> Markdown version of [/jobs/ext/2655138-penetration-tester](https://www.wearedevelopers.com/jobs/ext/2655138-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Penetration Tester - **Company:** Guidepoint Global, LLC - **Location:** Alexandria, VA, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Applicant Tracking Systems, Software System Penetration Testing, Cyber Security, Information Systems, Networking Hardware, Open Web Application Security, Cloud Services, System Testing, Web Applications, Scripting, Advanced Reports, Information Technology, Nessus, Purple Team (Cyber Security), Network Server, Automation Anywhere, Vulnerability Analysis - **Published:** August 10, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88010371/1 ## About the Role * Ability to obtain and maintain a Public Trust clearance. * Bachelor's degree in computer science, Cybersecurity, Information Systems, Engineering, or a related technical field, or equivalent experience. * 5 years of experience leading penetrating testing * Experience developing custom scripts for certain exploit scenarios and tailoring attack scenarios to test specific system vulnerabilities. * Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes, * Experience performing red-team or penetration testing engagements in a federal environment. * Penetration testing on HVA assets in a federal environment. * Hands-on experience with Meterpreter Pro, Nessus, and Cobalt Strike. * US Government Clearance preferred "Applicants selected will be subject to a security investigation and must meet eligibility requirements for access to classified information." We use Greenhouse Software as our applicant tracking system and Zoom Scheduler for HR screen request scheduling. At times, your email may block our communication with you. Please be sure to check your SPAM folder so that you don't miss updates on your application. ## Description The Pen Tester role will be responsible for performing comprehensive Risk and Vulnerability Analysis (RVA) assessments, functioning as penetration and purple team assessments. The role will be in response to performing penetration testing engagements using major frameworks like OWASP and NIST, against a range of technologies such as web applications, servers, operating systems, cloud services, AI workflows, and network devices. Onsite requirement (Candidates must reside within the Washington, D.C. metropolitan area) - This role supports a federal customer in Alexandria, VA. What You'll Get To Do: * Perform analysis of submitted findings and vulnerabilities and provide a written report covering risk, likelihood of exploitation, and recommendations for remediation. * Handle vetting of multiple vulnerabilities simultaneously, demonstrating efficiency and organization, to ensure all vulnerabilities are addressed in a timely manner. * Swiftly confirm or deny the legitimacy of submitted vulnerabilities, ensuring rapid response times while maintaining the integrity of the vulnerability disclosure process. * Provide insightful guidance and support to system owners regarding the agency's patching processes and timelines, helping them navigate and comply with these procedures. * Ensure all findings and analyses are reported in a timely and efficient manner, maintaining a consistent flow of information and updates. * Provide comprehensive start-to-finish RVA assessments, encompassing initial customer outreach, meticulous planning, thorough execution, and detailed reporting. * Utilize expertise in assessing both current and emerging technology platforms and architectures, ensuring assessments are relevant and comprehensive. * Conduct expert-level assessments using major frameworks like OWASP and NIST, covering a range of technologies such as web applications, servers, operating systems, cloud services, AI workflows, and network devices. * Perform in-depth insider threat analysis, integrating it as a crucial part of the assessment process to identify potential internal security risks. * Research and simulate emerging zero-day threats, creating mock-up scenarios to demonstrate the feasibility of exploitation and assess system vulnerabilities. * Develop custom scripts for specialized exploitation scenarios, tailoring attack strategies to effectively test specific system vulnerabilities. * Demonstrate hands-on experience with popular penetration testing software such as Meterpreter Pro, Nessus, and Cobalt Strike, using these tools to conduct thorough assessments. * Analyze vulnerability scans and perform follow-on testing of systems to verify exploitability, ensuring comprehensive identification of security weaknesses. * Conduct trend analysis across assessments to identify common vulnerabilities among disparate systems, aiding in the development of targeted security strategies. * Develop SOPs and best practices for penetration testing and vulnerability assessment, documenting these in corporate knowledge repositories for enterprise-wide distribution. * Communicate technical issues effectively to non-technical management, translating complex cybersecurity concepts into understandable terms. * Work within corporate issue and knowledge tracking systems, providing continuous status updates on projects and ensuring seamless integration with existing workflows. * Test and document new tools, techniques, tactics, and scripts for usability security acceptance testing. ## Related Videos - [Let’s write an exploit using AI](https://www.wearedevelopers.com/videos/1004-let-s-write-an-exploit-using-ai) - [Kubernetes Security - Challenge and Opportunity](https://www.wearedevelopers.com/videos/412-kubernetes-security-challenge-and-opportunity) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Hiring AI Native Talents](https://www.wearedevelopers.com/videos/100268-hiring-ai-native-talents) - [tRPC: API schemas are pure overhead](https://www.wearedevelopers.com/videos/796-trpc-api-schemas-are-pure-overhead) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 129 - Now that's what I call private data!](https://www.wearedevelopers.com/magazine/468-dev-digest-129-now-that-s-what-i-call-private-data) - [Dev Digest 182: GPT5 Prompts, MCP Vulnerabilities, Code Traps](https://www.wearedevelopers.com/magazine/622-dev-digest-182-gpt5-prompts-mcp-vulnerabilities-code-traps)