that may involve OT, ICS, SCADA, industrial control networks, or other critical infrastructure environments, where applicable.
  • Complete the full penetration-testing lifecycle: planning and scoping, hands-on testing, identifying and validating attack paths, evaluating security controls, documenting findings, communicating risk, supporting remediation, and validating corrective actions.

Responsibilities

  • Plan, scope, and execute authorized penetration tests and offensive security assessments.
  • Identify and validate vulnerabilities, exploitable weaknesses, attack paths, and security-control gaps.
  • Assess web and enterprise applications, APIs, network infrastructure, cloud environments, identity platforms, systems, and related technologies.
  • Prepare high-quality reports describing technical evidence, risk, business impact, and practical remediation recommendations.
  • Present findings and recommendations to technical teams, system owners, business stakeholders, and management.
  • Partner with technology owners to prioritize findings, support remediation, and validate corrective actions.
  • Collaborate with other penetration testers through peer review, methodology development, knowledge sharing, and coordinated testing activities.
  • Research emerging vulnerabilities, attack techniques, tools, and offensive security methodologies.
  • Perform testing in a controlled, ethical, and business-aware manner that minimizes unintended operational impact.

Requirements

  • Five years of hands-on experience working with systems, networks, cloud environments, identity platforms, OT/ICS environments, or related enterprise infrastructure.
  • A Master’s degree counts as one year of experience.
  • A partial year of six months or more is rounded up to one year.
  • Demonstrated ability to plan, scope, execute, and document penetration tests or offensive security assessments.
  • Demonstrated ability to identify, validate, document, and communicate exploitable vulnerabilities, attack paths, security-control weaknesses, and associated risks.
  • Experience developing reports including technical evidence, business-impact descriptions, risk-based findings, and practical remediation recommendations.
  • Verbal and written communication skills, including experience presenting technical findings to technical and non-technical audiences.
  • Ability to test ethically and responsibly within an authorized scope while considering business operations, system availability, reliability, and safety.
  • Ability to work cooperatively in a team environment, participate in peer reviews, share technical knowledge, and coordinate testing activities.
  • Initiative, analytical and investigative ability, intellectual curiosity, and commitment to developing offensive security skills and methodologies.
  • Experience assessing or securing OT, ICS, SCADA, industrial control networks, or critical infrastructure environments is preferred.
  • Experience testing web applications, APIs, Active Directory, cloud platforms, network infrastructure, identity platforms, or other enterprise technologies is preferred.

Preferred certifications

  • OSCP, OSEP, PNPT, GPEN, GXPN, GWAPT, GCIH, GCFA, GICSP, CISSP, CPTS, or another comparable GIAC, OffSec, Hack The Box, or recognized offensive security certification.

Compensation

  • Expected hiring base salary range: USD 102,300 - 132,800 per year.

Benefits

  • Health, dental, and vision benefits with coverage for families and domestic partners
  • Vacation
  • Retirement plans including 401k contributions and matches
  • Paid holidays
  • Tuition reimbursement
  • Bonus eligibility
  • Sick leave
  • Disability insurance

Working conditions and logistics

  • Office work environment: 76 - 100%
  • Travel: up to 25%
  • No testing required

Eligibility and compliance notes

  • Certain positions may involve access to information and technology subject to U.S. export controls, and compliance may limit consideration of certain applicants.
  • Dominion Energy cannot transfer or sponsor a work visa or employment authorization for this position.
  • No relocation assistance is offered.
  • Military service members and veterans with ranks from E5-E9, W1-CW5, or O3-O6, plus an appropriate equivalent combination of education and years of experience as outlined below, will be considered.

Similar Jobs