
Penetration Tester
Posted Sep 15

Posted Sep 15
This is a fully remote position, open to applicants in United States.
• Assist in the planning of assessments by managing test schedules, maintaining scope records, documenting stakeholder coordination, and compiling necessary pre-assessment documentation.
• Aid in controlled discovery, enumeration, testing support, and evidence collection within the designated authorization boundaries.
• Record findings, identify affected assets, document ownership details, reproducibility information, remediation suggestions, and retest requirements for final reporting.
• Facilitate the validation and triage of findings related to external-facing assets, as well as results from CISA WAS, FAST, KEV exposure items, and VDP submissions.
• Manage daily status updates, document meeting notes, track actions, and provide after-action support for assigned testing activities.
• Leverage approved automation and AI-driven tools to enhance data collection, initial correlation, draft reporting, and improve the efficiency of testing workflows.
• Deliver both analytical and practical support for authorized penetration testing initiatives for a major federal agency.
• U.S. Citizenship or Permanent Residency is a prerequisite for this federal engagement.
• Around 2 to 4 years of experience in penetration testing, vulnerability assessments, or a similar offensive/defensive cybersecurity position.
• Proficient understanding of standard penetration testing methodologies and tools, including Burp Suite, Nmap, Metasploit, or their equivalents.
• Knowledge of reconnaissance, enumeration, and evidence collection within authorized testing parameters.
• Excellent written documentation skills for articulating findings, reproducibility steps, and remediation proposals.
• Capability to work fully remote with dependable and secure connectivity.
• Previous experience in federal contracting is preferred.
• Familiarity with CISA Web Application Scanning (WAS) and Fast Attack Surface Testing (FAST) programs is advantageous.
• Understanding of the Known Exploited Vulnerabilities (KEV) catalog and Vulnerability Disclosure Program (VDP) triage is a plus.
• Relevant certifications such as Security+, CEH, GPEN, or OSCP, or actively pursuing these credentials, are preferred.
• Experience with AI-enabled or automation tools to enhance testing and reporting workflows is desirable.
• Strong written and verbal communication skills.
• Detail-oriented with a commitment to thorough documentation practices.
• Ability to operate independently within a remote, distributed team environment.
• Collaborative skills for coordinating with stakeholders and testing leads.
• Effective time management across multiple assessment activities.
• All responsibilities related to this position must be completed within the continental U.S.
• Medical, Multiple POS health plan options including an HSA-compatible plan.
• Dental, PPO coverage for preventive, basic, and major services.
• Vision, Annual exam, frames, lenses, and contact lens allowance.
• 401(k), Employer match up to 5% of eligible compensation.
• Long-Term Disability, 100% employer-paid coverage at 50% of pre-disability earnings.
• Life Insurance and AD&D, 100% employer-paid coverage valued at $10,000 each.
• PTO, 15 to 25 days annually based on tenure.
• Paid Federal Holidays, All 11 federal holidays observed.
• Fully remote work arrangement.
GSB Solutions
Carrington Holding Company, LLC
Capgemini
SAI360
Get handpicked remote jobs straight to your inbox weekly.