Penetration Tester

Leidos, Inc.
Alexandria, VA, United States
2 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Compensation
$87,100.0 - $157,450.0
Working hours
Regular working hours

Tech stack

Software System Penetration Testing Cyber Security Data Centers Network Protocols Open Source Technology Red Team (Cyber Security) Security Information and Event Management Strategies of Testing Web Applications Computer Networking Systems Cyber Threat Analysis Information Technology
+3 more
Cybercrime Blue Team (Cyber Security) Vulnerability Analysis

Job description

Leidos is seeking experienced Penetration Tester to support the Defense Manpower Data Center (DMDC) CyberPRIMES program. Leidos is a major partner on the contract and will provide a substantial portion of the cybersecurity workforce supporting the Defense Human Resources Activity (DHRA) and DMDC.

The Penetration Tester will conduct Government-directed penetration testing and threat-hunting assessments across DHRA systems, networks, applications, and supporting technologies. This position will identify exploitable weaknesses, validate the effectiveness of defensive cybersecurity capabilities, and provide actionable findings that help system owners and cybersecurity teams reduce risk., DMDC supports the Defense Human Resources Activity within the Office of the Under Secretary of Defense for Personnel and Readiness (OUSD(P&R)) and maintains the Department of Defense’s largest and most comprehensive central repository of personnel, manpower, casualty, pay, entitlement, personnel security, identity, readiness, training, and related data. The DHRA Information Technology (IT) environment includes approximately 15,000 network and endpoint devices supporting more than 600 Government-Off-The-Shelf (GOTS) applications and approximately 100 Risk Management Framework (RMF) authorization boundaries managed through the Enterprise Mission Assurance Support Service (eMASS).

The penetration-testing team conducts Government-selected assessments of DHRA programs and also performs ad hoc testing with cybersecurity-tool administrators and Security Operations Center personnel to determine whether defensive capabilities are detecting and alerting as intended. Testing may span enterprise networks, web applications, applications, code, and other mission systems., * Conduct Government-selected penetration-testing assessments and threat-hunting activities in accordance with established DMDC procedures and the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-115.

  • Develop assessment plans, methodologies, test objectives, rules of engagement, and technical approaches appropriate to the target environment.
  • Execute authorized penetration-testing activities against networks, systems, applications, web applications, and code.
  • Identify vulnerabilities, exploitable configurations, attack paths, and weaknesses that could be used by a malicious actor.
  • Assess the practical exploitability and potential mission impact of identified security weaknesses.
  • Research emerging and existing threats, attack techniques, vulnerabilities, and adversary behaviors that may affect DHRA systems.
  • Develop testing methodologies designed to identify areas of risk likely to be targeted by an intruder.
  • Conduct threat-hunting activities to identify suspicious or malicious activity that may not be detected through routine monitoring.
  • Perform cooperative testing with cybersecurity-tool administrators, Security Operations Center (SOC) analysts, incident-response personnel, and Security Information and Event Management (SIEM) content developers.
  • Validate whether enterprise cybersecurity tools properly detect, generate alerts for, and support analysis of authorized offensive activity.
  • Identify detection or alerting gaps discovered during testing and provide technical findings to the appropriate cybersecurity teams.
  • Support pre-audit penetration testing to identify exploitable weaknesses before formal assessments or reviews.
  • Apply established penetration-testing methodologies and approved commercial or open-source offensive-security tools.
  • Support Red Team and Blue Team activities designed to evaluate and improve enterprise cybersecurity defenses.
  • Document testing activities, technical evidence, vulnerabilities, exploitation results, and risk findings.
  • Develop post-assessment out-briefs and final assessment reports for Government stakeholders.
  • Provide technically actionable remediation recommendations based on assessment findings.
  • Coordinate findings with system owners, application teams, network engineers, cybersecurity personnel, SOC analysts, and incident responders.
  • Maintain Government-Furnished Equipment and approved penetration-testing systems, laptops, software, and tools required to perform assessments.
  • Protect assessment data, technical artifacts, credentials, exploit information, and other sensitive testing information in accordance with Government requirements.

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical discipline and 4 - 8 years of prior relevant experience in order to operate within the scope contemplated by the level. Specific experience, education and training may be considered in lieu of degree.
  • Experience conducting penetration testing, vulnerability assessment, threat hunting, offensive security, or comparable cybersecurity assessment activities.
  • Experience assessing enterprise networks, systems, applications, web applications, or code for exploitable cybersecurity weaknesses.
  • Experience using commercial or open-source penetration-testing and offensive-security tools.
  • Understanding of common attack techniques, exploitation methods, network protocols, operating systems, and application-security concepts.
  • Experience developing penetration-testing methodologies, test plans, or technical assessment procedures.
  • Experience documenting vulnerabilities, technical evidence, exploitation results, and remediation recommendations.
  • Ability to distinguish theoretical vulnerabilities from weaknesses that present practical exploitation or mission risk.
  • Ability to communicate technical findings clearly to system owners, engineers, cybersecurity personnel, and Government stakeholders.
  • Ability to conduct authorized offensive-security activities within defined rules of engagement and Government-approved procedures.
  • U.S. Citizenship required.
  • Active Secret security clearance required., * Experience conducting penetration testing within Department of Defense or Federal environments.
  • Experience applying National Institute of Standards and Technology Special Publication 800-115 testing methodologies.
  • Experience conducting network, web-application, application, and source-code security assessments.
  • Experience performing threat hunting or adversary-emulation activities.
  • Experience supporting Red Team and Blue Team exercises.
  • Experience working with Security Operations Center analysts and incident responders during cooperative testing.
  • Experience validating SIEM detections, security alerts, or cybersecurity-tool effectiveness using controlled offensive activity.
  • Experience conducting pre-audit or pre-authorization security assessments.
  • Experience researching emerging vulnerabilities, attack techniques, and adversary tradecraft.
  • Experience developing executive and technical penetration-testing out-briefs and assessment reports.
  • Familiarity with Department of Defense Risk Management Framework processes.
  • Familiarity with DHRA, DMDC, or comparable Department of Defense enterprise environments.

Benefits & conditions

Pay and benefits are fundamental to any career decision. That’s why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits .

About the company

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com .

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

51 sec

Exploring offensive security with red team tooling

Stefania Chaplin · World Congress 2022

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

51 sec

Repurposing hardware and operating underwater data centers

Chris Heilmann +1 · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · World Congress 2023

2:11 min

Securing heterogeneous legacy payment infrastructure against AI

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

Videos

See all

Related articles

See all