Penetration Tester
Posted 12hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Penetration Testing Analyst supporting authorized assessments for federal agencies. Conducting reconnaissance, evidence collection, triage, and reporting at Dragonfli Group, a cybersecurity and IT consulting firm.
Responsibilities:
- Support assessment planning by maintaining test schedules, scope records, stakeholder coordination notes, and required pre-assessment documentation
- Assist with controlled discovery, enumeration, testing support, and evidence capture within approved authorization boundaries
- Document findings, affected assets, ownership, reproducibility details, remediation recommendations, and retest requirements for final reports
- Support validation and triage of external-facing asset findings, CISA WAS and FAST results, KEV exposure items, and VDP submissions
- Coordinate daily status inputs, meeting notes, action tracking, and after-action support for assigned testing activities
- Use approved automation and AI-enabled tools to improve data collection, initial correlation, draft reporting, and testing workflow efficiency
- Provide analytical and hands-on support for authorized penetration testing activities for a large federal agency
Requirements:
- U.S. Citizenship or Permanent Residency required for this federal engagement
- Approximately 2 to 4 years of experience in penetration testing, vulnerability assessment, or a related offensive/defensive cybersecurity role
- Working knowledge of common penetration testing methodologies and tools, such as Burp Suite, Nmap, Metasploit, or equivalents
- Familiarity with reconnaissance, enumeration, and evidence collection within authorized testing boundaries
- Strong written documentation skills for findings, reproducibility steps, and remediation recommendations
- Ability to work fully remote with reliable, secure connectivity
- Previous federal contracting experience preferred
- Exposure to CISA Web Application Scanning (WAS) and Fast Attack Surface Testing (FAST) programs preferred
- Familiarity with Known Exploited Vulnerabilities (KEV) catalog and Vulnerability Disclosure Program (VDP) triage preferred
- Relevant certifications such as Security+, CEH, GPEN, or OSCP, or actively pursuing, preferred
- Experience using AI-enabled or automation tools to support testing and reporting workflows preferred
- Strong written and verbal communication
- Attention to detail and thorough documentation habits
- Ability to work independently in a remote, distributed team
- Collaborative coordination with stakeholders and testing leads
- Time management across concurrent assessment activities
- All work related to this role must be performed within the continental U.S.
Benefits:
- Medical, Multiple POS health plan options including an HSA-compatible plan
- Dental, PPO coverage for preventive, basic, and major services
- Vision, Annual exam, frames, lenses, and contact lens allowance
- 401(k), Employer match up to 5% of eligible compensation
- Long-Term Disability, 100% employer-paid coverage at 50% of pre-disability earnings
- Life Insurance and AD&D, 100% employer-paid coverage valued at $10,000 each
- PTO, 15 to 25 days annually based on tenure
- Paid Federal Holidays, All 11 federal holidays observed
- Fully remote work arrangement


















