Penetration Tester
* This position is contingent upon a future opening with Gunnison.
Salary: $150,000 - $170,000/year
Work location: Hybrid, 2-3 days per week on-site in Alexandria, VA. The first 30 days of work will be full-time on-site.
- Coordinate and conduct all Agency penetration testing on systems operated by and on behalf of NCUA, ensuring access to NCUA applications and infrastructure occurs only through NCUA-specified authentication methods and is limited to vetted personnel
- Develop, maintain, and update the Penetration Testing Concept of Operations (CONOPS) and Standard Operating Procedures (SOPs) in accordance with NIST guidance, applicable Federal regulations, and industry best practices
- Coordinate with NCUA prior to each assessment to determine the appropriate assessment model and identify the underlying technology to be tested
- Draft Rules of Engagement and test-specific penetration testing documentation for each engagement
- Perform a range of testing and detection activities — including red teaming, blue teaming, penetration testing, adversary emulation, purple teaming, and breach and attack simulation — to improve SOC operations and strengthen the Agency's overall defensive posture
- Meticulously document all findings and vulnerabilities identified during testing, including categorizing risk, evaluating potential impact, and prioritizing remediation based on severity; provide regular status updates to stakeholders to ensure transparency and timely action
- Simulate advanced persistent threat (APT) scenarios by emulating sophisticated adversary tactics, techniques, and procedures (TTPs) to evaluate system resilience, identify gaps in security posture, and inform enhanced protective measures
- Conduct red and blue team exercises in which the red team simulates attacks and the blue team detects and responds in real time; produce post-exercise reviews highlighting successful detections and areas for improvement
- Execute the full assessment lifecycle, including onboarding, active assessment of the target, findings development, triage, detailed reporting, and patch validation
- Draft and publish a report for each penetration test, including results, findings, and proposed remediation efforts where applicable
- Maintain overall tracking of penetration testing activities across engagements
- Integrate penetration testing with related security efforts, including vulnerability assessments, threat modeling, event detection evaluation, continuous monitoring tool verification, incident response, and incident reporting compliance