Senior Penetration Tester

GovCIO
Washington, United States of America
yesterday

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior
Compensation
$ 180K

Job location

Washington, United States of America

Tech stack

Amazon Web Services (AWS)
Software System Penetration Testing
Azure
Burp Suite
Cloud Computing
Cross-Site Request Forgery
Linux
Identity and Access Management
Kali Linux
Red Hat Enterprise Linux - RHEL
Zero Trust Network Access
SQL Injection
Web Applications
Google Cloud Platform
Mitre Att&ck
Cross-Site Scripting (XSS)
Metasploit
Vulnerability Analysis

Job description

The Senior Penetration Tester serves as Key Personnel responsible for leading advanced penetration testing and vulnerability assessment activities within a TS/SCI environment. This role ensures mission-critical security assurance across enterprise systems, applications, and cloud infrastructures by applying deep technical expertise, zero-trust principles, and attacker-focused methodologies. The Senior Penetration Tester guides technical direction, ensures rigorous execution, and provides authoritative recommendations to strengthen security posture across sensitive environments.

  • Lead, plan, and oversee penetration testing operations for systems, networks, cloud resources, and web-based applications in a TS/SCI environment
  • Execute comprehensive vulnerability assessments and software assurance evaluations; authoritatively document findings and drive remediation strategies
  • Conduct deep technical analysis of vulnerabilities including buffer overflows, SQL injection, CSRF, XSS, race conditions (TOCTOU), XXE, encryption weaknesses, authentication bypass, and similar issues
  • Assess and advise on security considerations during software acceptance activities, including criteria definition, risk acceptance evaluation, documentation review, and independent validation approaches
  • Apply advanced security defense functions (encryption, access control, identity management) to reduce exploitation risks, including those related to supply chain considerations
  • Provide threat intelligence insights and vulnerability research aligned with frameworks such as NIST 800-53 and MITRE ATT&CK to inform cloud security architecture decisions
  • Develop new or enhanced penetration testing methodologies to identify emerging vulnerabilities and expand organizational capability
  • Serve as a senior technical advisor and mentor to penetration testing staff; ensure consistency, quality, and rigor in testing execution
  • Represent the penetration testing function in discussions with leadership, engineering teams, and mission stakeholders as required for Key Personnel roles

Requirements

  • Bachelor's with 12+ years of penetration testing experience (or commensurate experience)
  • Minimum of 8 years of experience supporting enterprise security architectures and cloud platforms (AWS, Azure, Google Cloud)
  • Proven, extensive experience as a Penetration Tester in complex or classified environments
  • Advanced knowledge of penetration testing methodologies, offensive security techniques, and industry tools
  • Experience with AWS, Azure, RHEL, Linux, and Tenable
  • Hands-on experience with tools including Kali Linux, Burp Suite Pro, and Metasploit
  • Strong analytical and problem-solving skills with an ability to think like an attacker
  • Excellent communication skills to deliver clear, actionable findings to both technical and executive stakeholders
  • Preferred certifications: CEH, OSCP, or equivalent offensive security certifications
  • Clearance Required: Active TS/SCI clearance

Benefits & conditions

USD $124,540.00 - USD $180,000.00 /Yr.

Apply for this position