Quick Overview
Salary
$100k - $130k/yr
Seniority
Mid Senior
Employment type
Employee
Work mode
Remote
Location
Ashburn, VA, United States
Posted
Yesterday
Penetration Testing
Job Description
Penetration Tester The Penetration Tester Mid independently plans and performs authorized penetration testing activities across systems, applications, networks, wireless environments, and other assigned technologies. The role develops testing approaches and Rules of Engagement, validates exploitability, produces defensible reports, and advises stakeholders on remediation.
Location
- Primary duty location: Government site in the Washington, DC metropolitan area, primarily Ashburn, VA.
- Telework may be approved, but should not be the expectation.
- Travel to CBP locations may be required based on assigned work; role-specific travel expectations are identified below
- 3+ years of penetration testing, vulnerability assessment, red-team, application security, network security, or related experience
- Experience with approved penetration testing methodologies, Rules of Engagement, vulnerability exploitation, evidence handling, technical reporting, and remediation validation
- Hands-on knowledge of network, web application, database, mobile, wireless, cloud, and operating-system security testing techniques appropriate to the role level
- Ability to document reproducible findings, business and technical impact, evidence, and actionable remediation recommendations
- Security+ required; CEH, PenTest+, OSCP, GPEN, GWAPT, or comparable technical certification preferred
- Strong written communication, operational discipline, and ability to work under tightly controlled testing authorities
- U.S. citizenship and ability to obtain and maintain the required CBP background investigation
- Conduct authorized penetration tests supporting security control assessments, accreditation, continuous monitoring, FISMA requirements, and system-owner requests
- Develop Rules of Engagement and test plans for review and approval before testing
- Execute approved testing procedures, collect and protect evidence, validate exploitability, and avoid unauthorized impact to systems or networks
- Prepare detailed assessment reports, executive summaries, findings, and remediation recommendations for system owners, ISSOs, ISSMs, and Government leads
- Maintain assessment records, metrics, knowledge-base content, and repositories of prior findings and remediation results
- Support retesting, comparative analysis, adversarial assessments, cooperative vulnerability penetration assessments, and purple-team activities
- Coordinate with SOC, CTI, CDF, vulnerability assessment, and system stakeholders to emulate relevant IOCs, TTPs, and CWEs
- Support wireless, radio-frequency, mobile application, HVA, and on-site assessments as assigned
- Travel CONUS and OCONUS, including CBP locations in the United States, Puerto Rico, and Guam, when required for approved assessments
Similar jobs
- CA
Payload Operations Systems Engineer with Security Clearance
NewCACI
Danbury, CT🇺🇸$94.4k - $198.2k/yrHybridYesterdayMATLABTechnology - WS
AI/ML Software Developer with Security Clearance
NewWarriors Solutions
Tysons, VA🇺🇸HybridYesterdayJavaJavaScriptLLM+1Technology - AE
Full-Stack Developer | Contingent | Washington, DC with Security Clearance
NewARES Enterprise
Washington, DC🇺🇸HybridYesterdayOracleSQLAWS+2Technology - ML
Associate Staff - Space Systems Engineer with Security Clearance
NewMIT Lincoln Laboratory
Lexington, MA🇺🇸$116.4k - $140k/yrHybridYesterdayMATLABC++PythonTechnology - BT
Cloud Architect/Engineer with Security Clearance
NewBluemont Technology & Research, Inc.
Bethesda, MD🇺🇸HybridYesterdayAWSAzureTechnology - CA
Mid-Level Oracle Database Administrator (US Citizens only) with Security Clearance
NewCALNET, Inc.
Washington, DC🇺🇸HybridYesterdayMariaDBOracleEncryptionTechnology