Penetration Tester

M2 Technology Group

Fort Meade (MD)

On-site

USD 175,000 - 235,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

20 Days of Personal Time Off
Three Tiered Medical Plans
$5,500 Medical Opt-Out
Training/Tuition Reimbursements
Referral Bonus

Job summary

M2 Technology Group is seeking a senior-level Penetration Tester and RMF Subject Matter Expert to lead complex security assessments in Fort Meade, Maryland. This role requires at least 12 years of experience in information security and technical testing.

The ideal candidate will provide critical expertise for the Risk Management Framework lifecycle and deliver technical risk reports. Benefits include generous personal time off, medical plans, and significant training reimbursements.

Qualifications

  • Minimum of 12 years of directly related work experience in information security.
  • Proficient in deploying and configuring vulnerability assessment tools.
  • Experience interpreting and applying federal security mandates.

Responsibilities

  • Lead complex security assessments and advanced vulnerability discovery.
  • Direct comprehensive testing phases during assessments.
  • Deliver technical risk reports to system owners.

Skills

Penetration Testing
Risk Management Framework (RMF)
Vulnerability Assessment
Regulatory Compliance
Network Protocols

Education

Bachelor’s Degree in Computer Science or IT Engineering

Tools

Vulnerability Scanners
Exploitation Frameworks
Automated Testing Tools

Job description

M2 Technology Group provides high-assurance cyber and engineering support to federal, defense, and intelligence community programs. We bring that same rigor, discipline, and execution-focused approach to commercial assessments, delivering practical solutions designed for real-world operational environments.

We also have amazing benefits, check them out below!

Role Overview

We are seeking an elite, senior-level Penetration Tester and RMF Subject Matter Expert to lead complex security assessments and drive advanced vulnerability discovery. In this role, you will act as the principal authority on defensive and offensive testing, providing critical technical expertise to support the Risk Management Framework (RMF) lifecycle. You will direct comprehensive testing phases during security controls assessments, leveraging deep, specialized knowledge of network architectures, specialized equipment, operating systems, protocols, and federal compliance standards.

Core Responsibilities & Expanded Penetration Testing Duties
  • RMF & Security Control Testing: Provide senior-level technical expertise to validate, assess, and challenge security controls throughout the RMF lifecycle. Direct and participate in rigorous testing phases during formal authorization assessments.
  • Full-Scope Penetration Testing: Plan, scope, and execute advanced network-level and application-level penetration tests (both black-box and white-box) using established methodologies, framework protocols, and custom exploitation techniques.
  • Red Teaming & Simulation: Emulate sophisticated adversary tactics, techniques, and procedures (TTPs) to evaluate the resilience of enterprise architectures, equipment, and services against live threats.
  • Vulnerability Assessment & Research: Lead active research efforts into emerging technologies, novel exploits, and zero-day vulnerabilities relevant to information systems security to proactively defend agency assets.
  • Post-Exploitation & Risk Analysis: Analyze penetration testing results to determine lateral movement potential, data exfiltration vectors, and the true business or mission impact of discovered vulnerabilities.
  • Regulatory Interpretation & Reporting: Translate complex federal and agency-specific security regulations into actionable engineering and testing criteria. Deliver comprehensive technical risk reports and executive-level briefs detailing mitigation roadmaps for system owners.
Required Qualifications & Experience Matrix
  • Experience Threshold: Minimum of 12 years of directly related work experience in information security and technical testing.
  • Education Substitution: A Bachelor’s Degree in Computer Science or IT Engineering may be substituted for exactly 4 years of experience (requiring 8 years of hands‑on experience alongside the degree).
  • Technical Tool Proficiency: Highly proficient in deploying, configuring, and modifying a diverse toolkit of industry‑standard vulnerability scanners, exploitation frameworks, and automated or manual penetration testing tools.
  • System & Protocol Expertise: Advanced understanding of network protocols, complex enterprise architectures, operating system internals, and modern IT services.
  • Regulatory Knowledge: Proven experience interpreting, applying, and auditing against federal security mandates and agency‑specific regulations.
Compliance, Certifications & Clearance Requirements
  • Mandatory Professional Certifications: Candidates must satisfy DoD 8570.01‑M requirements by holding:
  • IAT Level III or IAM Level III baseline certification.
  • Certified Ethical Hacker (CEH).
  • An active, recognized vendor certification in a major operating system (e.g., Linux/Unix or Windows environments).

Position requires active Security Clearance with appropriate Polygraph

Pay Range:$175 ,000-$235,000

  • Please note that the listed salary range for this position at M2 Technology Group is intended as a helpful guide, not a fixed guarantee. We strive to build offers that are equitable and competitive by looking at a variety of factors. Your final compensation will be tailored based on your individual experience, educational background, specialized skills, and the specific demands of the role.
Personal Time Off & Holidays
  • Employees earn 20 Days of Personal Time Off Annually *Want more? Earn an extra day every anniversary for up to 25 Days!
  • Three Tiered Medical Plans from CareFirst BCBS
  • $5,500 Medical Opt-Out
  • Dental, Vision, LTD and STD- 100% Company-paid
401k (Nothing but the best here!)
  • 10% Employer Contribution (No match needed!) 7% Safe Harbor - 3% Profit Sharing
  • Includes Safe Harbor and Profit Sharing - Immediate Vesting!
Training & Education Reimbursement
  • Up to $7,500 Training/Tuition Reimbursements
  • Flexible Additional Training Support Available Upon Request
Charity Donation Match
  • Feeling Charitable?
  • $250 Annual Donation Match to any Charitable Organization
Pet Adoption
  • Need a furry companion?
Referral Bonus & Company Events
  • $7,500 Referral Bonus
  • Quarterly Happy Hours, Annual Picnic, Holiday Party, Movie Nights, All Hands Meet Ups
Other Perks
  • Swag Drops!, Flexible work schedule, Employee Appreciation Awards, Work Anniversary Gifts, Newborn Gifts
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Mid-Senior System Vulnerability Analyst
Mid-Senior System Vulnerability Analyst

M2 Technology Group • Fort Meade (MD)

On-site
USD 150,000 - 240,000
20 Days of Personal Time Off
Three Tiered Medical Plans
$5,500 Medical Opt-Out
+7
Sr. System Engineer
Sr. System Engineer

M2 Technology Group • Fort Meade (MD)

On-site
USD 175,000 - 220,000
20 Days of Personal Time Off Annually
10% Employer Contribution to 401k
$7,500 Training/Tuition Reimbursement
+1
System Administrator
System Administrator

M2 Technology Group • Fort Meade (MD)

On-site
USD 125,000 - 185,000
20 Days Personal Time Off
10% Employer Contribution to 401k
Training/Tuition Reimbursement up to $7,500
+3
Customer Support Specialist
Customer Support Specialist

M2 Technology Group • Fort Meade (MD)

On-site
USD 125,000 - 165,000
20 Days of Personal Time Off Annually
Medical, Dental, and Vision Plans
$5,500 Medical Opt-Out
+5
Mid-Senior Reverse Engineer
Mid-Senior Reverse Engineer

M2 Technology Group • Fort Meade (MD)

On-site
USD 140,000 - 235,000
20 Days of Personal Time Off Annually
Three Tiered Medical Plans
401k Plan with Employer Contribution
+5
Information System Security Engineer
Information System Security Engineer

M2 Technology Group • Fort Meade (MD)

On-site
USD 155,000 - 255,000
20 Days Personal Time Off annually
10% Employer Contribution to 401k
$7,500 Training/Tuition Reimbursements
+1
Network Engineer 2
Network Engineer 2

M2 Technology Group • Fort Meade (MD)

On-site
USD 155,000 - 190,000
20 Days of Personal Time Off Annually
10% Employer Contribution to 401k
$7,500 Training/Tuition Reimbursements
+2
Penetration Tester
Penetration Tester

LV8D Solutions • Chantilly (VA)

On-site
USD 90,000 - 130,000
401(k) Company Match
Career development
Flexible work hours
Penetration Tester
Penetration Tester

LV8D Solutions, LLC • Chantilly (VA)

Hybrid
USD 90,000 - 130,000
Profit Sharing
401(k) Company Match
Retention Incentive
+3
Information System Security Officer
Information System Security Officer

M2 Technology Group • Fort Meade (MD)

On-site
USD 140,000 - 190,000
20 Days of Personal Time Off
401k with 10% Employer Contribution
$7,500 Training/Tuition Reimbursement
+3