Penetration Testing Engineer

Praescient Analytics
Arlington, VA, United States
25 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Data Analysis Software System Penetration Testing Automation of Tests Microsoft Azure Bash Shell Bug Tracking Systems Burp Suite Databases Continuous Integration Software Debugging Identity and Access Management
+22 more
Python (Programming Language) Network Protocols Nmap Open Source Intelligence Open Web Application Security Windows PowerShell Software Architecture Red Team (Cyber Security) Reverse Engineering Secure Coding SQL Injection Wireshark Software Vulnerability Management Web Applications Scripting GWAPT Containerization Metasploit Purple Team (Cyber Security) Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

Praescient Analytics is seeking a seasoned Senior Penetration Testing Engineer to join our team supporting Army programs. The ideal candidate will be an experienced offensive security practitioner with strong hands-on technical skills in penetration testing, vulnerability management, and software/system assurance. This role requires creativity in attack development, excellent reporting skills, and the ability to collaborate with developers, system owners, and leadership to reduce risk across complex environments., * Plan, develop, and execute comprehensive penetration tests against applications, services, hosts, and networks to identify security weaknesses and exploitability.

  • Perform hands-on offensive activities including reverse shells, SQL injection, buffer overflow analysis, trojan/backdoor development, password-cracking, privilege escalation, and social-engineering campaigns where authorized.
  • Conduct threat and vulnerability assessments, risk analysis, and recommend pragmatic mitigation strategies.
  • Develop attack vectors, perform reconnaissance, OSINT collection, enumeration, footprinting, and build exploit payloads/backdoors for testing purposes.
  • Test system and software modifications to validate security posture prior to deployment.
  • Document findings clearly and concisely in vulnerability reports and trackers; maintain databases of known defects and test artifacts.
  • Participate in software design and architecture reviews to provide security input on requirements and operational characteristics.
  • Integrate vulnerability management processes and tools into development/operational workflows; advise on secure coding and configuration baselines.
  • Mentor junior testers and contribute to team best practices, playbooks, and test automation.
  • Support red team / purple team engagements and collaborate with defensive teams to validate mitigations., Real opportunity for career growth in an environment where your achievements will be celebrated. Constant collaboration with numerous teams to ensure client success. A team that respects and embraces your ideas and expertise. Coworkers that are motivated by pursuing excellence, rather than the prospect of personal gain. A workplace dedicated to supporting and improving public safety and government agencies.

Requirements

  • Active TS/SCI clearance - Required
  • GPEN (GIAC Penetration Tester) or OSCP (Offensive Security Certified Professional) - Required.
  • Minimum 5+ years hands-on experience in penetration testing, vulnerability assessment, or offensive security roles.
  • Strong practical experience with common pentest tools and frameworks (e.g., Metasploit, Burp Suite, Nmap, Wireshark, Empire, Cobalt Strike, password-cracking tools) and offensive distributions (Kali, Parrot).
  • An IAT Level III certification (one of the following: CASP, CCNP, CISA, CISSP, IH)
  • Proven ability to develop and modify exploits, payloads, and backdoors; experience with reverse engineering and debugging.
  • Solid programming/scripting skills (Python, Bash, PowerShell). Comfortable reading or writing C/C++/assembly when needed for exploit development or binary analysis.
  • Deep understanding of web application vulnerabilities (OWASP Top 10), network protocols, authentication systems, and privilege escalation techniques.
  • Experience with vulnerability management workflows and bug-tracking systems.
  • Excellent written and verbal communication skills; ability to produce high-quality technical reports tailored to technical and non-technical stakeholders.
  • U.S. citizenship required.

Preferred / Nice-to-Have

  • Experience with targeting cloud platforms (AWS, Azure) and containerized environments.
  • Familiarity with CI/CD security, SAST/DAST tooling, and secure SDLC practices.
  • Experience with red team operations, social engineering campaigns, or physical/technical assessment integration.
  • Additional certifications: OSCE, CREST, CISSP, GWAPT, GPYC, or similar.
  • Prior experience in or supporting Army / DoD programs and mission environments.

Benefits & conditions

Very competitive salary based on qualifications and experience. Comprehensive, Company paid Aetna Health Care Medical for you (We pay your premiums and deductibles) 401(k) with company match Travel & performance incentives 3 weeks paid time off (plus Federal Holidays) $5K annual training allowance $500 book allowance Tuition reimbursement program

About the company

Praescient Analytics is a Certified Woman-Owned Small Business (WOSB) with over a decade of expertise in advanced analytics, engineering, and DevOps, specializing in transforming complex data into actionable intelligence for informed decision-making. Since 2011, we have supported over 40 organizations across diverse domains, including military intelligence operations, financial and fraud investigations, and insider threat detection.

Our team of experts-skilled in cloud computing, artificial intelligence, machine learning, data science, DevOps, and engineering-brings deep experience in solving complex challenges. With a proven track record in federal contracting, we deliver tailored, high-impact solutions designed to enhance operational efficiency, ensure mission success, and address the evolving needs of our clients. Praescient’s innovative and adaptive approach makes us a trusted partner in delivering data-driven insights and technological excellence for critical missions.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:52 min

Refining the agent by automating physical hardware restarts

Marc Plogas Marc Plogas · WWC Europe 2026

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · WWC 2023

2:39 min

Shifting security testing focus toward critical application logic problems

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · WWC Europe 2026

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

4:30 min

Evaluating developer experience constraints in native scripts

Steve Shadders · LIVE

Videos

See all

Related articles

See all