{"schemaVersion":"jobsearcher.job.v1","id":"959550e71048162594dea6f1","url":"https://jobsearcher.com/jobs/959550e71048162594dea6f1","canonicalUrl":"https://jobsearcher.com/jobs/959550e71048162594dea6f1","title":"Penetration Tester","description":"Tharros has an immediate opportunity to support the US Navy with operational test and evaluation support. The Penetration Tester will assist in the development of cyber test plans, execute cyber tests, and report cyber test results. In this role you will conduct cyber tests on operational systems, in laboratory environments, or in cyber range environments. Testing may be against physical, virtualized, or cloud-based systems. This position shall leverage all authorized resources and analytic techniques to penetrate/access targeted networks and systems under test in support of OPTEVFOR’s cyber OT&E mission. Team member will perform these duties under the supervision of the 01D Cyber Operations Officer.\n\nReview and become proficient in OPTEVFOR cyber T&E concept of operations, SOPs, policies and guidance.\nMaintain and participate in the development of 01D SOPs and documentation for DCAT authorization established in DoDI 8585.01.\nResearch, review, prioritize, and submit operational requirements for acquisition of equipment or cyber capabilities, following the 01D tool approval process.\nSupport development and execution of TTPs for penetration testing or Red Teaming.\nResearch adversary cyber actors’ TTPs, organizational structures, capabilities, personas, and environments, and integrate findings into cyber survivability test planning and execution.\nParticipate in OPTEVFOR Cyber Test planning:\n\nConduct open-source research and system under test documentation review to familiarize with the system’s mission, architecture and interfaces including critical components to identify its attack surface and threat vectors\nParticipate in check point meetings\nSupport development of test plan objectives\nReview test plans, ensuring that test plans objectives are feasible\nParticipate in test planning site visits\nParticipate in test preparation:\n\nParticipate in site pre-test coordination visits. Support in-brief to the test site.\nSupport red team test plan review\nAdd relevant system technical information to test reference library\nOrganize and support research presentations for advanced capability development in support of future tests\nPrepare OPTEV-RT test assets (Government Furnished)\nExecute test events, including Cooperative Vulnerability Penetration Assessments, Adversarial assessments, and Cyber Tabletops, in support of Operational Testing, Developmental Testing, risk reduction events, or other events, as assigned.\n\nUse OPTEVFOR provided and NAO approved commercial and open-source network cyber assessment tools (e.g. Core Impact, Nmap, Burp, Metasploit, and Nessus).\nEmployee ethical hacking knowledge to exploit discovered vulnerabilities and misconfigurations associated with but not limited to operating systems (Windows, Linux, etc.), protocols (HTTP, FTP, etc.), and network security services (PKI, HTTPS, etc.) to accomplish test objectives\nBe able to accomplish testing independently\nEnsure tests are conducted safely, in accordance with the test plan, and OPTEVFOR policies are adhered to\nFollow Joint Forces Headquarters (JFHQ)-DODIN deconfliction procedures\nVerify collected data for accuracy and completeness\nParticipate in the post-test iterative process, including generation of documents (e.g. deficiency/risk sheets).\nDocument lessons learned.\nParticipate in capture the flag events, cyber off sites, external engagements such as red team huddles and red team technical exchange meetings; develop required products and materials in support of these events.\nAttend OPTEVFOR required meetings in support of OT&E.\nGenerate and update documentation to maintain DCAT authorization compliance per DoDI 8585.0.\nProcess exfiltrated data for analysis and/or dissemination to customers.\nTest and evaluate locally developed tools for operational use and implementation.\nMinimum 3 years’ experience performing any combination of: penetration testing, red teaming, or exploitation development.\nMinimum 3 years’ with proficiency in leading red team operators in penetration testing/red teaming to accomplish assigned test objectives.\nOffensive Security Certified Professional (OSCP), OSCE, GX-PT, GXPM, PNPT, or HTB CPTS required.\nProficient in multiple offensive tools, including:\n\nMetasploit, Cobalt Strike, Core Impact, Burp Suite, Nessus, SharpHoundBloodHound\n\nAbility to validate functionality and safety of offensive tools (e.g. exploits) given the source code and document the results.\nAbility to detect malicious activity of a program using dynamic analysis techniques and document the results.\n\nIndependently operate to conduct penetration testing/red teaming to accomplish assigned test objectives.\nSkill in assessing current tools to identify needed improvements.\nSkill in knowledge management, including technical documentation techniques (e.g., Wiki page).\nKnowledge of current software and methodologies for active defense and system hardening.\nKnowledge of encryption algorithms and cyber capabilities/tools (e.g., Transport Layer Security, Pretty Good Privacy).\nKnowledge of evasion strategies and techniques.\nKnowledge of forensic implications of operating system structure and operations.\nKnowledge of host-based security products and how they affect exploitation and vulnerability.\nKnowledge of network administration.\nKnowledge of network construction and topology.\nKnowledge of security hardware and software options, including the network artifacts they induce and their effects on exploitation.\nKnowledge of security implications of software configurations.\nKnowledge of the fundamentals of digital forensics in order to extract actionable intelligence.\nKnowledge of cryptologic capabilities, limitations, and contributions to cyber operations.\nKnowledge of Unix/Linux and Windows operating systems structures and internals (e.g., process management, directory structure, installed applications).\nKnowledge of network collection procedures to include decryption capabilities/tools, techniques, and procedures.\nProcess exfiltrated data for analysis and/or dissemination to customers.\nTest and evaluate locally developed tools for operational use.\nSkill in testing and evaluating tools for implementation.\nProficient in Microsoft Office Suite to include Teams or similar workplace chat and videoconferencing tools.\nExcellent written and verbal communication skills.\n\nTharros combines extensive cyber defense knowledge with the world’s preeminent vulnerability expertise to identify and defend against attacks before they become problems. Working at mission speed, we harden mission systems faster and secure them for longer, so agencies never lose the mission edge. Tharros lifts the veil of enterprise cybersecurity to detect zero days before they affect you, enabling mission maneuverability and the confidence to move missions forward.\n\nIn the ever-evolving realm of cyberspace, we are dedicated to becoming the paramount defender in the 5th warfighting domain. By pioneering innovative security solutions and fostering an environment of continuous learning and vigilance, we aim to protect the interests of our nation’s security. Our commitment to excellence in cybersecurity will establish new benchmarks, transforming the digital landscape into a secure and thriving frontier for future generations.\n\nTharros. See Everything. Secure Anything.\n\nTharros is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Opportunity/Affirmative Action Employer and make employment decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected status.","company":"Tharros","rawCompany":"tharros","city":"Norfolk","state":"VA","isRemote":false,"isActive":false,"createdAt":"2026-08-19T16:04:43.503Z","occupations":[{"code":"15-1299.04","title":"Penetration Testers","slug":"penetration-testers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"928110","title":"National Security","slug":"national-security"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Penetration Tester","description":"Tharros has an immediate opportunity to support the US Navy with operational test and evaluation support. The Penetration Tester will assist in the development of cyber test plans, execute cyber tests, and report cyber test results. In this role you will conduct cyber tests on operational systems, in laboratory environments, or in cyber range environments. Testing may be against physical, virtualized, or cloud-based systems. This position shall leverage all authorized resources and analytic techniques to penetrate/access targeted networks and systems under test in support of OPTEVFOR’s cyber OT&E mission. Team member will perform these duties under the supervision of the 01D Cyber Operations Officer.\n\nReview and become proficient in OPTEVFOR cyber T&E concept of operations, SOPs, policies and guidance.\nMaintain and participate in the development of 01D SOPs and documentation for DCAT authorization established in DoDI 8585.01.\nResearch, review, prioritize, and submit operational requirements for acquisition of equipment or cyber capabilities, following the 01D tool approval process.\nSupport development and execution of TTPs for penetration testing or Red Teaming.\nResearch adversary cyber actors’ TTPs, organizational structures, capabilities, personas, and environments, and integrate findings into cyber survivability test planning and execution.\nParticipate in OPTEVFOR Cyber Test planning:\n\nConduct open-source research and system under test documentation review to familiarize with the system’s mission, architecture and interfaces including critical components to identify its attack surface and threat vectors\nParticipate in check point meetings\nSupport development of test plan objectives\nReview test plans, ensuring that test plans objectives are feasible\nParticipate in test planning site visits\nParticipate in test preparation:\n\nParticipate in site pre-test coordination visits. Support in-brief to the test site.\nSupport red team test plan review\nAdd relevant system technical information to test reference library\nOrganize and support research presentations for advanced capability development in support of future tests\nPrepare OPTEV-RT test assets (Government Furnished)\nExecute test events, including Cooperative Vulnerability Penetration Assessments, Adversarial assessments, and Cyber Tabletops, in support of Operational Testing, Developmental Testing, risk reduction events, or other events, as assigned.\n\nUse OPTEVFOR provided and NAO approved commercial and open-source network cyber assessment tools (e.g. Core Impact, Nmap, Burp, Metasploit, and Nessus).\nEmployee ethical hacking knowledge to exploit discovered vulnerabilities and misconfigurations associated with but not limited to operating systems (Windows, Linux, etc.), protocols (HTTP, FTP, etc.), and network security services (PKI, HTTPS, etc.) to accomplish test objectives\nBe able to accomplish testing independently\nEnsure tests are conducted safely, in accordance with the test plan, and OPTEVFOR policies are adhered to\nFollow Joint Forces Headquarters (JFHQ)-DODIN deconfliction procedures\nVerify collected data for accuracy and completeness\nParticipate in the post-test iterative process, including generation of documents (e.g. deficiency/risk sheets).\nDocument lessons learned.\nParticipate in capture the flag events, cyber off sites, external engagements such as red team huddles and red team technical exchange meetings; develop required products and materials in support of these events.\nAttend OPTEVFOR required meetings in support of OT&E.\nGenerate and update documentation to maintain DCAT authorization compliance per DoDI 8585.0.\nProcess exfiltrated data for analysis and/or dissemination to customers.\nTest and evaluate locally developed tools for operational use and implementation.\nMinimum 3 years’ experience performing any combination of: penetration testing, red teaming, or exploitation development.\nMinimum 3 years’ with proficiency in leading red team operators in penetration testing/red teaming to accomplish assigned test objectives.\nOffensive Security Certified Professional (OSCP), OSCE, GX-PT, GXPM, PNPT, or HTB CPTS required.\nProficient in multiple offensive tools, including:\n\nMetasploit, Cobalt Strike, Core Impact, Burp Suite, Nessus, SharpHoundBloodHound\n\nAbility to validate functionality and safety of offensive tools (e.g. exploits) given the source code and document the results.\nAbility to detect malicious activity of a program using dynamic analysis techniques and document the results.\n\nIndependently operate to conduct penetration testing/red teaming to accomplish assigned test objectives.\nSkill in assessing current tools to identify needed improvements.\nSkill in knowledge management, including technical documentation techniques (e.g., Wiki page).\nKnowledge of current software and methodologies for active defense and system hardening.\nKnowledge of encryption algorithms and cyber capabilities/tools (e.g., Transport Layer Security, Pretty Good Privacy).\nKnowledge of evasion strategies and techniques.\nKnowledge of forensic implications of operating system structure and operations.\nKnowledge of host-based security products and how they affect exploitation and vulnerability.\nKnowledge of network administration.\nKnowledge of network construction and topology.\nKnowledge of security hardware and software options, including the network artifacts they induce and their effects on exploitation.\nKnowledge of security implications of software configurations.\nKnowledge of the fundamentals of digital forensics in order to extract actionable intelligence.\nKnowledge of cryptologic capabilities, limitations, and contributions to cyber operations.\nKnowledge of Unix/Linux and Windows operating systems structures and internals (e.g., process management, directory structure, installed applications).\nKnowledge of network collection procedures to include decryption capabilities/tools, techniques, and procedures.\nProcess exfiltrated data for analysis and/or dissemination to customers.\nTest and evaluate locally developed tools for operational use.\nSkill in testing and evaluating tools for implementation.\nProficient in Microsoft Office Suite to include Teams or similar workplace chat and videoconferencing tools.\nExcellent written and verbal communication skills.\n\nTharros combines extensive cyber defense knowledge with the world’s preeminent vulnerability expertise to identify and defend against attacks before they become problems. Working at mission speed, we harden mission systems faster and secure them for longer, so agencies never lose the mission edge. Tharros lifts the veil of enterprise cybersecurity to detect zero days before they affect you, enabling mission maneuverability and the confidence to move missions forward.\n\nIn the ever-evolving realm of cyberspace, we are dedicated to becoming the paramount defender in the 5th warfighting domain. By pioneering innovative security solutions and fostering an environment of continuous learning and vigilance, we aim to protect the interests of our nation’s security. Our commitment to excellence in cybersecurity will establish new benchmarks, transforming the digital landscape into a secure and thriving frontier for future generations.\n\nTharros. See Everything. Secure Anything.\n\nTharros is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Opportunity/Affirmative Action Employer and make employment decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected status.","datePosted":"2026-08-19T16:04:43.503Z","dateModified":"2026-08-19T16:04:43.503Z","hiringOrganization":{"@type":"Organization","name":"Tharros","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Norfolk","addressRegion":"VA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"959550e71048162594dea6f1"},"url":"https://jobsearcher.com/jobs/959550e71048162594dea6f1"}}