> Markdown version of [/jobs/ext/2189231-senior-penetration-tester](https://www.wearedevelopers.com/jobs/ext/2189231-senior-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Penetration Tester - **Company:** ClearFocus Technologies - **Location:** Leesburg, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Cloud Computing Security, IT Management, Mobile Application Software, Wireless Security, Red Team (Cyber Security), Web Application Security, Web Applications, Wireless Networks, Google Cloud, Cloud Platform System, Vulnerability Analysis - **Published:** August 22, 2026 - **Apply:** https://www.careerjet.com/job/use564ddc15524be208a24ea8d54f4869e/eaa ## About the Role * 7+ years of hands-on penetration testing, red team, or offensive security experience. * Experience conducting federal, healthcare, or regulated-industry security assessments. * Ability to obtain and maintain a Tier 4 High Risk Public Trust clearance Strong knowledge of: * Web application security * Active Directory security * Cloud security (AWS, Azure, GCP) * Network and wireless security * Mobile application testing * Social engineering methodologies * NIST SP 800-115 and cybersecurity assessment frameworks * Ability to communicate highly technical information to non-technical audiences. * Ability to obtain and maintain a Public Trust ## Description We are seeking a Senior Penetration Tester for a Part-time opportunity. This opportunity requires travel to throughout the DMV area. The Senior Penetration Tester serves as a technical lead supporting the Department of Health and Human Services (HHS) Office of Inspector General (OIG) Cyber Assessment Team. This position performs advanced penetration testing, vulnerability assessments, security research, exploitation activities, and technical consulting across federal systems, applications, cloud environments, and networks. The individual will lead testing engagements, provide expert recommendations to auditors and stakeholders, develop detailed technical reports, and assist with cybersecurity training initiatives., * Lead penetration testing engagements for web applications, external and internal networks, cloud environments, mobile applications, wireless networks, containers, and emerging technologies. * Conduct reconnaissance, enumeration, vulnerability analysis, exploitation, privilege escalation, persistence, and post-exploitation activities. * Develop and review Rules of Engagement (RoE) documentation and participate in planning meetings, entrance conferences, and results briefings. * Analyze vulnerability scan results and correlate findings from multiple tools to validate security weaknesses and eliminate false positives. * Provide expert technical consulting and security guidance to federal auditors and assessment teams. * Develop attack confirmation documentation, evidence collection packages, and technical recommendations for remediation. * Author formal penetration testing reports, conclusions memoranda, executive summaries, and technical findings. * Present complex technical findings to senior executives, IT management, and technical staff. * Participate in the design and delivery of hands-on cybersecurity training and live demonstrations. * Mentor junior penetration testers and review technical deliverables for quality and accuracy. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) ## Related Articles - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)