Senior Penetration Tester

Cybersecurity Jobs

Alexandria (VA)

Hybrid

USD 145,000 - 155,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

401(k)
Health insurance
Relocation assistance
Paid time off
Vision insurance

Job summary

Cybersecurity Jobs is seeking a Senior Penetration Tester to lead planning, coordination, execution, and reporting of enterprise penetration testing across agency systems, applications, and infrastructure. The role requires U.S.

citizenship and the ability to satisfy personnel-security requirements for a Non-Sensitive/High-Risk position, with a hybrid work setup in Alexandria, VA. You will collaborate with stakeholders, follow NIST/MITRE/OWASP standards, and drive risk-based remediation

Qualifications

  • U.S. citizenship and ability to satisfy personnel-security requirements for a Non-Sensitive/High-Risk position.
  • Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or related field.
  • Minimum of five years conducting, supporting, or leading penetration tests.
  • Experience assessing enterprise networks, systems, and security controls.
  • Strong knowledge of Windows and Linux, networking, and common protocols.

Responsibilities

  • Plan, coordinate, and execute internal, external, and web application penetration testing across enterprise environments.
  • Develop and maintain CONOPS, SOPs, test plans, and ROE aligned with NIST SP 800-115, MITRE ATT&CK, and OWASP.
  • Coordinate with stakeholders to define scope, objectives, and testing constraints.
  • Perform internal penetration testing using Nmap, Metasploit, Impacket, BloodHound, NetExec and related tools.
  • Execute external and web app penetration testing using Nmap, Nessus, Nuclei, Metasploit, Burp Suite, and ZAP.
  • Lead red team, blue team, and purple team exercises with MITRE ATT&CK-aligned TTPs.

Skills

Penetration testing
Adversary emulation
Technical writing

Education

Bachelor's degree in Computer Science or related field

Tools

Nmap
Metasploit
Nessus
Burp Suite
OWASP ZAP
MITRE CALDERA

Job description

The Senior Penetration Tester role supports a federal cybersecurity program by leading the planning, coordination, execution, and reporting of enterprise penetration testing activities across agency systems, applications, and infrastructure. This position requires U.S. citizenship and the ability to satisfy personnel-security requirements for a Non-Sensitive/High-Risk position.

Location and Employment Details
  • Location: Alexandria, VA (hybrid)
  • Work location: Hybrid remote in Alexandria, VA 22308
  • Ability to commute: Alexandria, VA 22308 (Required)
  • Salary: USD 145,000 - 155,000 per year
  • Minimum experience: 5 years
Responsibilities
  • Plan, coordinate, and execute adversarial-based internal, external, and web application penetration testing across enterprise networks, systems, applications, APIs, and cloud environments.
  • Develop and maintain penetration testing CONOPS, SOPs, methodologies, test plans, Rules of Engagement (ROE), and supporting documentation aligned with NIST SP 800-115, MITRE ATT&CK, and OWASP standards.
  • Coordinate with stakeholders to define assessment scope, objectives, target technologies, testing constraints, authorized TTPs, and success criteria.
  • Conduct internal penetration testing using Nmap, Metasploit, Impacket, BloodHound, NetExec, and other tools to evaluate Active Directory, network segmentation, credential security, privilege escalation, and lateral movement.
  • Perform external penetration testing using Nmap, Nessus, Nuclei, Metasploit, and reconnaissance techniques to identify exploitable vulnerabilities, exposed services, and potential attack paths.
  • Execute web application and API penetration testing using Burp Suite, OWASP ZAP, SQLmap, and other tools to identify authentication, authorization, injection, session management, and OWASP Top 10 vulnerabilities.
  • Conduct red team, blue team, and purple team exercises, adversary emulation, and breach-and-attack simulations using MITRE ATT&CK-aligned TTPs and tools such as MITRE CALDERA and Atomic Red Team.
  • Execute authorized reconnaissance, enumeration, exploitation, credential attacks, privilege escalation, lateral movement, persistence simulation, and post-exploitation analysis to assess enterprise security resilience.
  • Assess security controls, including EDR, IDS/IPS, SIEM detection capabilities, SOC monitoring, and incident response effectiveness against simulated adversarial activity.
  • Validate vulnerabilities through manual and automated testing, controlled exploitation, attack-path analysis, and proof-of-concept demonstrations.
  • Document findings, technical evidence, exploitability, severity, mission impact, and recommended remediation; immediately escalated critical vulnerabilities.
  • Verify remediation through exploit retesting, patch validation, and post-engagement reviews to identify control gaps and improve defensive capabilities.
  • Maintain penetration testing records, findings, remediation tracking, and deliverables while integrating results with vulnerability management, RMF, threat intelligence, and continuous monitoring.
  • Prepare comprehensive technical and executive reports and present attack paths, risk implications, and corrective actions to Government stakeholders and leadership.
Required Qualifications
  • U.S. citizenship and ability to satisfy personnel-security requirements for a Non-Sensitive/High-Risk position.
  • Education: Bachelor of Science in Computer Science, Information Technology, Information Security, Cybersecurity, or a related field.
  • Experience: Minimum of five years conducting, supporting, or leading penetration tests.
  • Demonstrated experience assessing enterprise networks, systems, applications, and security controls.
  • Strong knowledge of Windows and Linux operating systems, network architecture, and common networking protocols.
  • Demonstrated ability to identify, validate, and safely exploit security vulnerabilities.
  • Knowledge of web application technologies, common attack methods, and application-security testing practices.
  • Proficiency with industry-standard penetration-testing, vulnerability-assessment, and exploitation tools.
  • Proficiency with one or more scripting or programming languages used to automate testing, analyze results, or develop custom assessment capabilities.
  • Experience conducting adversary emulation, red team, or purple team exercises using threat-informed tactics, techniques, and procedures.
  • Experience developing Rules of Engagement, test plans, assessment documentation, and technical penetration-testing reports.
  • Ability to translate complex technical findings into clear, risk-based recommendations for technical and nontechnical stakeholders.
  • Strong analytical, problem-solving, technical writing, and verbal communication skills.
Experience Requirements
  • Performing adversarial-based penetration testing: 5 years (Required)
  • Kali Linux, Metasploit, Rapid 7, Cobalt Strike: 3 years (Required)
  • OWASP based web application testing: 3 years (Preferred)
Technologies
  • Nmap, Metasploit, Impacket, BloodHound, NetExec, Nessus, Nuclei
  • Burp Suite, OWASP ZAP, SQLmap
  • MITRE CALDERA, Atomic Red Team, MITRE ATT&CK
  • OWASP, NIST SP 800-115
  • Active Directory, EDR, IDS/IPS, SIEM, RMF
  • Kali Linux, Rapid 7, Cobalt Strike
  • OWASP Top 10
Certifications
  • Required: CEH, OSCP, Pentest+, CPENT
Preferred Qualifications
  • Offensive Security Certified Professional (OSCP), Certified Ethical Hacker (CEH), or a comparable penetration-testing certification.
  • Advanced offensive security certifications such as OSCE, OSEP, OSWE, GPEN, GWAPT, GXPN, or equivalent.
  • Experience conducting penetration tests within federal government or other highly regulated environments.
  • Experience applying NIST guidance and federal cybersecurity requirements to penetration-testing activities and reporting.
  • Experience with APT simulation and threat-informed testing based on frameworks such as MITRE ATT&CK.
  • Experience evaluating SOC detection and response capabilities in coordination with blue teams.
  • Experience testing cloud, identity, web application, endpoint, and network environments.
  • Experience presenting findings and remediation priorities to C-suite, executive, or senior government leadership.
Benefits
  • 401(k)
  • Dental insurance
  • Health insurance
  • Paid time off
  • Relocation assistance
  • Vision insurance
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Penetration Tester Senior
Penetration Tester Senior

Cybersecurity Jobs • Ashburn (VA)

On-site
USD 143,000 - 170,000
Penetration Testing Team Lead
Penetration Testing Team Lead

ECS Corporate Services • Fairfax (VA)

Remote
USD 170,000 - 190,000
Senior Penetration Tester
Senior Penetration Tester

Cybersecurity Jobs • Washington

Hybrid
USD 155,000 - 264,000
Health care
Life insurance
401(k)
+2
Penetration Tester
Penetration Tester

Saic • Texas

Hybrid
USD 120,000 - 160,000
Senior System Security Specialist
Senior System Security Specialist

Compunnel, Inc. • Baltimore (MD)

On-site
USD 120,000 - 150,000
Penetration Tester
Penetration Tester

Saic • Town of Texas (WI)

On-site
USD 120,000 - 160,000
Senior Penetration Tester
Senior Penetration Tester

The Matlen Silver Group, Inc. • Charlotte (NC)

Remote
USD 85,000 - 121,000
Penetration Tester
Penetration Tester

TalentFish • Illinois

On-site
USD 100,000 - 160,000
Penetration Tester
Penetration Tester

SAIC • United States

Remote
USD 120,000 - 160,000
Senior Penetration Tester
Senior Penetration Tester

Cybersecurity Jobs • United States

Remote
USD 125,000 - 145,000
401(k)
Dental insurance
Health insurance
+7