Penetration Tester

PlanIT Group

Reston (VA)

Hybrid

USD 110,000 - 170,000

Full time

11 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

PlanIT Group seeks an experienced Penetration Tester to perform web, API, and network testing within Reston, VA. The role requires hands-on testing using Burp Suite Pro, Kali Linux, Metasploit Pro, and Cobalt Strike, plus scripting in Python or PowerShell.

You will support PCI-DSS, contribute to blue/purple team exercises, and communicate vulnerabilities with clear risk paths. US citizenship or equivalent clearance may apply.

Qualifications

  • 8+ years of relevant experience required.
  • Certification in penetration testing is recommended (OCSP, GPEN, GWAPT, GXPN).
  • Experience with Red Team engagements from planning to execution.

Responsibilities

  • Lead penetration testing engagements from planning to execution.
  • Coordinate with CSOC and engineering teams for monitoring and defense testing.
  • Assess and report on vulnerabilities with clear remediation paths.

Skills

Web application testing
API testing
Network testing
Scripting (Python/PowerShell)
Technical writing
PCI-DSS support
ASVS & MITRE ATT&CK

Education

Bachelor's degree in a relevant field

Tools

Burp Suite Professional
DAST tools
Kali Linux
Metasploit Pro
Cobalt Strike

Job description

Reston, VA Contract On-Site Flexibility/Remote: 100%

Penetration Tester

Task description and/or any specific requirements:

  • Highly skilled in web application testing, API testing, and network testing
  • Prior experience with Burp Suite Professional, or other similar DAST tools
  • Experience with AI and penetration testing AI
  • Experience with Kali Linux and most of the tools available in the distro for penetration testing
  • Experience with tools such as Metasploit Pro and Cobalt Strike for red team operations
  • Experience with Red Team engagements from planning to execution
  • Experience with phishing network users to gain access for lateral movement on the network
  • Experience with Purple Team engagements to test monitoring controls in coordination with engineering teams and CSOC teams.
  • Proficiency in scripting, such as Python and/or PowerShell
  • Experience with penetration testing supporting PCI-DSS
  • Technical writing skills, along with ease in communicating concepts related to security vulnerabilities and attack path scenarios.
  • Familiar with OWASP Application Security Verification Standard (ASVS) and MITRE Telecommunication&CK framework
  • Penetration testing certification recommended. Acceptable certifications: Offensive Security Certified Professional (OCSP), Global Information Assurance Certification (GIAC) Certifications (e.g., GIAC Certified Penetration Tester (GPEN), GIAC Web Application Penetration Tester (GWAPT), or GIAC Exploit Researcher and Advanced Penetration Tester (GXPN))
Experience
  • A minimum of eight (8) years relevant experience.
  • A degree from an accredited College/University in the applicable field of services is required. If the individual's degree is not in the applicable field then four additional years of related experience is required.
Additional Provisions
  • Pass a client mandated clearance process to include drug screening, criminal history check and credit check.
  • Once candidate's resume is approved and interview passed, the agency is responsible for providing drug screening. Failure to submit the drug screening results will delay the security clearance process.
  • If a candidate is given an interim clearance, continuation of employment is then based on the candidate receiving a sensitive clearance.
  • All candidates must be a US Citizen or permanent status Green Card holder.
  • Cannot have more than 6 months travel outside the United States within the last five years. Military Service excluded. (Exception does not include military family members.)
  • All overtime must be pre-approved in writing by the client manager or his/her designated representative.
  • Agency will not be reimbursed for overtime charges without previous written authorization. Authorized overtime will be reimbursed at straight time.
  • The enforced dress code is business casual, i.e., collared shirt with slacks for men, no skirts above the knee for women.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Penetration Tester
Penetration Tester

Akaasa Technologies • Falls Church (VA)

On-site
USD 120,000 - 180,000
Penetration Tester
Penetration Tester

Arena Technical Resources, LLC • United States

Remote
USD 110,000 - 170,000
Network Penetration Tester – Washington D.C.
Network Penetration Tester – Washington D.C.

Silent Professionals • Washington

On-site
USD 90,000 - 150,000
Comprehensive Health Insurance
401(k) with company match
Access to IT and cyber training courses
+3
Penetration Tester / Secret
Penetration Tester / Secret

Peraton • Washington

On-site
USD 104,000 - 166,000
Penetration Tester
Penetration Tester

TestPros • United States

Remote
USD 143,270,000 - 242,458,000
Penetration Tester
Penetration Tester

NikSoft Systems Corporation • United States

On-site
USD 120,000 - 170,000
Penetration Tester
Penetration Tester

WarCollar Industries, LLC • Herndon (VA)

On-site
USD 110,000 - 180,000
Medical insurance premium coverage
PTO based on billable hours
Federal holidays plus your birthday
+6
Penetration Tester
Penetration Tester

Cybersecurity Jobs • San Antonio (TX)

On-site
USD 90,000 - 140,000
Penetration Tester
Penetration Tester

Cybersecurity Jobs • Nashville (TN)

On-site
USD 90,000 - 140,000
Limited immigration sponsorship may be
Penetration Testing Team Lead
Penetration Testing Team Lead

ecsfederal • Virginia (MN)

Hybrid
USD 170,000 - 190,000