Mid-Level Penetration Tester
Posted 12hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Mid-Level Penetration Tester conducting authorized assessments for a cybersecurity and IT consulting firm serving federal agencies and Fortune 100 enterprises. Testing networks, applications, infrastructure, and vulnerabilities remotely.
Responsibilities:
- Plan and execute authorized penetration tests across network, endpoint, wireless, database, application, and infrastructure environments
- Follow structured Planning, Discovery, Testing, and Reporting phases
- Develop and tailor Rules of Engagement, Execution Plans, daily status updates, and final reporting inputs
- Coordinate with system owners, SOC personnel, and other stakeholders on scope, test windows, prerequisites, safety thresholds, and stop/pause procedures
- Validate vulnerabilities arising from misconfigurations, outdated software, weak access controls, incomplete control implementation, and exploitable attack paths
- Support validation of CISA WAS, CISA FAST, KEV exposure, and external-facing asset findings
- Coordinate retesting to confirm closure
- Use approved automated and AI-enabled tools to improve reconnaissance, testing efficiency, ATT&CK/ATLAS mapping, evidence development, and reporting while maintaining human oversight
- Mentor junior testing staff
- Independently lead assessments with minimal oversight
Requirements:
- U.S. Citizenship or Permanent Residency required for this federal engagement
- Approximately 5 to 8 years of experience conducting or leading penetration testing engagements
- Demonstrated ability to plan and execute assessments across network, endpoint, wireless, database, application, and infrastructure environments
- Experience developing Rules of Engagement, Execution Plans, and formal, decision-ready reporting for stakeholders
- Experience coordinating directly with system owners and SOC personnel on scope, safety thresholds, and stop/pause procedures
- Ability to work fully remote with reliable, secure connectivity
- Previous federal contracting experience preferred
- Experience with CISA WAS, CISA FAST, and KEV validation and retest workflows preferred
- Familiarity with MITRE ATT&CK and ATLAS mapping preferred
- Advanced certifications such as OSCP, OSCE, GPEN, or GXPN preferred
- Experience integrating AI-enabled tools into testing workflows while maintaining human oversight of results preferred
Benefits:
- Medical, multiple POS health plan options including an HSA-compatible plan
- Dental, PPO coverage for preventive, basic, and major services
- Vision, annual exam, frames, lenses, and contact lens allowance
- 401(k) with employer match up to 5% of eligible compensation
- Long-Term Disability, 100% employer-paid coverage at 50% of pre-disability earnings
- Life Insurance and AD&D, 100% employer-paid coverage valued at $10,000 each
- 15 to 25 PTO days annually based on tenure
- All 11 federal holidays observed


















