General Dynamics Information Technology is looking for a Senior Penetration Tester in Ashburn, VA (onsite) to support mission-critical cybersecurity operations. In this role, you will lead advanced penetration testing engagements, emulate real-world adversary behavior, and help drive vulnerability discovery, validation, and remediation through clear, actionable reporting. This position is based on BI Full 6C (T4) public trust and includes a salary range of USD 142,792 - 170,200 per year.
What you’ll do
- Lead complex penetration testing engagements and provide guidance to junior and mid-level testers across scoping, tooling, exploitation techniques, documentation quality, and professional development.
- Plan test approaches, conduct advanced exploitation, and deliver detailed reporting that supports corrective actions for critical systems.
- Define objectives, rules of engagement, and test boundaries in partnership with system owners, ISSOs, engineering leads, and mission stakeholders.
- Create tailored test plans that align with system architecture, threat scenarios, and compliance requirements.
- Perform hands‑on testing across network, application, wireless, and enclave targets using modern red‑team methodologies to discover and validate exploitable weaknesses.
- Use industry tools and frameworks including Nmap, Nessus, Metasploit, Burp Suite, CANVAS, and Kismet to enumerate, exploit, and confirm vulnerabilities at scale.
- Develop proofs of concept, chained exploits, and post‑exploitation procedures that demonstrate realistic impact and help system owners prioritize remediation.
- Produce comprehensive technical reports with vulnerability descriptions, reproduction steps, affected assets, exploit evidence, and prioritized remediation recommendations for both engineering and executive audiences.
- Present findings, defend methodologies, and translate technical risk into mission‑aligned decisions during briefs and touchpoints.
- Partner with developers, system engineers, SOC, and risk teams to recommend mitigation strategies and validate fixes during retesting cycles.
Required qualifications
- Minimum 5 years of offensive security or penetration testing experience, including leading complex assessments and delivering authoritative reports.
- Strong leadership and communication abilities.
- Advanced proficiency with penetration testing tooling and exploitation techniques for network, application, and wireless vectors.
- Strong technical writing and oral presentation skills that meet audit and executive communication standards.
- Ability to collaborate with technical and non‑technical stakeholders across federal and enterprise environments.
- U.S. Citizenship Required.
- Less than 10% travel.
- A degree in cybersecurity, computer science, information technology, or a related field is preferred.
Preferred certifications
- OSCP (highly valued)
- GIAC Penetration Tester (GPEN)
- CREST Registered Pen Tester (CRT)
Additional notes
- Preferred: Previous or Current CBP Background Investigation.
- Clearance level: None.
- Public trust: BI Full 6C (T4).
- Category: Cyber and IT Risk Management.
- Technologies: Nmap, Nessus, Metasploit, Burp Suite, CANVAS, Kismet.
Identity verification process
- Virtual interviews require you to be on camera.
- The company reserves the right to take your picture to verify your identity and prevent fraud.
- You authorize the collection, processing, and use of your biometric data for identity verification and security purposes.