Guidehouse logo
GuidehousePosted 3 weeks ago

Pentest Operator

$113,000–$188,000 year

On-siteBeltsville, Maryland, United States

Full TimeSenior LevelLarge

Job Summary

Conduct penetration testing and adversary emulation engagements for High Value Asset systems, including internal network mapping, web application security testing, and Active Directory assessments. Execute red team operations to simulate realistic threat behavior, validate defensive controls, and document attack paths within approved Rules of Engagement. Analyze telemetry and logs to support purple team activities, identify detection gaps, and recommend improvements to SIEM and EDR processes. Deliver evidence-based reports and executive out-briefs to system owners and senior leaders, translating technical findings into risk-based remediation strategies. Maintain active Secret clearance and utilize offensive security tools to evaluate mission risk across commercial and federal environments.

Required Qualifications

  • An ACTIVE and MAINTAINED SECRET Federal or DoD security clearance
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field
  • Minimum of FIVE (5) or more years of demonstrated hands-on experience in penetration testing, red team operations, adversary emulation, vulnerability assessment, application security testing, cyber operations, or related offensive security work
  • Experience performing internal and external network penetration testing, including reconnaissance, enumeration, exploitation, privilege escalation, lateral movement, and documentation of attack paths
  • Experience performing web application penetration testing using manual and automated techniques
  • Experience assessing Active Directory environments, Windows and Linux systems, and common enterprise network services
  • Experience using common penetration testing tools such as Burp Suite, Metasploit, Nmap, Nessus, Kali Linux, Wireshark, BloodHound, Impacket, Responder, Hashcat, John the Ripper, Cobalt Strike, Sliver, or similar tools
  • Experience developing test plans, documenting Rules of Engagement, tracking assessment activities, and producing formal penetration test reports
  • Ability to explain technical findings, attack paths, business impact, and remediation options to both technical and non-technical stakeholders
  • Strong written and verbal communication skills, including the ability to develop client-ready deliverables and executive-ready summaries
  • Ability to work independently, manage multiple priorities, and collaborate across multidisciplinary teams in complex federal environments
  • Active Secret clearance

Desired Qualifications

  • An ACTIVE and MAINTAINED TOP SECRET Federal or DoD security clearance
  • Experience supporting HVA cybersecurity assessments or federal enterprise penetration testing programs
  • One or more relevant offensive security certifications such as OSCP, GPEN, GWAPT, GXPN, GRTP, PenTest+, CEH, GCIH, or similar certification
  • Experience with adversary emulation, purple team operations, detection engineering support, or validation of SIEM and EDR detection coverage
  • Experience with Cobalt Strike, Sliver, custom payload development, or command-and-control simulation in approved assessment environments
  • Experience with cloud security testing or assessment activities across AWS, Azure, or other cloud environments
  • Experience supporting incident response, threat hunting, or post-incident analysis
  • Experience creating proof-of-concept exploit examples for reports or live demonstrations in controlled, authorized environments
  • Experience mentoring junior penetration testers or leading small offensive security workstreams
  • Excellent oral and written communication and presentation skills

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce