> Markdown version of [/jobs/ext/536316-senior-penetration-tester](https://www.wearedevelopers.com/jobs/ext/536316-senior-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Penetration Tester - **Company:** BIG IMPACT TECH CORP - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Automation of Tests, Burp Suite, Nmap, Open Web Application Security, Web Applications, GWAPT, Nessus - **Published:** June 10, 2026 - **Apply:** https://www.clearancejobs.com/jobs/8966236/senior-penetration-tester ## About the Role * Minimum 8-10 years of professional penetration testing experience * Demonstrated experience leading enterprise penetration testing engagements * Strong understanding of NIST SP 800-115, PTES, OWASP, and industry best practices * Excellent written and verbal communication skills * Strong organization and project documentation abilities * Ability to independently manage testing activities and deliverables Preferred Certifications: * OSCP * PNPT * GPEN * GWAPT * CISSP * CEH, * Examples of prior penetration testing reports (sanitized versions acceptable) * References or examples of previous client engagements * Proposed fixed-price quote for the engagement * Estimated timeline for completion * Brief overview of testing methodology and reporting approach Preference will be given to candidates with prior consulting experience and a demonstrated ability to communicate findings effectively to both technical and executive audiences. All testing tools and associated licenses must be provided by the selected contractor. ## Description We are seeking a Senior Lead Penetration Tester to support an upcoming client engagement involving external network, web application, and security assessment activities. This is a fixed-price project with the potential for recurring quarterly assessments and future client engagements. Responsibilities: * Lead the execution of an external penetration test against approved client assets * Conduct vulnerability identification, validation, and controlled exploitation activities * Perform web application and public-facing infrastructure assessments * Validate findings and eliminate false positives * Develop technical and executive-level reporting * Participate in client coordination discussions as needed * Support remediation validation and retesting activities, Required Deliverables: * Penetration Test Plan * Asset and Scope Coverage Summary * Technical Findings Report * Risk Register & Findings Tracker * Attack Narrative / Exploitation Path Analysis * Executive Summary Report * Prioritized Remediation Plan * Risk Register Development * Remediation Validation Report (Retest) * Defined Risk Register Matrix Important Evaluation Criteria: Our biggest concern is finding a tester who can do more than simply operate security tools. Most penetration testers can: * Run Nmap * Run Nessus * Run Burp Suite Far fewer can: * Write a professional executive report suitable for leadership review * Build a clear attack narrative that demonstrates business impact * Map findings to NIST, CMMC, and compliance requirements * Present findings and recommendations in a professional manner to technical and non-technical stakeholders Candidates should be prepared to demonstrate both technical expertise and the ability to communicate findings effectively. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [It's a (testing) trap! - Common testing pitfalls and how to solve them](https://www.wearedevelopers.com/videos/1193-it-s-a-testing-trap-common-testing-pitfalls-and-how-to-solve-them) - [Testing .NET applications a Tool box for every developer](https://www.wearedevelopers.com/videos/704-testing-net-applications-a-tool-box-for-every-developer) ## Related Articles - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Should senior developers refuse interview coding challenges?](https://www.wearedevelopers.com/magazine/29-should-senior-developers-refuse-interview-coding-challenges) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Benefits of Using JMeter For Performance Testing](https://www.wearedevelopers.com/magazine/96-benefits-of-using-jmeter-for-performance-testing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)