Penetration Testing Lead

Jobtailor

Washington (District of Columbia)

On-site

USD 180,000 - 240,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking a senior cybersecurity leader to serve as the primary technical contact for penetration testing across network, system, and application domains, including aircraft cyber. You will develop ROE, ensure scope clarity, and drive high‑complexity engagements in NAS and Mission Support environments.

You will guide red/blue team exercises, craft attack scenarios, document PTRs, and report findings to FAA, while overseeing testing tools and FAA‑approved environments.

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Mathematics, Physics, or a related technical discipline from an accredited institution.
  • Minimum of fifteen (15) years of cybersecurity experience, including at least five (5) years leading or supervising penetration testing teams.
  • At least two (2) years of relevant experience performed within the last three (3) years.
  • Demonstrated experience planning, executing, and documenting penetration testing engagements in complex, multi‑system environments.
  • Expert‑level proficiency with penetration testing tools such as Metasploit, Burp Suite, Nmap, and related frameworks.
  • Ability to conduct manual testing beyond automated tool output.
  • Deep understanding of NIST SP 800‑115, PTES, OWASP, and industry‑standard penetration testing methodologies.
  • Experience developing and operating within formal Rules of Engagement (ROE) for penetration testing.
  • Experience with red team / blue team exercises, including scenario development, execution, and after‑action reporting.
  • Understanding of network exploitation across multi‑vendor environments, including wireless, routing (Layer 3), switching (Layer 2), firewalls, IDS/IPS, and cloud services.
  • Candidate must have the ability to obtain and maintain a Public Trust; an active Secret clearance is preferred.

Responsibilities

  • Serve as primary technical point of contact for all penetration testing activities, including network, system, application, aircraft cyber, and specialized assessments.
  • Develop Rules of Engagement (ROE) with system owners and ACG for each penetration test.
  • Ensure all parties understand scope, constraints, and reporting requirements before testing begins.
  • Personally lead high‑complexity penetration tests in NAS and Mission Support environments.
  • Direct testing teams during execution.
  • Plan and execute red team and blue team exercises in simulated environments as directed by the FAA.
  • Design realistic attack scenarios that test the effectiveness of NAS cybersecurity defenses.
  • Document all penetration test results in Penetration Test Reports (PTRs) including attack vectors tested, vulnerabilities discovered, exploitation paths, and recommended remediation actions.
  • Assess and document impact when access is gained during testing, including potential cascading effects on associated systems and network infrastructure.
  • Report high‑risk findings immediately to the FAA.
  • Lead regression penetration testing to validate that previously identified vulnerabilities have been effectively remediated.
  • Manage and maintain penetration testing tools and environments; all tools must be FAA‑approved.
  • Attend all Program Management Reviews and report on penetration testing status, findings trends, and upcoming test schedules.

Job description

Responsibilities
  • Serve as primary technical point of contact for all penetration testing activities, including network, system, application, aircraft cyber, and specialized assessments.
  • Develop Rules of Engagement (ROE) with system owners and ACG for each penetration test.
  • Ensure all parties understand scope, constraints, and reporting requirements before testing begins.
  • Personally lead high‑complexity penetration tests in NAS and Mission Support environments.
  • Direct testing teams during execution.
  • Plan and execute red team and blue team exercises in simulated environments as directed by the FAA.
  • Design realistic attack scenarios that test the effectiveness of NAS cybersecurity defenses.
  • Document all penetration test results in Penetration Test Reports (PTRs) including attack vectors tested, vulnerabilities discovered, exploitation paths, and recommended remediation actions.
  • Assess and document impact when access is gained during testing, including potential cascading effects on associated systems and network infrastructure.
  • Report high‑risk findings immediately to the FAA.
  • Lead regression penetration testing to validate that previously identified vulnerabilities have been effectively remediated.
  • Manage and maintain penetration testing tools and environments; all tools must be FAA‑approved.
  • Attend all Program Management Reviews and report on penetration testing status, findings trends, and upcoming test schedules.
Requirements
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Mathematics, Physics, or a related technical discipline from an accredited institution.
  • Minimum of fifteen (15) years of cybersecurity experience, including at least five (5) years leading or supervising penetration testing teams.
  • At least two (2) years of relevant experience performed within the last three (3) years.
  • Demonstrated experience planning, executing, and documenting penetration testing engagements in complex, multi‑system environments.
  • Expert‑level proficiency with penetration testing tools such as Metasploit, Burp Suite, Nmap, and related frameworks.
  • Ability to conduct manual testing beyond automated tool output.
  • Deep understanding of NIST SP 800‑115, PTES, OWASP, and industry‑standard penetration testing methodologies.
  • Experience developing and operating within formal Rules of Engagement (ROE) for penetration testing.
  • Experience with red team / blue team exercises, including scenario development, execution, and after‑action reporting.
  • Understanding of network exploitation across multi‑vendor environments, including wireless, routing (Layer 3), switching (Layer 2), firewalls, IDS/IPS, and cloud services.
  • Candidate must have the ability to obtain and maintain a Public Trust; an active Secret clearance is preferred.
Core Competencies

Demonstrates expert‑level proficiency in penetration testing, including planning, executing, and documenting complex engagements. Capable of leading teams in high‑complexity environments while ensuring compliance with established methodologies and reporting standards.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Penetration Tester
Penetration Tester

Jobtailor • Washington

On-site
USD 120,000 - 180,000
Penetration Tester
Penetration Tester

ANALYGENCE • San Antonio (TX)

On-site
USD 90,000 - 120,000
Penetration Testing Lead
Penetration Testing Lead

Ochtec • Washington

Hybrid
USD 180,000 - 240,000
Paid time off and Holidays
Medical, Dental, Vision Insurance
401(k)
+1
Senior Penetration Testing Lead - Red/Blue Team Expert
Senior Penetration Testing Lead - Red/Blue Team Expert

Jobtailor • Washington

On-site
USD 180,000 - 240,000
Penetration Tester
Penetration Tester

nDepth Security, LLC • Columbia (MD)

On-site
USD 90,000 - 120,000
Penetration Tester / Red Team Operator
Penetration Tester / Red Team Operator

Digital-Global-Connectors • McLean (VA)

Hybrid
USD 110,000 - 170,000
Penetration Tester / Red Team Operator
Penetration Tester / Red Team Operator

Digital Global Connectors • McLean (VA)

Hybrid
USD 120,000 - 190,000
Penetration Tester
Penetration Tester

Decision Point Security, Inc • Eglin Air Force Base (FL)

On-site
USD 80,000 - 120,000
Jr Cyber Penetration Tester
Jr Cyber Penetration Tester

Peraton • Virginia (MN)

Hybrid
USD 70,000 - 90,000
Security Assessment Lead
Security Assessment Lead

Jobtailor • Oklahoma

On-site
USD 180,000 - 230,000