Senior Penetration Tester/ Red Team Lead
Senior Penetration Tester/ Red Team Lead
security 1st consultingNewport News, VA
Apply for this role →yesterday
IT
Location
Work Mode
Employment Type
Experience Level
Security Clearance
Type:
Active Secret
Status: Preferred
Job Description:
The Senior Penetration Tester and Red Team Lead is responsible for designing and executing all external, internal, and wireless penetration testing for this engagement. You will work against a real-world network with 50+ facilities, 40,000 devices, and two geographically diverse data centers. This is not a simulated lab — you are testing a live district network with real users and real systems, which requires both technical skill and professional discipline.
Responsibilities:
Lead all external, internal, and wireless penetration testing activities within the approved scope.
Develop and submit the written test plan, including scope confirmation, attack vector mapping, and communication protocols, before testing begins.
Conduct external penetration testing from outside the network perimeter via the internet, mimicking an attacker with no credentials or prior network knowledge.
Conduct internal penetration testing from inside the organization, testing internal systems for exploitable vulnerabilities including privilege escalation and lateral movement.
Perform wireless penetration testing across four identified wireless networks, validating security mechanisms against unauthorized access.
Communicate with third-party vendors to obtain authorization as required for scoped systems.
Document all findings with CVSS severity ratings, technical detail, business impact analysis, and step-by-step remediation guidance.
Coordinate testing timing with the client IT team to avoid disruption to classroom instruction — network-intensive testing is conducted after hours.
Ensure no hardware or software is used that would interrupt network connectivity or production systems; disclose in advance any testing with potential network impact.
Requirements:
REQUIRED QUALIFICATIONS
Active OSCP (Offensive Security Certified Professional) certification.
5 or more years of hands‑on penetration testing experience across external, internal, and wireless environments.
Proficiency with standard penetration testing tools including Metasploit, Nmap, Burp Suite, Aircrack‑ng, Wireshark, and equivalent platforms.
Experience identifying and exploiting privilege escalation paths and lateral movement opportunities.
Strong technical writing skills — findings reports must be clear, accurate, and actionable.
Ability to manage testing activities without disrupting production systems.
PREFERRED QUALIFICATIONS:
CEH, GPEN, GWAPT, or equivalent offensive security certifications.
Experience testing K-12, higher education, or state/local government networks.
Familiarity with OpenVAS (current scanning tool in the environment).
Experience conducting white box, black box, and grey box testing engagements.
Active security clearance or Public Trust eligibility.
Also on the board Same function, level within a rung
Level
Senior
Location
Newport News, VA
Occupation
Penetration Testers
Industry
Computer Systems Design Services
Posted
yesterday