> Markdown version of [/jobs/ext/730175-junior-penetration-tester](https://www.wearedevelopers.com/jobs/ext/730175-junior-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Junior Penetration Tester - **Company:** Gunnison Consulting Group Inc - **Location:** Washington, DC, United States (Remote available) - **Experience:** Starter - **Salary:** $65,000.0 - $71,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Burp Suite, Cloud Engineering, Computer Networks, Mobile Application Software, Network Security, Open Web Application Security, Web Applications, Cloud Platform System, Information Technology, Nessus, CIS Benchmarks, Qualys, Vulnerability Analysis - **Published:** June 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=bdff7c66fbb3764d ## About the Role Do you have experience in Vuls?, Do you have a Bachelor's degree?, * Knowledge and experience with manual host testing per CIS benchmarks. * Strong knowledge of and experience with Burp Suite. * Strong knowledge of and experience with Qualys. * 3+ years of experience in the information technology field. * Knowledge of and experience with Nessus. * Knowledge of OWASP Top 10. * Some penetration testing experience required. * Prefer knowledge of and experience with the following tools: + Acunetix + Appdetective + DbVisualizer * Knowledge of NIST SPs and NIST Risk Management Framework (RMF). * Knowledge of computer networking concepts and protocols, and network security methodologies. * Strong attention to detail. Education: Bachelor's Degree in STEM field preferred. Certification: Industry standard certification (e.g. Security+) strongly preferred. Clearance: Ability to obtain and maintain a Public Trust required. The salary range for this position depends upon multiple factors including location, the individual's knowledge, skills, competencies, and experience, and contract-specific budget constraints and organizational requirements. ## Description The Junior Penetration Tester supports security assessments by planning and executing tests on web applications, infrastructure, cloud environments, and other technologies connected to the client network. Responsibilities include developing test plans, performing vulnerability and risk analyses, automating testing processes, and mapping findings to NIST SP 800-53 controls to ensure compliance and improve security posture. * Conduct security testing of IT assets, web applications, infrastructure assets and technologies, mobile applications, custom developed software implementations, virtual technologies, COTS products, cloud implementations, common application platforms, and other technologies connecting to or interacting with the Judiciary network. * Develop and maintain a repeatable methodology for performing security testing. Security test planning should include, but is not limited to: threat modeling, map business requirements to the applicable security requirements, determine appropriate security controls, test scenarios and test cases. * Develop the Security Test Plans. * Perform security testing, vulnerability analysis, and risk analysis in accordance with an industry-proven, repeatable methodology. * Evaluate the effectiveness of security controls as they relate to the applicable security controls of the system tested. * Relate test results to controls in NIST SP 800-53, as reflected in the JISF. * Develop, maintain and use customized testing scripts (testing automation) for individual and team use. * Develop and deliver reports as required. ## Related Videos - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [It's a (testing) trap! - Common testing pitfalls and how to solve them](https://www.wearedevelopers.com/videos/1193-it-s-a-testing-trap-common-testing-pitfalls-and-how-to-solve-them) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [Should senior developers refuse interview coding challenges?](https://www.wearedevelopers.com/magazine/29-should-senior-developers-refuse-interview-coding-challenges)