Senior Penetration Tester
GovCIO
Washington, United States of America
yesterday
Role details
Contract type
Permanent contract Employment type
Full-time (> 32 hours) Working hours
Regular working hours Languages
English Experience level
Senior Compensation
$ 180KJob location
Washington, United States of America
Tech stack
Amazon Web Services (AWS)
Software System Penetration Testing
Azure
Burp Suite
Cloud Computing
Cross-Site Request Forgery
Linux
Identity and Access Management
Kali Linux
Red Hat Enterprise Linux - RHEL
Zero Trust Network Access
SQL Injection
Web Applications
Google Cloud Platform
Mitre Att&ck
Cross-Site Scripting (XSS)
Metasploit
Vulnerability Analysis
Job description
The Senior Penetration Tester serves as Key Personnel responsible for leading advanced penetration testing and vulnerability assessment activities within a TS/SCI environment. This role ensures mission-critical security assurance across enterprise systems, applications, and cloud infrastructures by applying deep technical expertise, zero-trust principles, and attacker-focused methodologies. The Senior Penetration Tester guides technical direction, ensures rigorous execution, and provides authoritative recommendations to strengthen security posture across sensitive environments.
- Lead, plan, and oversee penetration testing operations for systems, networks, cloud resources, and web-based applications in a TS/SCI environment
- Execute comprehensive vulnerability assessments and software assurance evaluations; authoritatively document findings and drive remediation strategies
- Conduct deep technical analysis of vulnerabilities including buffer overflows, SQL injection, CSRF, XSS, race conditions (TOCTOU), XXE, encryption weaknesses, authentication bypass, and similar issues
- Assess and advise on security considerations during software acceptance activities, including criteria definition, risk acceptance evaluation, documentation review, and independent validation approaches
- Apply advanced security defense functions (encryption, access control, identity management) to reduce exploitation risks, including those related to supply chain considerations
- Provide threat intelligence insights and vulnerability research aligned with frameworks such as NIST 800-53 and MITRE ATT&CK to inform cloud security architecture decisions
- Develop new or enhanced penetration testing methodologies to identify emerging vulnerabilities and expand organizational capability
- Serve as a senior technical advisor and mentor to penetration testing staff; ensure consistency, quality, and rigor in testing execution
- Represent the penetration testing function in discussions with leadership, engineering teams, and mission stakeholders as required for Key Personnel roles
Requirements
- Bachelor's with 12+ years of penetration testing experience (or commensurate experience)
- Minimum of 8 years of experience supporting enterprise security architectures and cloud platforms (AWS, Azure, Google Cloud)
- Proven, extensive experience as a Penetration Tester in complex or classified environments
- Advanced knowledge of penetration testing methodologies, offensive security techniques, and industry tools
- Experience with AWS, Azure, RHEL, Linux, and Tenable
- Hands-on experience with tools including Kali Linux, Burp Suite Pro, and Metasploit
- Strong analytical and problem-solving skills with an ability to think like an attacker
- Excellent communication skills to deliver clear, actionable findings to both technical and executive stakeholders
- Preferred certifications: CEH, OSCP, or equivalent offensive security certifications
- Clearance Required: Active TS/SCI clearance
Benefits & conditions
USD $124,540.00 - USD $180,000.00 /Yr.