> Markdown version of [/jobs/ext/856359-pen-tester-sme-level-4](https://www.wearedevelopers.com/jobs/ext/856359-pen-tester-sme-level-4). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Pen Tester, SME/Level 4 - **Company:** Arcfield, Inc. - **Location:** Chantilly, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cyber Security, Information Systems, Networking Basics, Network Protocols, Comptia Pentest+ CE, Scripting, SARS Software Products, Software Security, Information Technology, Vulnerability Analysis - **Published:** June 2, 2026 - **Apply:** https://www.clearancejobs.com/jobs/8948546/pen-tester-smelevel-4 ## About the Role * Must be able to possess and maintain a TS/SCI clearance with Poly * BS 10-12 Years, MS 8-10 Years, Phd 5-7 Years * Bachelor/STEM with 7+yrs Relevant Experience * Certifications (One or more): + GCIH + GPEN + PenTest+ * Basic scripting abilities * Basic understanding of network fundamentals * Basic understanding of vulnerability scanning tools * Expertise in: + Network protocols + Application security + Social engineering + Advanced scripting * Extensive knowledge of: + Cybersecurity frameworks + Industry standards + Advanced security tools * 6+ yrs-Pen Testing experience * Strong leadership and project management abilities * Excellent communication skills (both written and verbal) * Ability to work with both technical and non-technical stakeholders * Problem-solving and analytical thinking skills * Ability to work under pressure and manage multiple priorities Desired * BS/STEM degree(s) in Computer Science, Information Technology, Cybersecurity, or a related field * Experience with government and military IT systems, particularly in the IC and DoD environments * Understanding of IC and DoD organizational structures and processes * Familiarity with government reporting requirements and procedures * Demonstrated ability to develop innovative solutions for complex technical problems * Recognition as an authority in information security within previous roles * Experience in developing and implementing security policies and procedures ## Description Arcfield's Cyber programs are expanding and currently in need of Penetration Tester (Pen Tester), Level 4 (SME) professionals to review and evaluate NRO Information Systems (IS) and recommend changes to the Government that can improve information confidentiality, integrity, and availability. Note: An offer for this position is contingent upon contract award., * Conduct basic reconnaissance and vulnerability scanning using established methodologies * Identify, document, and report common vulnerabilities that could be exploited * Perform security-focused services to improve the security posture of NRO Information Systems * Execute active and passive penetration testing capabilities on NRO IT assets, as per government policy and direction * Document findings in detailed reports for inclusion in Security Assessment Reports (SARs) * Support Risk Management Framework (RMF) Steps 4 and 6 processes * Review and write Information System Accreditation Packages (ISAPs) and Technical Information System Security Requirements (TISSRs) * Conduct approved testing as well as writing reports following government-approved templates * Complete ISAP/TISSR reports within 30 calendar days of on-site assessment completion * Maintain and update report templates with government approval * Demonstrate basic scripting abilities and understanding of network fundamentals * Proficiently use vulnerability scanning tools * Adhere to rules of engagement agreements between COMM Pen Testers and NRO Program ISO * Collaborate with Program Offices to determine the scope and depth of Information System testing ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Uncertainty Estimation of Neural Networks](https://www.wearedevelopers.com/videos/227-uncertainty-estimation-of-neural-networks) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Dev Digest 182: GPT5 Prompts, MCP Vulnerabilities, Code Traps](https://www.wearedevelopers.com/magazine/622-dev-digest-182-gpt5-prompts-mcp-vulnerabilities-code-traps) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [Dev Digest 129 - Now that's what I call private data!](https://www.wearedevelopers.com/magazine/468-dev-digest-129-now-that-s-what-i-call-private-data)