Mid-Level Penetration Tester

Posted 12hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Mid-Level Penetration Tester conducting authorized assessments for a cybersecurity and IT consulting firm serving federal agencies and Fortune 100 enterprises. Testing networks, applications, infrastructure, and vulnerabilities remotely.

Responsibilities:

  • Plan and execute authorized penetration tests across network, endpoint, wireless, database, application, and infrastructure environments
  • Follow structured Planning, Discovery, Testing, and Reporting phases
  • Develop and tailor Rules of Engagement, Execution Plans, daily status updates, and final reporting inputs
  • Coordinate with system owners, SOC personnel, and other stakeholders on scope, test windows, prerequisites, safety thresholds, and stop/pause procedures
  • Validate vulnerabilities arising from misconfigurations, outdated software, weak access controls, incomplete control implementation, and exploitable attack paths
  • Support validation of CISA WAS, CISA FAST, KEV exposure, and external-facing asset findings
  • Coordinate retesting to confirm closure
  • Use approved automated and AI-enabled tools to improve reconnaissance, testing efficiency, ATT&CK/ATLAS mapping, evidence development, and reporting while maintaining human oversight
  • Mentor junior testing staff
  • Independently lead assessments with minimal oversight

Requirements:

  • U.S. Citizenship or Permanent Residency required for this federal engagement
  • Approximately 5 to 8 years of experience conducting or leading penetration testing engagements
  • Demonstrated ability to plan and execute assessments across network, endpoint, wireless, database, application, and infrastructure environments
  • Experience developing Rules of Engagement, Execution Plans, and formal, decision-ready reporting for stakeholders
  • Experience coordinating directly with system owners and SOC personnel on scope, safety thresholds, and stop/pause procedures
  • Ability to work fully remote with reliable, secure connectivity
  • Previous federal contracting experience preferred
  • Experience with CISA WAS, CISA FAST, and KEV validation and retest workflows preferred
  • Familiarity with MITRE ATT&CK and ATLAS mapping preferred
  • Advanced certifications such as OSCP, OSCE, GPEN, or GXPN preferred
  • Experience integrating AI-enabled tools into testing workflows while maintaining human oversight of results preferred

Benefits:

  • Medical, multiple POS health plan options including an HSA-compatible plan
  • Dental, PPO coverage for preventive, basic, and major services
  • Vision, annual exam, frames, lenses, and contact lens allowance
  • 401(k) with employer match up to 5% of eligible compensation
  • Long-Term Disability, 100% employer-paid coverage at 50% of pre-disability earnings
  • Life Insurance and AD&D, 100% employer-paid coverage valued at $10,000 each
  • 15 to 25 PTO days annually based on tenure
  • All 11 federal holidays observed