Cyber - Attack & Penetration Testing - Senior - Consulting

EYHartford, DC
$104,800 - $218,500Remote

About The Position

Cyber threats, social media, artificial intelligence, privacy requirements, and continuity of the business as usual require heavy information security measures. As a Senior Attack & Penetration Tester, you will contribute to our client’s resilience through the execution of sophisticated offensive security operations.

Requirements

  • A bachelor's degree in Computer Science, Computer Engineering, Cybersecurity, Management Information Systems, Information Technology, Engineering, or a related field, and at least five years of relevant offensive security experience.
  • Hands-on experience planning and executing advanced red team engagements, including adversary emulation, objective-based operations, attack-path development, and testing against mature security monitoring and response capabilities.
  • Advanced experience conducting external and internal network penetration testing, including host and service enumeration, exploitation, privilege escalation, lateral movement, and post-exploitation activities.
  • Experience assessing Active Directory environments, including domain and trust configurations, privileged access, authentication protocols, delegation, Group Policy, credential exposure, certificate services, security configurations, and other identity-based attack paths.
  • Experience performing cloud security testing, including identity and access management, exposed services, configuration weaknesses, privilege escalation, and attack-path analysis.
  • Experience conducting wireless security assessments, including enterprise and guest wireless configurations, authentication controls, segmentation, and authorized wireless attack techniques.
  • Experience testing web applications, mobile applications, and APIs using manual techniques and industry-recognized testing methodologies.
  • Experience evaluating security configurations and system-hardening requirements and working with client technical teams to develop practical remediations, mitigations, compensating controls, and validation approaches for identified findings.
  • Experience with scripting or programming languages used to automate testing, analyze data, or develop offensive security tooling, such as Python, PowerShell, Bash, C#, Go, Rust, or Java.
  • Experience using commercial and open-source penetration testing tools while adapting techniques to client-specific environments and constraints.
  • Familiarity with endpoint detection and response (EDR), security information and event management (SIEM), network monitoring, and other defensive controls, including how those controls influence authorized stealth and evasion testing.
  • Experience with red team command-and-control (C2) platforms and associated operational infrastructure, payload development, redirectors, logging, and campaign management.
  • Experience evaluating and bypassing EDR and other defensive controls during explicitly authorized engagements, including memory, execution, credential access, lateral movement, and persistence techniques designed for stealth testing against mature client environments.
  • Working knowledge of the MITRE ATT&CK framework, current vulnerabilities, exploits, adversary tactics, techniques, and procedures, and security remediation practices.
  • Experience leading remote and on-site technical teams, managing testing activities within approved rules of engagement, and communicating testing risks or potential operational impacts.
  • The ability to develop clear technical findings that describe evidence, exploitation paths, business risk, and actionable remediation guidance.
  • Any two relevant offensive security certifications, such as Offensive Security Certified Professional (OSCP), Offensive Security Wireless Professional (OSWP), Offensive Security Experienced Penetration Tester (OSEP), Offensive Security Certified Expert (OSCE), Offensive Security Exploitation Expert (OSEE), GIAC Penetration Tester (GPEN), GIAC Web Application Penetration Tester (GWAPT), GIAC Mobile Device Security Analyst (GMOB), GIAC Cloud Penetration Tester (GCPN), GIAC Exploit Researcher and Advanced Penetration Tester (GXPN), GIAC Red Team Professional (GRTP), GIAC Defending Advanced Threats (GDAT), Certified Red Team Operator (CRTO), Certified Red Team Professional (CRTP), Certified Red Team Expert (CRTE), CREST Registered Penetration Tester (CREST CRT), or Certified Cybersecurity Attack Specialist (CCSAS).
  • A valid U.S. driver's license and the willingness and flexibility to travel up to 80 percent, domestically and internationally, to meet client needs.

Nice To Haves

  • Hands-on cloud penetration testing and identity security assessment experience across Amazon Web Services (AWS), Microsoft Azure, Microsoft Entra ID, and Google Cloud Platform (GCP), including cloud-native identity, privileged access, service, configuration, and privilege-escalation attack paths in hybrid and fully cloud-based environments.
  • Experience assessing Microsoft Entra ID environments, including identity and access management, privileged roles, authentication controls, application registrations, service principals, conditional access, external identities, and cloud-based attack paths for clients operating fully in the cloud without on-premises Active Directory infrastructure.
  • Experience applying artificial intelligence (AI) and machine learning capabilities to support testing, including developing automation for reconnaissance, analysis, evidence processing, repeatable test execution, and offensive security workflows.
  • Advanced experience with API and application security testing, including authentication, authorization, business logic, data exposure, injection, and platform-specific attack paths.
  • Experience evaluating security baselines and hardening standards for Windows, Linux, cloud, and identity environments and helping clients prioritize remediation activities based on risk, feasibility, and operational impact.
  • Experience conducting authorized social engineering and physical penetration testing to evaluate personnel, facility, and access-control risks. This includes direct interaction with targeted personnel to assess susceptibility to credential disclosure, unauthorized access requests, and controlled execution of remote access tooling used for command-and-control testing, as well as evaluating physical security controls through lock bypass, access-control evasion, automated security system testing, tailgating, and radio-frequency identification (RFID) badge cloning techniques.
  • The ability to develop custom tooling, modify public exploits, build proof-of-concept code, and safely operationalize new offensive techniques.
  • Contributions to the security community through research, public vulnerability disclosures, bug bounty acknowledgments, open-source projects, conference presentations, publications, or technical blogs.
  • Strong knowledge of Windows, Linux, Unix, TCP/IP networking, common enterprise protocols, and modern identity and security architectures.
  • Exemplary verbal and written communication skills, including the ability to facilitate workshops and translate complex technical information into concise, executive-level deliverables.
  • Proficiency with consulting engagement methodologies, including estimating effort, prioritizing activities, managing dependencies, and aligning technical testing to client objectives.

Responsibilities

  • Plan, lead, and execute complex penetration testing and advanced red team engagements across diverse client environments.
  • Apply an intelligence-led, threat-informed approach to emulate realistic adversary behaviors, identify exploitable attack paths, and evaluate preventive, detective, and responsive security controls.
  • Span external and internal networks, Active Directory, Microsoft Entra ID, web and mobile applications, application programming interfaces (APIs), cloud environments, wireless networks, social engineering, and physical security scenarios, as permitted by the rules of engagement.
  • Translate technical testing results into clear, actionable insights for technical and executive audiences.
  • Work collaboratively with client technical teams to validate identified weaknesses and develop practical remediation or mitigation strategies, including Active Directory security improvements, system-hardening measures, and compensating controls aligned with the client environment and operational constraints.
  • Lead technical workstreams, coordinate testing activities, mentor junior team members, contribute to methodology and capability development, and remain current on emerging vulnerabilities, adversary tactics, offensive security tooling, and industry research.

Benefits

  • medical and dental coverage
  • pension and 401(k) plans
  • a wide range of paid time off options
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service