1

Penetration Tester Red Team Jobs (NOW HIRING)

Red Team Penetration Tester

Dahlgren, VA · On-site

$110K - $150K/yr

As a Red Team Penetration Tester, you will be responsible for conducting penetration testing and conducting offensive cybersecurity operations for the U.S. Government and DoD systems. You will work ...

next page

Showing results 1-20

Penetration Tester Red Team information

See salary details

$22.5K

$119.9K

$168.5K

How much do penetration tester red team jobs pay per year?

As of Sep 6, 2026, the average yearly pay for penetration tester red team in the United States is $119,895.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,000.00 and $141,000.00 per year, depending on experience, location, and employer.

What is a penetration tester red team?

A Penetration Tester on a Red Team is a cybersecurity professional responsible for simulating real-world attacks to test an organization's defenses. They use advanced tactics, techniques, and procedures (TTPs) to identify vulnerabilities in networks, applications, and systems. Unlike traditional penetration testers who focus on specific areas, Red Teamers take a broader approach, emulating adversaries to improve overall security posture. Their goal is to help organizations strengthen their defenses by uncovering weaknesses before real attackers exploit them.

What does a typical day look like for a penetration tester red team?

As a Penetration Tester Red Team member, your days often involve planning, executing, and documenting simulated cyberattacks against internal systems to uncover security weaknesses. You'll work closely with other team members to develop attack strategies, utilize advanced penetration testing tools, and report your findings to IT and security leaders. Collaboration with Blue Teams (defensive security teams) and regular debriefings are common, ensuring everyone learns from the assessments. The work is dynamic and varies by engagement, often requiring both independent problem-solving and coordination within a broader security team.

What are the key skills and qualifications needed to thrive in the penetration tester red team position, and why are they important?

To thrive as a Penetration Tester Red Team, you need strong expertise in cybersecurity, ethical hacking methodologies, network and application security, and typically a background in computer science or information security. Familiarity with tools such as Metasploit, Burp Suite, Nmap, and common certifications like OSCP, CEH, or CREST are highly valued. Outstanding problem-solving abilities, creativity, and effective communication skills help Red Team members articulate findings to both technical and non-technical stakeholders. These skills and qualities are crucial for simulating advanced cyberattacks, identifying critical vulnerabilities, and helping organizations fortify their security posture.

More about Penetration Tester Red Team jobs

What cities are hiring for Penetration Tester Red Team jobs?

Cities with the most Penetration Tester Red Team job openings:

What are the most commonly searched types of Penetration Tester Red Team jobs?

The most popular types of Penetration Tester Red Team jobs are:

What states have the most Penetration Tester Red Team jobs?

States with the most job openings for Penetration Tester Red Team jobs include:

Infographic showing various Penetration Tester Red Team job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 76% Full Time, 20% Part Time, and 3% Contract. Highlights an 91% Physical, 2% Hybrid, and 7% Remote job distribution, with an average salary of $119,895 per year, or $57.6 per hour.

Penetration Tester / Red Team Operator

Digital-Global-Connectors

Mclean, VA • On-site

$110 - $170/hr

Other

Posted 4 days ago


Key responsibilities

  • Conduct authorized internal and external penetration tests against enterprise systems, including network, application, wireless, cloud, and infrastructure security assessments.

  • Perform adversary emulation exercises, simulate advanced persistent threat activities, and evaluate enterprise detection and response capabilities.

  • Perform manual and automated web application security assessments, evaluate APIs, and validate vulnerability remediation.


Job description

Penetration Tester / Red Team Operator

Location: Bethesda, MD (Hybrid; On-site as Required)

Clearance: Tier 2 Public Trust (Required)

Employment Type: Full-Time

Position Summary

Digital Global Connectors (DGC) is seeking an experienced Penetration Tester / Red Team Operator to support a Federal information security program. The Penetration Tester is responsible for performing authorized security assessments that evaluate the effectiveness of technical, administrative, and operational security controls protecting enterprise information systems, cloud environments, applications, wireless networks, and supporting infrastructure.

This position conducts penetration tests, adversary emulation exercises, vulnerability exploitation, security validation, and red team assessments to identify weaknesses before they can be exploited by malicious actors. The Penetration Tester collaborates with Security Engineers, Security Architects, Threat Hunters, Incident Responders, ISSOs, System Owners, and program leadership to strengthen enterprise cybersecurity through proactive security testing and risk-based recommendations.

The successful candidate will possess extensive experience performing enterprise penetration testing, application security testing, network exploitation, and adversary simulation within complex enterprise environments.

Essential Duties and Responsibilities:

Penetration Testing

  • Conduct authorized internal and external penetration tests against enterprise systems.
  • Perform network, application, wireless, cloud, and infrastructure security assessments.
  • Validate vulnerabilities identified during automated vulnerability scans.
  • Identify exploitable weaknesses in enterprise environments.
  • Document attack paths and associated business risks.
  • Recommend remediation strategies to eliminate identified vulnerabilities.
Red Team Operations
  • Conduct adversary emulation exercises based on real-world threat actor tactics.
  • Simulate advanced persistent threat (APT) activities.
  • Evaluate the effectiveness of enterprise detection and response capabilities.
  • Test security monitoring, alerting, and incident response processes.
  • Coordinate red team activities with authorized stakeholders.
  • Support purple team engagements to improve defensive capabilities.
Web and Application Security Testing
  • Perform manual and automated web application security assessments.
  • Test for vulnerabilities consistent with the OWASP Top 10 and API Security Top 10.
  • Evaluate authentication, authorization, session management, and input validation.
  • Assess application programming interfaces (APIs) for security weaknesses.
  • Validate remediation of application vulnerabilities.
  • Document technical findings and business impacts.
Network Security Testing
  • Assess internal and external network security.
  • Evaluate firewalls, routers, switches, VPNs, wireless networks, and remote access solutions.
  • Test network segmentation and access controls.
  • Assess Active Directory security.
  • Evaluate identity and privilege escalation paths.
  • Validate network hardening measures.
Cloud Security Assessments
  • Perform security assessments of Microsoft Azure, Microsoft 365, Amazon Web Services (AWS), and hybrid cloud environments.
  • Evaluate cloud identity configurations and privileged access.
  • Test cloud networking and storage configurations.
  • Assess cloud-native security controls.
  • Identify cloud misconfigurations and excessive permissions.
  • Recommend improvements to cloud security architecture.
Security Assessment Tools

Utilize technologies including:

  • Kali Linux
  • Metasploit Framework
  • Burp Suite Professional
  • Nmap
  • Nessus
  • Tenable Security Center
  • BloodHound
  • Cobalt Strike (where authorized)
  • Impacket
  • Wireshark
  • OWASP ZAP
  • Microsoft Defender XDR
  • Microsoft Sentinel
  • PowerShell
  • Python
  • Security Information and Event Management (SIEM) platforms

Evaluate new tools and techniques to improve testing effectiveness.

Reporting and Documentation

Develop and maintain:

  • Penetration Test Reports
  • Executive Summary Reports
  • Technical Findings Reports
  • Risk Assessments
  • Remediation Recommendations
  • Red Team After-Action Reports
  • Attack Path Diagrams
  • Proof-of-Concept Documentation
  • Standard Operating Procedures
  • Lessons Learned

Ensure reports clearly communicate technical findings, business impacts, and recommended corrective actions.

Collaboration
  • Coordinate with Security Engineers, Security Architects, ISSOs, SOC Analysts, Threat Hunters, Incident Responders, System Owners, and Government stakeholders.
  • Support remediation planning and validation efforts.
  • Participate in security assessments and technical working groups.
  • Provide technical briefings to technical and executive leadership.
  • Mentor junior penetration testers when appropriate.
Continuous Improvement
  • Monitor emerging attack techniques, exploit methodologies, and threat actor tactics.
  • Evaluate new penetration testing tools and methodologies.
  • Recommend improvements to enterprise security testing capabilities.
  • Support purple team exercises and continuous security validation initiatives.
  • Maintain professional certifications and technical expertise.
Minimum Qualifications
  • Bachelor\'s degree in Cybersecurity, Computer Science, Information Technology, Information Systems, Engineering, or a related discipline.
  • Minimum five (5) years of experience performing penetration testing, red team operations, or offensive cybersecurity assessments.
  • Experience performing network, web application, cloud, and infrastructure penetration testing.
  • Experience using industry-standard penetration testing tools and frameworks.
  • Familiarity with the OWASP Testing Guide, MITRE ATT&CK Framework, NIST SP 800-115, and Federal cybersecurity requirements.
  • Strong analytical, troubleshooting, technical writing, and communication skills.
  • U.S. Citizenship required.
  • Ability to obtain and maintain a Tier 2 Public Trust.
Preferred Qualifications
  • Master\'s degree in Cybersecurity, Computer Science, Information Assurance, Engineering, or a related discipline.
  • Experience supporting a Federal civilian agency.
  • Experience conducting cloud security assessments in Azure or AWS environments.
  • Experience supporting purple team or adversary emulation exercises.
  • Offensive Security Certified Professional (OSCP)
  • GIAC Penetration Tester (GPEN)
  • GIAC Exploit Researcher and Advanced Penetration Tester (GXPN)
  • Certified Ethical Hacker (CEH)
  • CompTIA PenTest+
  • Certified Information Systems Security Professional (CISSP) (preferred)
Knowledge, Skills, and Abilities
  • Penetration Testing
  • Red Team Operations
  • Adversary Emulation
  • Purple Team Exercises
  • Ethical Hacking
  • Web Application Security
  • API Security Testing
  • OWASP Top 10
  • Network Security Testing
  • Cloud Security Assessments
  • Microsoft Azure
  • Amazon Web Services (AWS)
  • Microsoft 365 Security
  • Active Directory Security
  • Kali Linux
  • Metasploit Framework
  • Burp Suite Professional
  • Nmap
  • Nessus
  • Tenable Security Center
  • BloodHound
  • Cobalt Strike (authorized use)
  • Impacket
  • Wireshark
  • OWASP ZAP
  • Microsoft Defender XDR
  • Microsoft Sentinel
  • PowerShell
  • Python
  • MITRE ATT&CK Framework
  • NIST SP 800-115
  • Technical Documentation
  • Microsoft Office Suite
  • ServiceNow
  • Jira
Security Requirements
  • Ability to successfully obtain and maintain a Tier 2 Public Trust investigation.
  • Compliance with all applicable Federal security, privacy, ethics, and information assurance training requirements before receiving system access.
  • Ability to support authorized penetration testing engagements, scheduled maintenance windows, continuity of operations (COOP), emergency response activities, and surge support as required.
  • Must maintain strict confidentiality while handling assessment results, exploit methodologies, vulnerability data, system configurations, and Federal information systems.
  • Ability to conduct authorized offensive security assessments in a safe, controlled, and ethical manner while collaborating with Government stakeholders and technical teams to identify vulnerabilities, validate security controls, and improve the organization\'s overall cybersecurity posture.
#J-18808-Ljbffr