Penetration Tester / Red Team Operator

Digital Global Connectors

McLean, UShybridPosted Jul 28, 2026
Posting intelligenceActively listed

Skills

pythonazurejiraaws

About the role

Penetration Tester / Red Team Operator

Location: Bethesda, MD (Hybrid; On-site as Required)

Clearance: Tier 2 Public Trust (Required)

Employment Type: Full-Time

Position Summary

Digital Global Connectors (DGC) is seeking an experienced Penetration Tester / Red Team Operator to support a Federal information security program. The Penetration Tester is responsible for performing authorized security assessments that evaluate the effectiveness of technical, administrative, and operational security controls protecting enterprise information systems, cloud environments, applications, wireless networks, and supporting infrastructure.

This position conducts penetration tests, adversary emulation exercises, vulnerability exploitation, security validation, and red team assessments to identify weaknesses before they can be exploited by malicious actors. The Penetration Tester collaborates with Security Engineers, Security Architects, Threat Hunters, Incident Responders, ISSOs, System Owners, and program leadership to strengthen enterprise cybersecurity through proactive security testing and risk-based recommendations.

The successful candidate will possess extensive experience performing enterprise penetration testing, application security testing, network exploitation, and adversary simulation within complex enterprise environments.

Essential Duties and Responsibilities:

Penetration Testing

Conduct authorized internal and external penetration tests against enterprise systems.

Perform network, application, wireless, cloud, and infrastructure security assessments.

Validate vulnerabilities identified during automated vulnerability scans.

Identify exploitable weaknesses in enterprise environments.

Document attack paths and associated business risks.

Recommend remediation strategies to eliminate identified vulnerabilities.

Red Team Operations

Conduct adversary emulation exercises based on real-world threat actor tactics.

Simulate advanced persistent threat (APT) activities.

Evaluate the effectiveness of enterprise detection and response capabilities.

Test security monitoring, alerting, and incident response processes.

Coordinate red team activities with authorized stakeholders.

Support purple team engagements to improve defensive capabilities.

Web and Application Security Testing

Perform manual and automated web application security assessments.

Test for vulnerabilities consistent with the OWASP Top 10 and API Security Top 10.

Evaluate authentication, authorization, session management, and input validation.

Assess application programming interfaces (APIs) for security weaknesses.

Validate remediation of application vulnerabilities.

Document technical findings and business impacts.

Network Security Testing

Assess internal and external network security.

Evaluate firewalls, routers, switches, VPNs, wireless networks, and remote access solutions.

Test network segmentation and access controls.

Assess Active Directory security.

Evaluate identity and privilege escalation paths.

Validate network hardening measures.

Cloud Security Assessments

Perform security assessments of Microsoft Azure, Microsoft 365, Amazon Web Services (AWS), and hybrid cloud environments.

Evaluate cloud identity configurations and privileged access.

Test cloud networking and storage configurations.

Assess cloud-native security controls.

Identify cloud misconfigurations and excessive permissions.

Recommend improvements to cloud security architecture.

Security Assessment Tools

Utilize technologies including:

Kali Linux

Metasploit Framework

Burp Suite Professional

Nmap

Nessus

Tenable Security Center

BloodHound

Cobalt Strike (where authorized)

Impacket

Wireshark

OWASP ZAP

Microsoft Defender XDR

Microsoft Sentinel

PowerShell

Python

Security Information and Event Management (SIEM) platforms

Evaluate new tools and techniques to improve testing effectiveness.

Reporting and Documentation

Develop and maintain:

Penetration Test Reports

Executive Summary Reports

Technical Findings Reports

Risk Assessments

Remediation Recommendations

Red Team After-Action Reports

Attack Path Diagrams

Proof-of-Concept Documentation

Standard Operating Procedures

Lessons Learned

Ensure reports clearly communicate technical findings, business impacts, and recommended corrective actions.

Collaboration

Coordinate with Security Engineers, Security Architects, ISSOs, SOC Analysts, Threat Hunters, Incident Responders, System Owners, and Government stakeholders.

Support remediation planning and validation efforts.

Participate in security assessments and technical working groups.

Provide technical briefings to technical and executive leadership.

Mentor junior penetration testers when appropriate.

Continuous Improvement

Monitor emerging attack techniques, exploit methodologies, and threat actor tactics.

Evaluate new penetration testing tools and methodologies.

Recommend improvements to enterprise security testing capabilities.

Support purple team exercises and continuous security validation initiatives.

Maintain professional certifications and technical expertise.

Minimum Qualifications

Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, Engineering, or a related discipline.

Minimum five (5) years of experience performing penetration testing, red team operations, or offensive cybersecurity assessments.

Experience performing network, web application, cloud, and infrastructure penetration testing.

Experience using industry-standard penetration testing tools and frameworks.

Familiarity with the OWASP Testing Guide, MITRE ATT&CK Framework, NIST SP 800-115, and Federal cybersecurity requirements.

Strong analytical, troubleshooting, technical writing, and communication skills.

U.S. Citizenship required.

Ability to obtain and maintain a Tier 2 Public Trust.

Preferred Qualifications

Master's degree in Cybersecurity, Computer Science, Information Assurance, Engineering, or a related discipline.

Experience supporting a Federal civilian agency.

Experience conducting cloud security assessments in Azure or AWS environments.

Experience supporting purple team or adversary emulation exercises.

Offensive Security Certified Professional (OSCP)

GIAC Penetration Tester (GPEN)

GIAC Exploit Researcher and Advanced Penetration Tester (GXPN)

Certified Ethical Hacker (CEH)

CompTIA PenTest+

Certified Information Systems Security Professional (CISSP) (preferred)

Knowledge, Skills, and Abilities

Penetration Testing

Red Team Operations

Adversary Emulation

Purple Team Exercises

Ethical Hacking

Web Application Security

API Security Testing

OWASP Top 10

Network Security Testing

Cloud Security Assessments

Microsoft Azure

Amazon Web Services (AWS)

Microsoft 365 Security

Active Directory Security

Kali Linux

Metasploit Framework

Burp Suite Professional

Nmap

Nessus

Tenable Security Center

BloodHound

Cobalt Strike (authorized use)

Impacket

Wireshark

OWASP ZAP

Microsoft Defender XDR

Microsoft Sentinel

PowerShell

Python

MITRE ATT&CK Framework

NIST SP 800-115

Technical Documentation

Microsoft Office Suite

ServiceNow

Jira

Security Requirements

Ability to successfully obtain and maintain a Tier 2 Public Trust investigation.

Compliance with all applicable Federal security, privacy, ethics, and information assurance training requirements before receiving system access.

Ability to support authorized penetration testing engagements, scheduled maintenance windows, continuity of operations (COOP), emergency response activities, and surge support as required.

Must maintain strict confidentiality while handling assessment results, exploit methodologies, vulnerability data, system configurations, and Federal information systems.

Ability to conduct authorized offensive security assessments in a safe, controlled, and ethical manner while collaborating with Government stakeholders and technical teams to identify vulnerabilities, validate security controls, and improve the organization's overall cybersecurity posture.

Questions about this role

Click "Apply with AI Applyd" above and you are done. Your resume is rewritten for this advert, the screening questions are answered, and it is submitted on Digital Global Connectors's own hiring system. No retyping your history, no fourteen tabs, no evening lost.

Compensation for Penetration Tester roles in United States varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our Penetration Tester hub for United States medians across recent openings.

You never touch the form - the application is filled and submitted for you on Digital Global Connectors's own hiring system. It is not marked sent when we press submit. It is marked sent when a confirmation from their system arrives at the address we apply with, and your dashboard shows which stage each application is at until then.

Twelve applicant tracking systems have a real apply path: Workday, Greenhouse, Lever, Ashby, Workable, iCIMS, Personio, Recruitee, Teamtailor, Rippling, Breezy and SmartRecruiters. Your application goes in on the employer's own hiring system, never into an aggregator queue.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.