An application made for this job — a tailored resume and cover letter that speak straight to the posting.
SOSi is seeking a Penetration Tester III to support proactive cyber defense activities across enterprise environments. The role conducts penetration testing and red team activities and reports vulnerabilities with remediation recommendations to improve security posture.
Responsibilities include testing IoT, mobile, and cloud environments, supporting HVA assessments, and applying MITRE ATT&CK, OSSTMM, OWASP, NIST, PTES, and ISSAF methodologies while coordinating with security engineering and
Washington, DC, USA
Full-time
Clearance Requirement: Secret
Founded in 1989, SOSi is among the largest private, founder-owned technology and services integrators in the defense and government services industry. We deliver tailored solutions, tested leadership, and trusted results to enable national security missions worldwide.
SOSi is seeking a Penetration Tester III to support proactive cyber defense activities in alignment with our customer. This role is responsible for conducting penetration testing and red team activities, assessing security posture across enterprise environments, and supporting identification, validation, and reporting of vulnerabilities to improve cyber defense resilience.
Conduct penetration testing across enterprise systems, applications, and network environments
Perform red team activities to evaluate security controls and identify exploitable weaknesses
Support continuous penetration testing activities to assess evolving threats and vulnerabilities
Conduct testing of IoT, mobile, and cloud environments
Support High Value Asset (HVA) security assessments
Apply testing methodologies and frameworks including MITRE ATT&CK, OSSTMM, OWASP, NIST, PTES, and ISSAF
Identify, document, validate, and report vulnerabilities and recommended remediation actions
Support cyber defense operations through coordination with security engineering, vulnerability management, and incident response teams
Experience:
Five (5) to seven (7) years of penetration testing experience
Management or team lead experience
Experience performing continuous penetration testing
Experience conducting red team operations
Experience performing IoT, mobile, and cloud penetration testing
Experience supporting High Value Asset (HVA) assessments
Experience applying MITRE ATT&CK, OSSTMM, OWASP, NIST, PTES, and ISSAF methodologies
Education:
Bachelor’s Degree
Certifications: Required:
GPEN or GXPN
CISA AES HVA Lead or Technical Lead , or ability to obtain
Plus one of the following:
GRTP
CRTL
OSCP
CRTP
CMWAPT
CEPT
CPT
LPT
Clearance/Suitability : Secret (active)
Normal office conditions with potential to perform duties in deployed locations.
Core hours of operation are Monday through Friday, 0600 – 1700.
May be requested to work evenings and weekends to meet program and contract needs.
All interested individuals will receive consideration and will not be discriminated against for any reason.
SOSi is an equal employment opportunity employer and affirmative action employer. All interested individuals will receive consideration and will not be discriminated against on the basis of race, color, religion, sex, national origin, disability, age, sexual orientation, gender identity, genetic information, or protected veteran status. SOSi takes affirmative action in support of its policy to advance diversity and inclusion of individuals who are minorities, women, protected veterans, and individuals with disabilities.