> Markdown version of [/jobs/ext/1239941-penetration-tester](https://www.wearedevelopers.com/jobs/ext/1239941-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Penetration Tester - **Company:** General Dynamics Information Technology - **Location:** Indianapolis, IN, United States - **Experience:** Expert - **Salary:** $123,250.0 - $166,750.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, JavaScript (Programming Language), Application Programming Interfaces (APIs), Agile Methodology, Amazon Web Services, Amazon S3, Application Layers, Software System Penetration Testing, Confluence, JIRA, Automation of Tests, Burp Suite, Cloud Computing, Code Review, Information Systems, Continuous Integration, Github, Monitoring of Systems, Identity and Access Management, Python (Programming Language), Network Security, Nmap, Node.Js, OpenShift, Scrum Methodology, Program Analysis, Power BI, Fortify (Software), Prometheus, Secure Coding, Microsoft SharePoint, Security Information and Event Management, SonarQube, System Testing, Test Case, Web Applications, Datadog, Scripting, Cloud Platform System, ReactJS, Grafana, Software Security, Test Scripts, Amazon Virtual Private Cloud (VPC), GWAPT, Gitlab-ci, Kubernetes, Bug Reporting, Metasploit, Cybercrime, Nessus, Checkmarx, Functional Programming, Cloudwatch, Api Gateway, Restful APIs, Dynatrace, Devsecops, Docker, Elk Stack, Jenkins, Static Application Security Testing, Vulnerability Analysis, Microservices, Dynamic Application Security Testing - **Published:** July 11, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=8b2d7835a40e0de0 ## About the Role * 8+ years of experience in penetration testing, application security, or ethical hacking security roles. * Experience documenting test plans, test procedures, and detailed security findings. * Experience supporting federal security assessments or enterprise-scale security testing. * Hands-on experience performing penetration tests on web applications, APIs, microservices, and cloud environments. * Strong proficiency with tools such as Burp Suite, OWASP ZAP, Metasploit, Nmap, Nessus, Nikto, K6 Security, or custom scripts. * Experience testing applications built with NodeJS, ReactJS, REST APIs, and microservices. * Strong understanding of AWS security, including IAM, VPC, S3, Lambda, API Gateway, ECS/EKS, CloudTrail, and CloudWatch. * Experience with NIST 800-53, RMF, FedRAMP, or federal ATO processes. * Ability to interpret logs, metrics, and security telemetry to identify attack paths. * Familiarity with SIEM and monitoring tools such as Datadog, ELK, CloudWatch, Grafana. * Experience with container security (Docker, Kubernetes, OpenShift). * Understanding of network security, distributed tracing, and adversarial testing techniques. * Strong analytical, communication, and documentation skills., * 8+ years of general experience in information systems with BS/BA Degree, or 6+ years with MA/MS Degree * 6+ years experience with in integration, regression, and system testing using automated testing tools in web-based applications * Experience in writing test cases, test plans, executing test scripts, reporting defects and preparing test results reports * Experience in the entire QA Life Cycle, to include designing, developing and execution on the entire QA process and documentation of test plans, test cases, test procedures and test scripts * Experience may be considered in lieu of degree CERTIFICATIONS: * OSCP, OSWE, GWAPT, GPEN, or similar offensive security certifications. * AWS Security Specialty * SAFe, DevSecOps, or Agile certifications beneficial. TOOLS & TECHNOLOGIES: * Burp Suite, OWASP ZAP, Metasploit, Nmap, Nessus, Nikto * K6 Security, custom Python/JavaScript tools * AWS CloudWatch, CloudTrail, GuardDuty * Datadog, ELK Stack, Prometheus, Grafana * Jenkins, GitLab CI/CD, GitHub Actions * SAST/DAST tools (SonarQube, Checkmarx, Fortify) * Jira, Confluence, SharePoint, MS Teams * Power BI, Grafana dashboards COMMUNICATION & ORGANIZATIONAL * Excellent presentation and communication (oral and written) skills. * Consultant mindset with the ability to work with high level customer stakeholders and build excellent customer relationship. * Experience identifying and applying industry tools, solutions, methods best practices, and emerging technologies. * Strong analytical skills and problem-solving skills with the ability to formulate and communicate recommendations for improvement. * Demonstrated ability to work effectively, independently, and as part of a team. Work Requirements Years of Experience 8 + years of related experience * may vary based on technical training, certification(s), or degree Certification AWS Certified Security - Specialty | Amazon Web Services (AWS) - Amazon Web Services (AWS) ## Description The Penetration Tester supports the Case Management Modernization (CMM) Program for the Administrative Office of the U.S. Courts (AO) by conducting security, penetration, and vulnerability assessments required prior to Application ATO (Authority to Operate). This role ensures that CMM applications-built using React, NodeJS, AWS cloud services, and microservices-meet federal security standards and demonstrate resilience against real-world cyber threats. Working within Agile DevSecOps teams, the Penetration Tester performs hands-on exploitation, validates security controls, identifies weaknesses, and collaborates with engineering teams to remediate findings. This role is critical to ensure that CMM systems comply with NIST 800-53, RMF, and AO security requirements before production authorization., * Perform application, API, and cloud penetration tests on CMM systems prior to ATO submission. * Conduct web, mobile, API, and microservices security testing using industry-standard tools and manual exploitation techniques. * Execute AWS cloud penetration testing within approved boundaries (IAM, S3, Lambda, API Gateway, ECS/EKS, networking). * Perform static and dynamic analysis, including code review for security vulnerabilities. * Conduct credentialed and uncredentialed scans, privilege escalation testing, and lateral movement analysis. * Validate implementation of NIST 800-53 controls, including AC, AU, IA, SC, SI, and CM families. * Support RMF Step 3 (Security Assessment) activities and provide evidence for ATO packages. * Identify vulnerabilities across application layers, cloud infrastructure, and CI/CD pipelines. * Work with developers, cloud engineers, and DevSecOps teams to validate fixes and retest vulnerabilities. * Provide detailed remediation guidance aligned with secure coding and cloud security best practices. * Track findings in Jira or equivalent tools and ensure closure prior to ATO milestones. * Prepare Security Assessment Reports (SAR), penetration test summaries, and risk findings for AO stakeholders. * Document exploitation steps, proof-of-concepts, and risk severity aligned with federal scoring methodologies. * Contribute to System Security Plans (SSP), POA&Ms, and ATO evidence packages. * Support pre-ATO readiness reviews, including control validation and security walkthroughs. * Participate in tabletop exercises, threat modeling sessions, and architecture reviews. * Validate system resilience through stress, failover, and adversarial resilience testing. * Ensure compliance with federal security standards, including NIST, FISMA, and AO-specific guidelines. * Work closely with development teams to integrate security testing into Agile sprints. * Provide security insights during sprint planning, backlog refinement, and release readiness reviews. * Support secure CI/CD pipeline enhancements, including automated security scanning. ## Related Videos - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Integrate your Cognitive Assistant with 3rd-party DBs and software](https://www.wearedevelopers.com/videos/249-integrate-your-cognitive-assistant-with-3rd-party-dbs-and-software) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Why Attend a Developer Event in 2026?](https://www.wearedevelopers.com/magazine/688-why-attend-a-developer-event-in-2026)