> Markdown version of [/jobs/ext/1936530-penetration-testing-sme](https://www.wearedevelopers.com/jobs/ext/1936530-penetration-testing-sme). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Penetration Testing SME - **Company:** Meadowgate Technologies LLC - **Location:** Reston, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Active Directory, Software System Penetration Testing, Burp Suite, Cloud Computing, Cloud Computing Security, Cyber Security, Linux, Systems Analysis, Internet Security, Information Systems Security Architecture Professional, Kali Linux, Nmap, Red Team (Cyber Security), Web Application Security, Web Applications, Computer Networking Systems, Cloud Platform System, Software Security, Mitre Att&ck, SC Clearance, Information Technology, Metasploit, Cybercrime, Nessus, Vulnerability Analysis - **Published:** August 5, 2026 - **Apply:** https://www.careerbuilder.com/job-details/cyber-penetration-tester-sme-active-ts-sci-and-ci-poly-eligible-reston-va--d3820982-ed0c-41dd-84d8-556e9ba69206 ## About the Role * Advanced Penetration Testing Expertise: Proven experience leading and conducting complex penetration tests in enterprise or federal environments, including adversary emulation, red team-style assessments, and validation of security controls against advanced threats * Technical Proficiency in Offensive Security Tooling: Hands-on experience with tools such as Kali Linux, Metasploit, Burp Suite Pro, Cobalt Strike, Nmap, Nessus, BloodHound, Impacket, and other offensive security platforms used for enumeration, exploitation, and reporting * Training and Mentorship Experience: Demonstrated ability to train analysts and junior personnel in penetration testing concepts, offensive tooling, attack lifecycle methodology, and reporting standards * Application and Infrastructure Security Knowledge: Strong understanding of web application security, Active Directory exploitation, privilege escalation, lateral movement, cloud security testing, and common attack vectors affecting modern enterprise environments * Analytical and Collaborative Mindset: Strong ability to analyze complex environments, simulate realistic attack scenarios, and work closely with defenders, engineers, and leadership to improve security controls and reduce organizational risk, * 10+ years of experience in penetration testing, red teaming, or offensive cybersecurity operations * Hands-on experience using industry-standard penetration testing and vulnerability assessment tools (e.g., Burp Suite, Metasploit, Nmap, Nessus, BloodHound, etc.) * Demonstrated experience conducting exploitation, privilege escalation, and lateral movement in authorized environments * Experience training, mentoring, or leading analysts in cybersecurity or offensive security disciplines * Strong understanding of common cyber threats, attack vectors, and adversary tactics (MITRE ATT&CK, etc.) * Bachelor's degree in computer science, Cybersecurity, or related field (or equivalent experience) * Relevant certifications such as OSCP, OSCE, GPEN, GXPN, CISSP, or GIAC preferred * Active Top-Secret Clearance (SCI Eligible) preferred, Analysis Skills, Applications Security, Architectural Analysis, Best Practices, Business Operations, CISSP - Certified Information Systems Security Professional, Change Control, Cloud Applications, Cloud Computing, Computer Science, Computer Security, Financial Trend Analysis, GIAC - Global Information Assurance Certification, GPEN - GIAC Penetration Tester, Government, Incident Response, Industry Standards, Internet Application, Internet Security, Leadership, Leading Edge Technology, Linux Operating System, Machine Tool, Mentoring, Metasploit, Microsoft Active Directory, NMap, Nessus, Network Systems, Penetration Testing, Quality Assurance Methodology, Risk, Risk Analysis, Risk Management, Security Analysis, Security Architecture, Security Attacks, Security Infrastructure, Systems Analysis, Team Player, Technical Leadership, Testing, Top Secret Clearance, Training/Teaching, Wireless Software ## Description We are seeking a highly skilled and proactive Penetration Testing SME to join our Cybersecurity team. As a Penetration Testing SME, you will play a critical role in protecting our clients' infrastructure and data by identifying, testing, and validating security weaknesses across networks, systems, applications, and cloud environments. You will work closely with security engineers, incident responders, system owners, and other stakeholders to assess risk, recommend remediation strategies, and strengthen overall defensive posture. This role also requires the ability to train, mentor, and upskill analysts and team members in penetration testing methodologies, offensive security techniques, and adversary tradecraft., * Conduct advanced penetration testing across enterprise and government environments, including network, web application, wireless, and internal/external assessments * Perform authorized exploitation and post-exploitation activities to validate risk and demonstrate real-world attack impact * Develop and execute penetration testing methodologies, tactics, techniques, and procedures aligned with industry best practices * Analyze security architectures, configurations, and controls to identify gaps and provide actionable remediation recommendations * Produce clear, comprehensive technical reports and executive summaries outlining findings, risk, and mitigation strategies * Collaborate with blue teams, incident responders, system owners, and developers to improve security posture and validate remediation efforts * Stay current on adversary tactics, emerging vulnerabilities, and offensive security trends to continuously enhance testing capabilities * Provide technical leadership and oversight for penetration testing activities across the team * Train, mentor, and develop junior analysts through hands-on instruction, workshops, and knowledge-sharing sessions * Guide team members on offensive tools, methodologies, reporting standards, and operational best practices ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [It's a (testing) trap! - Common testing pitfalls and how to solve them](https://www.wearedevelopers.com/videos/1193-it-s-a-testing-trap-common-testing-pitfalls-and-how-to-solve-them) - [The best of two worlds - Bringing enterprise-grade Linux to the vehicle](https://www.wearedevelopers.com/videos/67-the-best-of-two-worlds-bringing-enterprise-grade-linux-to-the-vehicle) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany)