{"id":1679081,"url":"https://alion.io/job/och-technologies-penetration-tester","title":"Penetration Tester","company":{"id":3854350,"name":"OCH Technologies","domain":"ochtechnologies.com","url":"https://alion.io/company/och-technologies","size_band":"201-500","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Paylocity","truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":90000,"max_usd":179000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":974},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Active Directory","optional":false},{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"BloodHound","optional":false},{"name":"Burp Suite","optional":false},{"name":"Cobalt Strike","optional":false},{"name":"Impacket","optional":false},{"name":"Metasploit","optional":false},{"name":"Mythic","optional":false},{"name":"Nmap","optional":false},{"name":"Nuclei","optional":false},{"name":"OWASP","optional":false},{"name":"Pacu","optional":false},{"name":"Red Teaming","optional":false},{"name":"Sliver","optional":false}],"status":"live","first_seen_at":"2026-07-27T15:14:44Z","employer_posted_date":"2026-10-02","last_verified_at":"2026-10-06T21:00:26Z","board_verified":true,"closed_at":null,"days_open":71,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":71},"description":"Description\nOCH Technologies is seeking a Penetration Tester to execute network, system, application, and specialized penetration tests against FAA infrastructure under the direction of the Penetration Testing Lead. The candidate will work within formal Rules of Engagement, operate FAA-approved tools, and produce technically detailed test reports. You will also participate in red team and blue team exercises in simulated environments.\nThis position supports a proposal effort and is contingent upon award, customer approval, and successful onboarding requirements.\n Location\nHybrid- FAA Air Traffic Control System Command Center (ATCSCC)- Washington, DC\nThis position has the potential to travel up to 40% to other FAA facilities nationwide\n Core Responsibilities & Duties\nExecute penetration tests against NAS and Mission Support systems, networks, and applications following approved Rules of Engagement and test plans. \nIdentify and exploit vulnerabilities in network infrastructure, operating systems, web applications, and databases. \nParticipate in red team and blue team exercises in simulated environments. Execute attack scenarios and document findings. \nDocument all testing activities, findings, and exploitation paths in Penetration Test Reports (PTRs). \nPerform regression penetration tests to validate remediation of previously identified vulnerabilities. \nSupport aircraft cyber testing activities including avionics and flight system security assessments when directed. \nSupport specialized assessments of edge devices, firewalls, load balancers, and other network infrastructure components. \nAssess and document the potential for lateral movement when access is gained during testing. Report high-risk findings immediately. \nMaintain and update penetration testing tools and lab environments. All tools must be FAA-approved prior to use. \nSupport the Penetration Testing Lead in developing Rules of Engagement and test plans for upcoming engagements. \nResponsibilities may evolve over time to support team and organizational goals but will remain consistent with the overall scope of the role.\nRequirements\nMinimum Qualifications\nEducation\nBachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Mathematics, or Physics from an accredited institution\nExperience\nA minimum of five (5)+ years of hands-on penetration testing experience, including network, system, and web application testing. At least 2 years of relevant experience must be recent (performed within the last 3 years). \nProficiency with Metasploit, Burp Suite, nMap, and related penetration testing frameworks. \nExperience working within formal Rules of Engagement and producing structured penetration test reports. \nUnderstanding of network protocols, routing, switching, firewall configurations, and common misconfigurations. \nExperience with web application testing following OWASP methodology. \nSecurity Clearance Requirement\nCandidate must have the ability to obtain and maintain a Public Trust\nCertifications\nAt least one Red Teaming certification: OSCP, OSCE, OSWP, OSWE, CEH, ECSA, CEH Practical, ECSA Practical, LPT Master, GCIH, GPEN, GWAPT, GXPN, or GAWN. \nBlue Teaming certifications are also accepted: CND, CNDA, GCIH, GCIA, GDAT, GDSA, GCED, or GCFA. \nOSCP or GPEN preferred. \nPreferred Qualifications\nExperience testing ICS/OT environments or critical infrastructure systems. \nExperience with wireless security testing or satellite communication systems. \nExperience with cloud penetration testing (AWS, Azure). \nFamiliarity with aircraft systems, avionics, or aviation communication protocols. \nPrior red team experience in a government or military context. \nC2 frameworks (Cobalt Strike, Sliver, Mythic) for adversary simulation beyond Metasploit. \nBloodHound and Impacket for Active Directory attack path analysis and lateral movement. \nNuclei for automated vulnerability detection at scale. \nCloud pen testing tools (Pacu, AzureHound) for cloud-hosted environments. \nSDR/HackRF tools for wireless and RF communications testing. \nAI-assisted fuzzing tools for expanding exploit discovery on complex systems. \nOther Required Skills and Abilities\nWillingness to travel to FAA facilities and WJHTC for on-site testing engagements. \nDiscipline to operate within strict testing constraints in safety-critical environments. \nAbility to conduct manual testing beyond automated tool output. Ability to develop custom scripts and payloads as needed. \nAbout Us: At OCH, we are more than just a government contracting firm; we are innovators and leaders in providing cutting-edge IT services and cybersecurity solutions. Driven by a set of fundamental values, we excel in creating secure, efficient, and forward-thinking solutions that empower the government agencies we work with. Our commitment to maintaining the highest standards of integrity, adapting swiftly to new challenges, and focusing on the people we serve ensures that we consistently exceed expectations and lead the industry in innovation and reliability.\nWhat Defines Us:\nIntegrity - We act with unwavering honesty, ensuring every decision is rooted ethically. \nAdaptable - We swiftly adapt to changes, seizing opportunities to innovate and lead. \nPeople-Focused - We prioritize relationships, championing growth and mutual success. \nAccountable - We own our outcomes, striving for excellence through continuous improvement. \nCollaborative - We cultivate teamwork, harnessing diverse talents to forge groundbreaking solutions. \n Why Join Us?\nStep into a role at OCH where your contributions make a tangible impact. Join a team that values creativity and initiative, offering a platform to transform the landscape of government IT services. Here, your work is not just a career-it's a mission. Embrace the opportunity to grow, innovate, and excel alongside industry leaders who are as passionate about technology as they are about making a difference. Plus, we offer a comprehensive benefits package designed to support your wellbeing and work-life balance, including:\nPaid time off and Holidays \nMedical, Dental, and Vision Insurance \nPaid Parental Leave \nShort-term disability, long-term disability, and life insurance - Employer Paid! \n401(k) \nAdditional Voluntary Life Insurance \nTuition Reimbursement \n& More!\nE-Verify Participation: OCH Technologies, LLC is a participant of E-Verify to verify the identity and employment eligibility of newly hired employees.\nVeteran’s Preference and Accessibility Statement : At OCH Technologies, we deeply respect and appreciate the unique skills and experiences that veterans bring to our team. As a federal contractor, we encourage qualified veterans to apply and provide preference where permitted by law. Your service and dedication are valued here.\nWe are committed to creating a workplace that is open, welcoming, and accessible to everyone. In accordance with the Americans with Disabilities Act (ADA) and Section 503 of the Rehabilitation Act, we provide reasonable accommodations throughout the hiring process to ensure individuals with disabilities can apply without barriers. If you need assistance or an accommodation, please contact us at .\nOCH Technologies, LLC is proud to be an equal opportunity employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, disability, gender identity, or any other protected characteristic as outlined by federal, state, or local laws.","description_format":"text","description_chars":7529,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":true,"languages":[]},"benefits":["Life insurance","Parental leave","Vision insurance"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Penetration Testing"],"lifecycle":[{"event":"open","at":"2026-10-02T09:24:09Z"}],"visa":[],"liveness":{"score":26,"band":"fade","label":"Fading","p_open":1,"p_active":0.725,"p_room":0.36,"age_days":70,"expected_fill_days":45,"reasons":["conf:0","velocity","win:tail","crowd:"],"computed_at":"2026-10-06T05:45:30Z"},"pay":null,"html_url":"https://alion.io/job/och-technologies-penetration-tester","json_url":"https://alion.io/job/och-technologies-penetration-tester.json","meta":{"generated_at":"2026-10-06T22:45:44Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3452,"day_limit":5000,"remaining_today":1548,"minute_limit":60,"resets_at":"2026-10-07T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":3854350},"rest":"https://alion.io/mcp/rest/get_company?id=3854350"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Foch-technologies-penetration-tester"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Foch-technologies-penetration-tester"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Foch-technologies-penetration-tester"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/och-technologies-penetration-tester\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Foch-technologies-penetration-tester"}]}