> Markdown version of [/jobs/ext/1181273-penetration-tester](https://www.wearedevelopers.com/jobs/ext/1181273-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Penetration Tester - **Company:** WarCollar Industries - **Location:** Herndon, VA, United States - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Network Protocols, Web Application Security, Cloud Platform System, Cyber Warfare, Vulnerability Analysis - **Published:** July 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=4784e045056a3a4f ## About the Role Experience conducting penetration testing or offensive cyber operations. Knowledge of network protocols, operating systems, web application security, and common attack techniques. Experience with industry-standard penetration testing tools and frameworks. Strong understanding of vulnerability analysis, exploitation techniques, and security best practices. Excellent analytical, technical writing, and communication skills. Relevant certifications such as OSCP, GPEN, CEH, CISSP, or equivalent are a plus. ## Description WarCollar Industries is seeking a highly skilled Penetration Tester to support a mission-critical Federal client. If you're passionate about offensive cybersecurity, identifying vulnerabilities before adversaries do, and protecting national security systems, we'd like to speak with you. As a Penetration Tester, you will perform technical security assessments against customer systems in support of certification, accreditation, and overall cyber resilience. You'll leverage industry-leading tools and advanced technical expertise to identify vulnerabilities, simulate real-world attack scenarios, and deliver actionable recommendations that strengthen enterprise security., Conduct penetration tests against networks, applications, operating systems, and cloud environments. Perform vulnerability assessments using automated and manual testing techniques. Simulate adversary tactics, techniques, and procedures (TTPs) to identify exploitable weaknesses. Document findings, assess risk, and provide detailed remediation recommendations. Collaborate with cybersecurity engineers, system administrators, and stakeholders to improve security posture. Support security validation efforts for Certification & Accreditation (C&A) activities. Stay current on emerging threats, attack vectors, and offensive security methodologies. , Desired Skills ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cloud Vendor Lock-In - Is it just a new version of the Database Abstraction Layers?](https://www.wearedevelopers.com/videos/1185-cloud-vendor-lock-in-is-it-just-a-new-version-of-the-database-abstraction-layers) - [MySQL Protocol Features You Should Be Aware Of](https://www.wearedevelopers.com/videos/100267-mysql-protocol-features-you-should-be-aware-of) - [It's a (testing) trap! - Common testing pitfalls and how to solve them](https://www.wearedevelopers.com/videos/1193-it-s-a-testing-trap-common-testing-pitfalls-and-how-to-solve-them) - [Hosting a modern justice system](https://www.wearedevelopers.com/videos/332-hosting-a-modern-justice-system) - [The Vonage Trivia Voyage: Quiz Your Way to the Top!](https://www.wearedevelopers.com/videos/761-the-vonage-trivia-voyage-quiz-your-way-to-the-top) ## Related Articles - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)