> Markdown version of [/jobs/ext/515145-penetration-tester-iii](https://www.wearedevelopers.com/jobs/ext/515145-penetration-tester-iii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Penetration Tester III - **Company:** Revolutional, LLC - **Location:** Chandler, AZ, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Apple IOS, Software System Penetration Testing, Microsoft Azure, Cloud Computing, Cyber Security, Open Web Application Security, Red Team (Cyber Security), Zero Trust Network Access, Google Cloud, Sysadmin, Mitre Att&ck, SC Clearance, GWAPT, Information Technology, Purple Team (Cyber Security) - **Published:** June 12, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=38edf7a1221d10a5 ## About the Role Do you have a Bachelor's degree?, You bring 5 to 7+ years of hands-on penetration testing experience, deep familiarity with industry-standard methodologies, and the technical credibility to lead a team under operational pressure. You think like an adversary, work within rules of engagement, and translate what you find into clear, actionable reporting for both technical and executive audiences., * Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience) * Minimum 5 years of hands-on penetration testing experience; 7 years preferred * Experience in a management or team lead role, managing penetration testing projects and tasks against tight deadlines * Active Secret clearance, * Demonstrated experience with continuous penetration testing methodologies across diverse target environments * Experience planning and conducting Red Team engagements, including scoping, rules of engagement, adversary emulation, and post-engagement reporting * Experience conducting High Value Asset (HVA) assessments in federal environments * Hands-on experience with IoT device penetration testing methodologies * Experience with mobile device application penetration testing across iOS and/or Android platforms * Experience penetration testing federal and commercial cloud environments (AWS, Azure, GCP, or GovCloud) * Knowledge of Red, Blue, and Purple Team assessment processes and how offensive findings translate to defensive improvements * Proficiency with MITRE ATT&CK framework applied to engagement planning, TTP mapping, and findings documentation * Working knowledge of OSSTMM, OWASP, NIST, PTES, and ISSAF penetration testing methodologies * Proficiency with industry-standard penetration testing toolsets for reconnaissance, exploitation, post-exploitation, and reporting, * Senior-level technical operator: you lead engagements, not just execute tasks, and your findings hold up under scrutiny * Methodical and disciplined - you work within rules of engagement, document everything, and don't cut corners under deadline pressure * Strong communicator: your reports are clear, risk-rated, and written for the audience, whether that's a CISO or a sysadmin * Collaborative with defensive teams - you see Purple Team work as a force multiplier, not an afterthought Certifications The following certifications are required: Group 1 - Primary (one required) * GPEN (GIAC Penetration Tester) or GXPN (GIAC Exploit Researcher and Advanced Penetration Tester) Group 2 - Supplemental (one required) * GRTP, CRTL, OSCP (Offensive Security Certified Professional), CRTP, CMWAPT, CEPT, CPT, or LPT, * Both GPEN and GXPN, or additional GIAC offensive certifications (GWAPT, GMOB, GCLOUD) * OSEP (Offensive Security Experienced Penetration Tester) or OSED (Offensive Security Exploit Developer) * Experience conducting HVA assessments as Assessment Lead or Technical Lead under CISA AES * Familiarity with Zero Trust Architecture from an offensive assessment perspective * Experience with AI/ML system security testing or emerging attack surfaces * Active TS/SCI clearance ## Description As a Penetration Tester III at Revolutional, you are a senior offensive security practitioner with the range to operate across network, application, cloud, mobile, and IoT environments - and the experience to lead the engagements, not just execute them. You plan and conduct Red Team operations, High Value Asset assessments, and continuous penetration testing programs against complex federal infrastructure, and you produce findings that drive real security improvements., * Plan, lead, and execute penetration tests across network, application, cloud, mobile, and IoT environments using continuous penetration testing methodologies * Conduct and lead Red Team engagements end-to-end: scoping, planning, execution, post-engagement analysis, and reporting * Perform High Value Asset (HVA) assessments in accordance with CISA AES HVA assessment standards and methodologies * Execute penetration tests against federal and commercial cloud environments, mobile device applications, and IoT devices using appropriate platform-specific methodologies * Apply OSSTMM, OWASP, NIST, PTES, and ISSAF methodologies as appropriate to engagement type, scope, and client requirements * Leverage a broad toolset for reconnaissance, exploitation, post-exploitation, and lateral movement to conduct comprehensive penetration tests * Apply MITRE ATT&CK framework to map adversary TTPs, structure engagement findings, and inform defensive recommendations * Coordinate Blue and Purple Team activities; collaborate with defensive teams to validate detection coverage and improve security posture based on test findings * Produce clear, thorough penetration test reports with well-documented findings, risk ratings, and actionable remediation guidance for technical and executive audiences * Manage penetration testing projects and tasks against tight deadlines; lead and mentor junior testers on engagements * Develop and maintain standard operating procedures, test plans, and technical documentation for penetration testing operations * Stay current on offensive techniques, adversary tradecraft, vulnerability research, and emerging attack surfaces relevant to the federal environment ## Related Videos - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Xcode development redefAIned](https://www.wearedevelopers.com/videos/100195-xcode-development-redefained) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Fake or News: Self-Driving Cars on Subscription, Crypto Attacks Rising and Working While You Sleep - Théodore Lefèvre](https://www.wearedevelopers.com/videos/1793-fake-or-news-self-driving-cars-on-subscription-crypto-attacks-rising-and-working-while-you-sleep-theodore-lefevre) - [Harnessing Apple Intelligence: Live Coding with Swift for iOS](https://www.wearedevelopers.com/videos/1515-harnessing-apple-intelligence-live-coding-with-swift-for-ios) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 182: GPT5 Prompts, MCP Vulnerabilities, Code Traps](https://www.wearedevelopers.com/magazine/622-dev-digest-182-gpt5-prompts-mcp-vulnerabilities-code-traps) - [Should senior developers refuse interview coding challenges?](https://www.wearedevelopers.com/magazine/29-should-senior-developers-refuse-interview-coding-challenges) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)