> Markdown version of [/jobs/ext/2981977-penetration-tester](https://www.wearedevelopers.com/jobs/ext/2981977-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Penetration Tester - **Company:** ASRC FEDERAL - **Location:** Washington, DC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cloud Computing Security, Linux, Information Systems Security Architecture Professional, Forescout, Tenable Nessus, Purple Team (Cyber Security), Blue Team (Cyber Security), Vulnerability Analysis - **Published:** September 18, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9176030/penetration-tester ## About the Role * Education: Bachelor's degree in a related field. * Experience: 8+ years of relevant experience in cybersecurity and penetration testing (or equivalent combination of education and experience). * Clearance: Active DOE Q-Clearance or Top Secret (TS) equivalent required. * Certifications (Preferred): + OSCP (Offensive Security Certified Professional) + OSCE (Offensive Security Certified Expert) + CEH (Certified Ethical Hacker) + CISSP (Certified Information Systems Security Professional) Technical Skills & Tools * Strong proficiency in vulnerability analysis, risk remediation, and reporting. * Ability to clearly replicate vulnerabilities and provide actionable mitigation steps. * Familiarity with tools including: + Linux, Tenable Nessus, Forescout, Carbon Black, Invicti, + Scythe, Rubrik, Fidelis * Excellent written and verbal communication skills; ability to present technical findings to executive audiences. ## Description * Lead and perform advanced security assessments, including hands-on penetration testing of systems and applications. * Identify vulnerabilities, assess risks, and deliver clear, actionable remediation recommendations. * Develop and maintain assessment plans aligned withNIST SP 800-53 and FedRAMP Cloud Security Controls. * Execute security assessments per defined plans and document findings accurately and promptly. * Design, develop, and maintain tools/scripts to automate and enhance penetration testing activities. * Manage and mentor a small team of junior penetration testers; provide technical guidance and training. * Build and lead a Purple Team to perform joint red/blue team exercises with customer sites. * Support secure systems operations and maintenance, including security validation and accreditation activities. * Analyze and mitigate system security threats throughout the lifecycle, including risk assessments and implementation of security engineering controls. * Ensure compliance with business continuity, operations security, insider threat detection, physical security analysis, and regulatory requirements. * Communicate technical findings effectively to technical teams and executive stakeholders. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Capture the Flag 101](https://www.wearedevelopers.com/videos/416-capture-the-flag-101) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)