{"id":1679078,"url":"https://alion.io/job/och-technologies-penetration-testing-lead","title":"Penetration Testing Lead","company":{"id":3854350,"name":"OCH Technologies","domain":"ochtechnologies.com","url":"https://alion.io/company/och-technologies","size_band":"201-500","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Paylocity","truth_index":null},"role":"Security","role_family":"Security","seniority":"lead","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Washington, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":98000,"max_usd":207000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":307},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Active Directory","optional":false},{"name":"AWS","optional":false},{"name":"BloodHound","optional":false},{"name":"Burp Suite","optional":false},{"name":"Cobalt Strike","optional":false},{"name":"Impacket","optional":false},{"name":"Metasploit","optional":false},{"name":"Mythic","optional":false},{"name":"Nmap","optional":false},{"name":"Nuclei","optional":false},{"name":"OWASP","optional":false},{"name":"Pacu","optional":false},{"name":"Red Teaming","optional":false},{"name":"Sliver","optional":false}],"status":"live","first_seen_at":"2026-09-11T20:56:24Z","employer_posted_date":"2026-10-02","last_verified_at":"2026-10-07T23:32:27Z","board_verified":true,"closed_at":null,"days_open":26,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":26},"description":"Description\nOCH Technologies is seeking a Penetration Testing Lead responsible for planning, executing, and documenting all penetration testing activities performed under this contract, including network, system, application, and aircraft cybersecurity assessments. This individual develops Rules of Engagement with system owners, leads red and blue team exercises, and delivers comprehensive penetration test reports that provide actionable, technically sound findings and recommendations. The ideal candidate is an experienced offensive security professional who combines advanced technical expertise with the discipline, sound judgment, and attention to detail required to operate successfully in a highly regulated, safety-critical environment.\nThis position supports a proposal effort and is contingent upon award, customer approval, and successful onboarding requirements. \n Location\nHybrid - Air Traffic Control System Command Center (ATCSCC) Washington, DC\nThis position may require up to 50% travel to FAA facilities.\n Core Responsibilities & Duties\nServe as primary technical POC for all penetration testing activities, including network, system, application, aircraft cyber, and specialized assessments. \nDevelop Rules of Engagement (ROE) with system owners and ACG for each penetration test. Ensure all parties understand scope, constraints, and reporting requirements before testing begins. \nPersonally lead high-complexity penetration tests in NAS and Mission Support environments. Direct testing teams during execution. \nPlan and execute red team and blue team exercises in simulated environments as directed by the FAA. Design realistic attack scenarios that test the effectiveness of NAS cybersecurity defenses. \nDocument all penetration test results in Penetration Test Reports (PTRs) including attack vectors tested, vulnerabilities discovered, exploitation paths, and recommended remediation actions. \nAssess and document impact when access is gained during testing, including potential cascading effects on associated systems and network infrastructure. Report high-risk findings immediately to the FAA. \nLead regression penetration testing to validate that previously identified vulnerabilities have been effectively remediated. \nManage and maintain penetration testing tools and environments. All tools must be FAA-approved. No circumvention of access controls or privilege escalation outside approved ROE. \nAttend all Program Management Reviews and report on penetration testing status, findings trends, and upcoming test schedules. \nDevelop briefings to support POAM development and remediation activities. When requested, provide FAA leadership with prioritized remediation recommendations. \nResponsibilities may evolve over time to support team and organizational goals but will remain consistent with the overall scope of the role.\nRequirements\nMinimum Qualifications\nEducation\nBachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Mathematics, Physics, or a related technical discipline from an accredited institution.\nMaster's degree in a related field preferred.\nExperience\nMinimum of fifteen (15) years of cybersecurity experience, including at least 5 years leading or supervising penetration testing teams. \nAt least two (2) years of relevant experience must have been performed within the last 3 years. \nDemonstrated experience planning, executing, and documenting penetration testing engagements in complex, multi-system environments. \nExpert-level proficiency with penetration testing tools such as Metasploit, Burp Suite, Nmap, and related frameworks. \nAbility to conduct manual testing beyond automated tool output. \nExperience conducting manual testing and exploitation beyond automated scanner results. \nDeep understanding of NIST SP 800-115, PTES, OWASP, and industry-standard penetration testing methodologies. \nExperience developing and operating within formal Rules of Engagement (ROE) for penetration testing. \nExperience with red team / blue team exercises including scenario development, execution, and after-action reporting. \nUnderstanding of network exploitation across multi-vendor environments including wireless, routing (Layer 3), switching (Layer 2), firewalls, IDS/IPS, and cloud services. \nSecurity Clearance Requirement\nCandidate must have the ability to obtain and maintain a Public Trust.\nActive Secret clearance is preferred.\nCertifications\nSecurity certification such as OSCP, OSCE, OSWP, OSWE, CEH, ECSA, CEH Practical, ECSA Practical, LPT Master, GCIH, GPEN, GWAPT, GXPN, GAWN, or an equivalent industry-recognized credential.\nAdditional certifications in cyber defense, incident response, digital forensics, or threat detection disciplines are highly preferred, including CND, CNDA, GCIH, GCIA, GDAT, GDSA, GCED, GCFA, or comparable industry-recognized credentials.\nPreferred Qualifications\nPrior experience testing NAS systems, aviation systems, or other air traffic management infrastructure. \nExperience with aircraft cyber testing including avionics, flight control systems, or air-ground communications systems. \nExperience testing industrial control systems (ICS) or operational technology (OT) environments. \nExperience with wireless and satellite-based communication system security testing. \nFamiliarity with DoD offensive/defensive cyber operations frameworks. \nCommand-and-control frameworks (Cobalt Strike, Sliver, Mythic) for realistic adversary simulation during red team exercises. \nActive Directory attack path analysis tools (BloodHound, Impacket) for identifying lateral movement and privilege escalation paths. \nNuclei for scalable automated vulnerability detection beyond legacy scanner coverage. \nCloud-specific penetration testing tools (Pacu for AWS, AzureHound) for cloud-hosted NAS support systems. \nSoftware-defined radio (SDR/HackRF) tools for testing air-to-ground and wireless communications systems that do not traverse physical networks. \nAI-driven fuzzing and adaptive attack path discovery tools for expanding attack surface coverage across complex, interconnected NAS infrastructure. \nOther Required Skills and Abilities\nAbility and willingness to travel and lead on-site penetration testing events at FAA facilities nationwide. \nDemonstrated ability to operate safely and effectively within mission-critical and operationally sensitive environments. \nAbout Us: At OCH, we are more than just a government contracting firm; we are innovators and leaders in providing cutting-edge IT services and cybersecurity solutions. Driven by a set of fundamental values, we excel in creating secure, efficient, and forward-thinking solutions that empower the government agencies we work with. Our commitment to maintaining the highest standards of integrity, adapting swiftly to new challenges, and focusing on the people we serve ensures that we consistently exceed expectations and lead the industry in innovation and reliability.\nWhat Defines Us:\nIntegrity - We act with unwavering honesty, ensuring every decision is rooted ethically. \nAdaptable - We swiftly adapt to changes, seizing opportunities to innovate and lead. \nPeople-Focused - We prioritize relationships, championing growth and mutual success. \nAccountable - We own our outcomes, striving for excellence through continuous improvement. \nCollaborative - We cultivate teamwork, harnessing diverse talents to forge groundbreaking solutions. \n Why Join Us?\nStep into a role at OCH where your contributions make a tangible impact. Join a team that values creativity and initiative, offering a platform to transform the landscape of government IT services. Here, your work is not just a career-it's a mission. Embrace the opportunity to grow, innovate, and excel alongside industry leaders who are as passionate about technology as they are about making a difference. Plus, we offer a comprehensive benefits package designed to support your wellbeing and work-life balance, including:\nPaid time off and Holidays \nMedical, Dental, and Vision Insurance \nPaid Parental Leave \nShort-term disability, long-term disability, and life insurance - Employer Paid! \n401(k) \nAdditional Voluntary Life Insurance \nTuition Reimbursement \n& More!\nE-Verify Participation: OCH Technologies, LLC is a participant of E-Verify to verify the identity and employment eligibility of newly hired employees.\nVeteran’s Preference and Accessibility Statement : At OCH Technologies, we deeply respect and appreciate the unique skills and experiences that veterans bring to our team. As a federal contractor, we encourage qualified veterans to apply and provide preference where permitted by law. Your service and dedication are valued here.\nWe are committed to creating a workplace that is open, welcoming, and accessible to everyone. In accordance with the Americans with Disabilities Act (ADA) and Section 503 of the Rehabilitation Act, we provide reasonable accommodations throughout the hiring process to ensure individuals with disabilities can apply without barriers. If you need assistance or an accommodation, please contact us at .\nOCH Technologies, LLC is proud to be an equal opportunity employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, disability, gender identity, or any other protected characteristic as outlined by federal, state, or local laws.","description_format":"text","description_chars":9438,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":5,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":true},"security_clearance":true,"languages":[]},"benefits":["Life insurance","Parental leave","Vision insurance"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Penetration Testing","Information Security","Application Security","Vulnerability Management"],"lifecycle":[{"event":"open","at":"2026-10-02T09:24:09Z"}],"visa":[],"liveness":{"score":60,"band":"ok","label":"Likely open","p_open":1,"p_active":0.806,"p_room":0.75,"age_days":25,"expected_fill_days":36,"reasons":["conf:2","velocity","win:late"],"computed_at":"2026-10-07T05:47:15Z"},"pay":null,"html_url":"https://alion.io/job/och-technologies-penetration-testing-lead","json_url":"https://alion.io/job/och-technologies-penetration-testing-lead.json","meta":{"generated_at":"2026-10-08T00:21:15Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":331,"day_limit":5000,"remaining_today":4669,"minute_limit":60,"resets_at":"2026-10-09T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":3854350},"rest":"https://alion.io/mcp/rest/get_company?id=3854350"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Foch-technologies-penetration-testing-lead"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Foch-technologies-penetration-testing-lead"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Foch-technologies-penetration-testing-lead"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/och-technologies-penetration-testing-lead\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Foch-technologies-penetration-testing-lead"}]}