> Markdown version of [/jobs/ext/564131-penetration-tester-iii](https://www.wearedevelopers.com/jobs/ext/564131-penetration-tester-iii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Penetration Tester III - **Company:** The Sos - **Location:** Washington, DC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Open Web Application Security, Red Team (Cyber Security), Strategies of Testing, Software Vulnerability Management, Cloud Platform System, Mitre Att&ck, Cyber Warfare - **Published:** June 12, 2026 - **Apply:** https://dejobs.org/x/x/7EB1A9231225429B8494ACC8452CEE61/job/ ## About the Role * Experience: * Five (5) to seven (7) years of penetration testing experience * Management or team lead experience * Experience performing continuous penetration testing * Experience conducting red team operations * Experience performing IoT, mobile, and cloud penetration testing * Experience supporting High Value Asset (HVA) assessments * Experience applying MITRE ATT&CK, OSSTMM, OWASP, NIST, PTES, and ISSAF methodologies * Education: * Bachelor's Degree * Certifications: Required: * GPEN or GXPN * CISA AES HVA Lead or Technical Lead , or ability to obtain * Plus one of the following: * GRTP * CRTL * OSCP * CRTP * CMWAPT * CEPT * CPT * LPT * Clearance/Suitability : Secret (active) ## Description SOSi is seeking a Penetration Tester III to support proactive cyber defense activities in alignment with our customer. This role is responsible for conducting penetration testing and red team activities, assessing security posture across enterprise environments, and supporting identification, validation, and reporting of vulnerabilities to improve cyber defense resilience. Responsibilities · Conduct penetration testing across enterprise systems, applications, and network environments · Perform red team activities to evaluate security controls and identify exploitable weaknesses · Support continuous penetration testing activities to assess evolving threats and vulnerabilities · Conduct testing of IoT, mobile, and cloud environments · Support High Value Asset (HVA) security assessments · Apply testing methodologies and frameworks including MITRE ATT&CK, OSSTMM, OWASP, NIST, PTES, and ISSAF · Identify, document, validate, and report vulnerabilities and recommended remediation actions · Support cyber defense operations through coordination with security engineering, vulnerability management, and incident response teams ## Related Videos - [Your Testing Strategy is broken - lets fix it!](https://www.wearedevelopers.com/videos/1672-your-testing-strategy-is-broken-lets-fix-it) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Testing .NET applications a Tool box for every developer](https://www.wearedevelopers.com/videos/704-testing-net-applications-a-tool-box-for-every-developer) - [To Me My X-Tests! - Mutation testing Strategies](https://www.wearedevelopers.com/videos/1959-to-me-my-x-tests-mutation-testing-strategies) - [It's a (testing) trap! - Common testing pitfalls and how to solve them](https://www.wearedevelopers.com/videos/1193-it-s-a-testing-trap-common-testing-pitfalls-and-how-to-solve-them) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)