> Markdown version of [/jobs/ext/453937-penetration-tester](https://www.wearedevelopers.com/jobs/ext/453937-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Penetration Tester - **Company:** CACI International Inc. - **Location:** Chantilly, VA, United States - **Salary:** $113,200.0 - $237,800.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Software System Penetration Testing, Bash Shell, Burp Suite, Computer Forensics, Cross-Site Request Forgery, Data Centers, Linux, Perl (Programming Language), VMware ESX Servers, Fuzz Testing, Python (Programming Language), Kali Linux, Open Source Technology, Open Web Application Security, Windows PowerShell, Phishing, Red Team (Cyber Security), Ruby, Single Sign-On, SQL Injection, System Programming, TCP/IP, Web Applications, Scripting, Malware, Cyber Threat Analysis, Cross-Site Scripting (XSS), GWAPT, Metasploit, Iptables, Blue Team (Cyber Security) - **Published:** June 3, 2026 - **Apply:** https://dejobs.org/x/x/6A38DA2D03B1477AB78D9D0FF870961A/job/ ## About the Role Required: Experience performing Red Team, Blue Team Operations. Certifications such as OSCP, OSCE, GPEN, GWAPT, GPEN, GXPN, CEH, CISSP. Malware analysis or digital computer forensics experience. Cyber related Law Enforcement or Counterintelligence experience. Scripting (Windows/*nix), Bash, Python, Perl or Ruby, Systems Programming is a plus. Existing Subject Matter Expert of Advanced Persistent Threats and Emerging Threats. Proactive interest in emerging technologies and techniques related to penetration testing. Demonstrated real world experience performing grey and black box penetration testing. Have an understanding of and interest in common web application vulnerabilities like XSS, CSRF, Command Injection, SQLi, single sign-on limitations, etc. Must be proficient in any of the following: PowerShell Empire, Metasploit Framework, Cobalt Strike, Burp Suite, Canvas, Kali Linux, IPTables, Sysinternals, A/V evasion methodologies, Exploit Dev. Must have solid working experience and knowledge of Windows operating systems (incl. Active Directory), Linux operating systems; ESXi or similar; mobile platforms are a plus. Solid understanding of networking, TCP/IP, virtualization and cloud/data center architecture. Strong familiarity with some of the following: OWASP top 10, DoD and NSA Vulnerability and Penetration Testing Standards. Knowledge of exploitation concepts including phishing and social engineering tactics, buffer overflows, fuzzing, SQLi, MiTM, covert channels, secure tunneling and open source exfiltration techniques. Bachelors degree in related field. Active TS/SCI w/polygraph clearance. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Capture the Flag 101](https://www.wearedevelopers.com/videos/416-capture-the-flag-101) - [Fireside Chat with Werner Vogels, VP & CTO, Amazon.com & Daniel Gebler, CTO at Picnic](https://www.wearedevelopers.com/videos/1405-fireside-chat-with-werner-vogels-vp-cto-amazon-com-daniel-gebler-cto-at-picnic) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Should senior developers refuse interview coding challenges?](https://www.wearedevelopers.com/magazine/29-should-senior-developers-refuse-interview-coding-challenges) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)