Senior Penetration Tester

Govcio

Washington (District of Columbia)

On-site

USD 124,540 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Employee Assistance Program (EAP)
Corporate Discounts
Learning & Development platform
Training, Education and Certification
Referral Bonus Program
Internal Mobility Program
Pet Insurance
Flexible Work Environment

Job summary

GovCIO is seeking a Senior Penetration Tester with an active TS/SCI clearance to support DHS onsite in Washington, DC. You will lead advanced pentesting within a TS/SCI environment, guiding testing teams and delivering actionable findings to strengthen federal security postures.

Ideal candidates have 12+ years of penetration testing experience, hands-on cloud and enterprise security expertise (AWS, Azure, Google Cloud), and a track record in complex environments.

Qualifications

  • Bachelor's with 12+ years of penetration testing experience (or commensurate experience).
  • 8+ years in enterprise security architectures and cloud platforms (AWS, Azure, Google Cloud).
  • Proven, extensive experience as a Penetration Tester in complex or classified environments.
  • Advanced knowledge of penetration testing methodologies, offensive security techniques, and industry tools.
  • Experience with AWS, Azure, RHEL, Linux, and Tenable.
  • Hands-on experience with Kali Linux, Burp Suite Pro, and Metasploit.
  • Strong analytical and problem‑solving skills with an attacker mindset.
  • Excellent communication skills for technical and executive stakeholders.
  • Preferred certifications: CEH, OSCP, or equivalent offensive security certifications.
  • Clearance Required: Active TS/SCI clearance.

Responsibilities

  • Lead, plan, and oversee penetration testing operations for systems, networks, cloud resources, and web‑based applications in a TS/SCI environment
  • Execute comprehensive vulnerability assessments and software assurance evaluations; document findings and drive remediation strategies
  • Conduct deep technical analysis of vulnerabilities including buffer overflows, SQL injection, CSRF, XSS, race conditions (TOCTOU), XXE, encryption weaknesses, authentication bypass, and similar issues
  • Assess and advise on security considerations during software acceptance activities, including criteria definition, risk acceptance evaluation, documentation review, and independent validation approaches
  • Apply advanced security defense functions (encryption, access control, identity management) to reduce exploitation risks, including those related to supply chain considerations
  • Provide threat intelligence insights and vulnerability research aligned with frameworks such as NIST 800‑53 and MITRE ATT&CK to inform cloud security architecture decisions
  • Develop new or enhanced penetration testing methodologies to identify emerging vulnerabilities and expand organizational capability
  • Serve as a senior technical advisor and mentor to penetration testing staff; ensure consistency, quality, and rigor in testing execution
  • Represent the penetration testing function in discussions with leadership, engineering teams, and mission stakeholders as required for Key Personnel roles

Education

Bachelor's with 12+ years of penetration testing experience (or commensurate experience)

Job description

Overview

GovCIO is currently hiring for a Senior Penetration Tester with an active TS/SCI clearance to support DHS onsite in Washington, DC.

Responsibilities

The Senior Penetration Tester serves as Key Personnel responsible for leading advanced penetration testing and vulnerability assessment activities within a TS/SCI environment. This role ensures mission‑critical security assurance across enterprise systems, applications, and cloud infrastructures by applying deep technical expertise, zero‑trust principles, and attacker‑focused methodologies. The Senior Penetration Tester guides technical direction, ensures rigorous execution, and provides authoritative recommendations to strengthen security posture across sensitive environments.

  • Lead, plan, and oversee penetration testing operations for systems, networks, cloud resources, and web‑based applications in a TS/SCI environment
  • Execute comprehensive vulnerability assessments and software assurance evaluations; authoritatively document findings and drive remediation strategies
  • Conduct deep technical analysis of vulnerabilities including buffer overflows, SQL injection, CSRF, XSS, race conditions (TOCTOU), XXE, encryption weaknesses, authentication bypass, and similar issues
  • Assess and advise on security considerations during software acceptance activities, including criteria definition, risk acceptance evaluation, documentation review, and independent validation approaches
  • Apply advanced security defense functions (encryption, access control, identity management) to reduce exploitation risks, including those related to supply chain considerations
  • Provide threat intelligence insights and vulnerability research aligned with frameworks such as NIST 800‑53 and MITRE ATT&CK to inform cloud security architecture decisions
  • Develop new or enhanced penetration testing methodologies to identify emerging vulnerabilities and expand organizational capability
  • Serve as a senior technical advisor and mentor to penetration testing staff; ensure consistency, quality, and rigor in testing execution
  • Represent the penetration testing function in discussions with leadership, engineering teams, and mission stakeholders as required for Key Personnel roles
Qualifications
  • Bachelor\'s with 12+ years of penetration testing experience (or commensurate experience)
  • Minimum of 8 years of experience supporting enterprise security architectures and cloud platforms (AWS, Azure, Google Cloud)
  • Proven, extensive experience as a Penetration Tester in complex or classified environments
  • Advanced knowledge of penetration testing methodologies, offensive security techniques, and industry tools
  • Experience with AWS, Azure, RHEL, Linux, and Tenable
  • Hands-on experience with tools including Kali Linux, Burp Suite Pro, and Metasploit
  • Strong analytical and problem‑solving skills with an ability to think like an attacker
  • Excellent communication skills to deliver clear, actionable findings to both technical and executive stakeholders
  • Preferred certifications: CEH, OSCP, or equivalent offensive security certifications
  • Clearance Required: Active TS/SCI clearance
Posted Salary Range

USD $124,540.00 - USD $180,000.00 /Yr.

Company Overview

GovCIO is a team of transformers--people who are passionate about transforming government IT. Every day, we make a positive impact by delivering innovative IT services and solutions that improve how government agencies operate and serve our citizens.

But we can\'t do it alone. We need great people to help us do great things - for our customers, our culture, and our ability to attract other great people. We are changing the face of government IT and building a workforce that fuels this mission. Are you ready to be a transformer?

What You Can Expect
Interview & Hiring Process

If you are selected to move forward through the process, here’s what you can expect:

  • During the Interview Process
  • Virtual video interview conducted via video with the hiring manager and/or team
  • Camera must be on
  • A valid photo ID must be presented during each interview
  • During the Hiring Process
  • Enhanced Biometrics ID verification screening
  • Background check, to include:
  • Criminal history (past 7 years)
  • Verification of your highest level of education
  • Verification of your employment history (past 7 years), based on information provided in your application
Employee Perks

At GovCIO, we consistently hear that meaningful work and a collaborative team environment are two of the top reasons our employees enjoy working here. In addition, our employees have access to a range of perks and benefits to support their personal and professional well-being, beyond the standard company offered health benefits, including:

  • Employee Assistance Program (EAP)
  • Corporate Discounts
  • Learning & Development platform, to include certification preparation content
  • Training, Education and Certification Assistance*
  • Referral Bonus Program
  • Internal Mobility Program
  • Pet Insurance
  • Flexible Work Environment

*Available to full-time employees

Our employees’ unique talents and contributions are the driving force behind our success in supporting our customers, which ultimately fuels the success of our company. Join us and be a part of a culture that invests in its people and prioritizes continuous enhancement of the employee experience.

We are an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, disability, or status as a protected veteran. EOE, including disability/vets.

Posted Pay Range

The posted pay range, if referenced, reflects the range expected for this position at the commencement of employment, however, base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, education, experience, and internal equity. The total compensation package for this position may also include other compensation elements, to be discussed during the hiring process. If hired, employee will be in an “at-will position” and the GovCIO reserves the right to modify base salary (as well as any other discretionary payment or compensation program) at any time, including for reasons related to individual performance, GovCIO or individual department/team performance, and market factors.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer
Cybersecurity Engineer

GovCIO • Fort Meade (MD)

On-site
USD 193,000 - 213,000
Employee Assistance Program (EAP)
Corporate Discounts
Learning & Development opportunities
+4
Test Engineer (Remote)
Test Engineer (Remote)

GovCIO • Montgomery (AL)

Remote
USD 85,000 - 95,000
Employee Assistance Program (EAP)
Corporate Discounts
Learning & Development platform
+5
Security Specialist
Security Specialist

GovCIO • Fairfax (VA)

Hybrid
USD 85,000 - 110,000
EAP
Discounts
Learning platform
+5
Network Automations Engineer
Network Automations Engineer

GovCIO • Fort Bragg (NC)

On-site
USD 110,000 - 135,000
Employee Assistance Program (EAP)
Corporate Discounts
Learning & Development platform
+1
Sr. Configuration Manager
Sr. Configuration Manager

GovCIO • Fort Meade (MD)

On-site
USD 125,000 - 135,000
Employee Assistance Program (EAP)
Corporate Discounts
Learning & Development platform
+5
Senior Splunk Engineer - Infrastructure Operations
Senior Splunk Engineer - Infrastructure Operations

GovCIO • Augusta (ME)

Remote
USD 105,000 - 145,000
Employee Assistance Program (EAP)
Corporate Discounts
Learning & Development platform
+5
Systems Architect
Systems Architect

GovCIO • Fort Meade (MD)

On-site
USD 142,000 - 162,000
Employee Assistance Program (EAP)
Corporate Discounts
Learning & Development platform
+5
Penetration Tester
Penetration Tester

CACI International Inc • Chantilly (VA)

On-site
USD 113,000 - 238,000
Healthcare benefits
Wellness programs
Time-off benefits
+1
Database Administrator
Database Administrator

GovCIO • Fort Meade (MD)

On-site
USD 126,000 - 146,000
Employee Assistance Program (EAP)
Corporate Discounts
Learning & Development platform
+5
ServiceNow Workflow Manager
ServiceNow Workflow Manager

GovCIO • Hampton (VA)

On-site
USD 100,000 - 120,000
Employee Assistance Program (EAP)
Corporate Discounts
Flexible Work Environment