> Markdown version of [/jobs/ext/1364291-penetration-tester](https://www.wearedevelopers.com/jobs/ext/1364291-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Penetration Tester - **Company:** The Judge Group - **Location:** Beltsville, MD, United States - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Application Programming Interfaces (APIs), Amazon Web Services, Apple Mac Systems, Software System Penetration Testing, Microsoft Azure, Bash Shell, Cloud Computing, Cross-Site Request Forgery, Linux, Python (Programming Language), Windows PowerShell, Red Team (Cyber Security), SQL Injection, Software Vulnerability Management, Web Applications, Scripting, Google Cloud, Cloud Platform System, Cross-Site Scripting (XSS), Blue Team (Cyber Security) - **Published:** July 21, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9043882/penetration-tester ## About the Role * Active Security Clearance * Federal Contracting Experience * Familiarity with working in government environments, including compliance with NIST, FISMA, and FedRAMP standards. * Penetration Testing Tools * Vulnerability Remediation * Operating Systems Expertise: * Deep understanding of Windows, Linux, and macOS internals. * Scripting & Programming: * Experience with Python, PowerShell, Bash, or other scripting languages used in automation and exploit development. * Network & Web Application Testing: * Ability to identify and exploit vulnerabilities in networks, APIs, and web applications (e.g., SQLi, XSS, CSRF). * Active Directory & Cloud Environments: * Experience with AD enumeration and exploitation; familiarity with cloud platforms like AWS, Azure, and GCP. * HVA Operator Certification strongly desired * OSCP (Offensive Security Certified Professional) * CEH (Certified Ethical Hacker) * GPEN (GIAC Penetration Tester) * CPT (Certified Penetration Tester) * Strong report writing and communication skills * Ability to brief technical findings to non-technical stakeholders * Team collaboration and red team/blue team coordination experience ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [MCP doesn’t suck — your agent does](https://www.wearedevelopers.com/videos/100202-mcp-doesn-t-suck-your-agent-does) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)