Penetration Tester III

The Sos
Washington, DC, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Shift work
Job source

Tech stack

Software System Penetration Testing Open Web Application Security Red Team (Cyber Security) Strategies of Testing Software Vulnerability Management Cloud Platform System Mitre Att&ck Cyber Warfare

Job description

SOSi is seeking a Penetration Tester III to support proactive cyber defense activities in alignment with our customer. This role is responsible for conducting penetration testing and red team activities, assessing security posture across enterprise environments, and supporting identification, validation, and reporting of vulnerabilities to improve cyber defense resilience.

Responsibilities

· Conduct penetration testing across enterprise systems, applications, and network environments

· Perform red team activities to evaluate security controls and identify exploitable weaknesses

· Support continuous penetration testing activities to assess evolving threats and vulnerabilities

· Conduct testing of IoT, mobile, and cloud environments

· Support High Value Asset (HVA) security assessments

· Apply testing methodologies and frameworks including MITRE ATT&CK, OSSTMM, OWASP, NIST, PTES, and ISSAF

· Identify, document, validate, and report vulnerabilities and recommended remediation actions

· Support cyber defense operations through coordination with security engineering, vulnerability management, and incident response teams

Requirements

  • Experience:
  • Five (5) to seven (7) years of penetration testing experience
  • Management or team lead experience
  • Experience performing continuous penetration testing
  • Experience conducting red team operations
  • Experience performing IoT, mobile, and cloud penetration testing
  • Experience supporting High Value Asset (HVA) assessments
  • Experience applying MITRE ATT&CK, OSSTMM, OWASP, NIST, PTES, and ISSAF methodologies
  • Education:
  • Bachelor’s Degree
  • Certifications: Required:
  • GPEN or GXPN
  • CISA AES HVA Lead or Technical Lead , or ability to obtain
  • Plus one of the following:
  • GRTP
  • CRTL
  • OSCP
  • CRTP
  • CMWAPT
  • CEPT
  • CPT
  • LPT
  • Clearance/Suitability : Secret (active)

Benefits & conditions

  • Normal office conditions with potential to perform duties in deployed locations.
  • Core hours of operation are Monday through Friday, 0600 - 1700.
  • May be requested to work evenings and weekends to meet program and contract needs.

Working at SOSi

All interested individuals will receive consideration and will not be discriminated against for any reason.

About the company

Founded in 1989, SOSi is among the largest private, founder-owned technology and services integrators in the defense and government services industry. We deliver tailored solutions, tested leadership, and trusted results to enable national security missions worldwide.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · WWC Europe 2026

1:53 min

Actionable steps to improve team testing strategies immediately

Luise Freese Luise Freese · WWC 2025

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · WWC 2023

51 sec

Exploring offensive security with red team tooling

Stefania Chaplin · WWC 2022

4:04 min

Testing strategies and philosophical approaches for modern application delivery

Lian Li · WWC 2023

8:08 min

Addressing questions on development practices and testing strategies

Mesut Ayata Mesut Ayata · WWC 2024

Videos

See all

Related articles

See all