Penetration Tester

ASRC FEDERAL
Washington, DC, United States
6 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours

Tech stack

Software System Penetration Testing Cloud Computing Security Linux Information Systems Security Architecture Professional Forescout Tenable Nessus Purple Team (Cyber Security) Blue Team (Cyber Security) Vulnerability Analysis

Job description

  • Lead and perform advanced security assessments, including hands-on penetration testing of systems and applications.
  • Identify vulnerabilities, assess risks, and deliver clear, actionable remediation recommendations.
  • Develop and maintain assessment plans aligned withNIST SP 800-53 and FedRAMP Cloud Security Controls.
  • Execute security assessments per defined plans and document findings accurately and promptly.
  • Design, develop, and maintain tools/scripts to automate and enhance penetration testing activities.
  • Manage and mentor a small team of junior penetration testers; provide technical guidance and training.
  • Build and lead a Purple Team to perform joint red/blue team exercises with customer sites.
  • Support secure systems operations and maintenance, including security validation and accreditation activities.
  • Analyze and mitigate system security threats throughout the lifecycle, including risk assessments and implementation of security engineering controls.
  • Ensure compliance with business continuity, operations security, insider threat detection, physical security analysis, and regulatory requirements.
  • Communicate technical findings effectively to technical teams and executive stakeholders.

Requirements

  • Education: Bachelor’s degree in a related field.
  • Experience: 8+ years of relevant experience in cybersecurity and penetration testing (or equivalent combination of education and experience).
  • Clearance: Active DOE Q-Clearance or Top Secret (TS) equivalent required.
  • Certifications (Preferred):
  • OSCP (Offensive Security Certified Professional)
  • OSCE (Offensive Security Certified Expert)
  • CEH (Certified Ethical Hacker)
  • CISSP (Certified Information Systems Security Professional)

Technical Skills & Tools

  • Strong proficiency in vulnerability analysis, risk remediation, and reporting.
  • Ability to clearly replicate vulnerabilities and provide actionable mitigation steps.
  • Familiarity with tools including:
  • Linux, Tenable Nessus, Forescout, Carbon Black, Invicti,
  • Scythe, Rubrik, Fidelis
  • Excellent written and verbal communication skills; ability to present technical findings to executive audiences.

Benefits & conditions

We invest in the lives of our employees, both in and out of the workplace, by providing competitive pay and benefits packages. Benefits offered may include health care, dental, vision, life insurance; 401(k); education assistance; paid time off including PTO, holidays, and any other paid leave required by law. The salary offered will depend on several factors including, but not limited to, relevant experience, skills, education, geographic location, internal equity, business needs, and other factors permitted by law. Posted pay ranges are a general guideline only and are not a guarantee of compensation or salary.

About the company

ASRC Federal is a leading government contractor furthering missions in space, public health and defense. As an Alaska Native owned corporation, our work helps secure an enduring future for our shareholders. Join our team and discover why we are a top veteran employer and Certified Great Place to Work

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

51 sec

Exploring offensive security with red team tooling

Stefania Chaplin · World Congress 2022

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

1:51 min

Leveraging continuous penetration testing via red teams

Reto Kaeser · LIVE

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · World Congress 2023

8:22 min

Simulating a Linux terminal and running Spring Boot

Jakov Semenski · LIVE

Videos

See all

Related articles

See all