Senior Penetration Tester / Vulnerability Assessment Engineer

Cybersecurity Jobs

Washington (District of Columbia)

On-site

USD 180,000 - 230,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Tharros is seeking a Senior Penetration Tester / Vulnerability Assessment Engineer to support DHS with vulnerability identification, assessment, and validation across cloud and on-prem environments. The role requires on-site work in a Government SCIF in Washington, DC.

This position covers the full lifecycle of testing and reporting, from engagement through exploitation to post-exploitation, yielding actionable security improvements.

Qualifications

  • BS degree or 10+ years IT/cybersecurity experience.
  • Experience in penetration testing and vulnerability assessment.
  • Knowledge of MITRE ATT&CK, OWASP, PTES.

Responsibilities

  • Conduct penetration tests using MITRE ATT&CK and OWASP.
  • Apply manual testing to find hidden vulnerabilities.
  • Validate SOC incident response procedures.
  • Perform software assurance and secure code reviews.
  • Review source code with automated and manual methods.
  • Conduct vulnerability assessments and SCRM reviews.
  • Maintain testing kit and update SOPs.

Skills

Manual testing
Penetration testing
Vulnerability assessment
Technical reporting
Clear communication

Education

BS in IT/Cybersecurity/CS

Tools

Burp Suite
Metasploit
Core Impact
SonarQube
Fortify
Microsoft Office Suite
Teams
AWS
Azure

Job description

Tharros is seeking a Senior Penetration Tester / Vulnerability Assessment Engineer to support the Department of Homeland Security (DHS) with vulnerability identification, assessment, and validation across both cloud and on-premise environments. The position focuses on expert-driven, manual testing and requires on-site work within a Government SCIF in Washington, DC.

This role covers the full lifecycle of penetration testing and vulnerability assessment activities, from executing engagements through exploitation and post-exploitation, to producing actionable reporting and updating security procedures.

Responsibilities
  • Conduct penetration tests across the DHS IE portfolio using established methodologies (including MITRE ATT&CK and OWASP), covering rules of engagement through exploitation, post-exploitation, and reporting.
  • Apply manual techniques to identify vulnerabilities that automated tools commonly miss.
  • Validate SOC incident response procedures through controlled testing.
  • Perform software assurance activities through vulnerability and compliance testing of software requests, including providing approval recommendations.
  • Carry out source code reviews using both automated tooling and manual review approaches.
  • Execute vulnerability assessments and perform supply chain risk management (SCRM) reviews.
  • Maintain the security posture of the penetration testing kit used for engagements.
  • Update penetration testing, SCRM, and vulnerability assessment SOPs.
Requirements
  • BS degree in Information Technology, Cybersecurity, Information Systems, or Computer Science, or minimum of 10 years’ experience in IT or cybersecurity.
  • Minimum of 7 years’ experience in penetration testing or vulnerability assessment.
  • Active TS/SCI clearance and U.S. citizenship; willingness to undergo a DHS counterintelligence-scope polygraph.
  • Knowledge of penetration testing methodologies and frameworks, including MITRE ATT&CK, OWASP, and PTES.
  • Knowledge of software assurance and secure code review practices.
  • Knowledge of common attack vectors across network, application, and cloud layers.
  • Ability to perform manual exploitation using tools such as Burp Suite, Metasploit, or Core Impact.
  • Skill in static code analysis using tools such as SonarQube or Fortify.
  • Ability to write clear penetration test reports, including recommended corrective actions.
  • Proficiency in Microsoft Office Suite, including Teams or similar workplace chat and videoconferencing tools.
  • Excellent written and oral communications skills.
Technologies
  • MITRE ATT&CK, OWASP, PTES
  • Burp Suite, Metasploit, Core Impact
  • SonarQube, Fortify
  • Microsoft Office Suite, Teams
  • AWS, Azure
Desired
  • OSCP, GPEN, GWAPT, CEH, or CISSP certification.
  • Cloud (AWS, Azure) or Cross Domain Solution testing experience.

Location: Washington, DC (onsite)

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Penetration Tester & Vulnerability Expert DC Onsite
Senior Penetration Tester & Vulnerability Expert DC Onsite

Cybersecurity Jobs • Washington

On-site
USD 180,000 - 230,000
Senior Penetration Tester
Senior Penetration Tester

Cybersecurity Jobs • Washington

Hybrid
USD 155,000 - 264,000
Health care
Life insurance
401(k)
+2
Junior Security Engineer
Junior Security Engineer

Cybersecurity Jobs • Washington

On-site
USD 90,000 - 130,000
Penetration Tester
Penetration Tester

Akaasa Technologies • Falls Church (VA)

On-site
USD 120,000 - 180,000
Penetration Testing Team Lead
Penetration Testing Team Lead

ecsfederal • Virginia (MN)

Hybrid
USD 170,000 - 190,000
Senior Penetration Tester at Gray Tier Technologies Ashburn, VA
Senior Penetration Tester at Gray Tier Technologies Ashburn, VA

Gray Tier Technologies • Ashburn (VA)

On-site
USD 100,000 - 130,000
Security Control Assessor
Security Control Assessor

ANALYGENCE • Washington

On-site
USD 120,000 - 180,000
Expert Penetration Tester
Expert Penetration Tester

Amatriot Group, LLC • United States

Hybrid
USD 200,000 - 215,000
Junior Security Control Assessor
Junior Security Control Assessor

ANALYGENCE • Washington

On-site
USD 65,000 - 90,000
Junior Security Engineer
Junior Security Engineer

ANALYGENCE • Washington

On-site
USD 75,000 - 110,000