
Senior Penetration Tester – Assessments Lead
Posted 10 hours ago

Posted 10 hours ago
This is a fully remote position, open to applicants in United States.
• Oversee assigned penetration-testing projects from the initial scoping and development of rules-of-engagement to test planning, execution, reporting, out-briefing, and clarification of remediation.
• Convert client objectives, system architectures, constraints, and safety requirements into structured assessment plans that include authorization boundaries and conflict resolution procedures.
• Guide and mentor junior testers while executing intricate attack paths involving networks, web/API, Active Directory/AD CS, Linux, Windows, AWS, Azure, and identity-focused assessments.
• Confirm vulnerabilities through safe manual testing and controlled exploitation, ensuring no disruption to operations or alteration of live data.
• Analyze scanner outputs and operator evidence, eliminate false positives, reproduce findings, assign severity, and prioritize remediation efforts.
• Ensure assessment reports comprehensively document scope, methodologies, evidence, attack vectors, root causes, risks, and actionable remediation suggestions.
• Conduct technical quality reviews prior to report submission.
• Facilitate technical discussions and customer out-briefs, address remediation inquiries, and assist in validating rectified vulnerabilities.
• Report scope conflicts, safety concerns, unexpected access, and significant findings to the Technical Lead and customer contacts.
• Provide ongoing technical assessment support for proactive evaluations of both externally and internally visible federal cyber assets aligned with the CDM Program.
• U.S. citizenship is mandatory.
• Must satisfy eligibility criteria for access to sensitive information.
• Must be capable of obtaining a Public Trust fitness determination (High Risk).
• Ability to operate in customer-provided remote settings and adhere to rules of engagement, data-handling protocols, evidence controls, conflict resolution procedures, and stop-work criteria.
• Five or more years of practical penetration-testing or offensive-security experience, including a minimum of two years leading technical assessments or managing small assessment teams.
• Proficient in scoping, planning, executing, and reporting on enterprise penetration tests across internal/external networks, web applications/APIs, Windows/Active Directory, Linux, and cloud environments.
• Advanced knowledge of tools such as Nmap, Tenable/Nessus, Burp Suite Pro, OWASP ZAP, Metasploit, BloodHound, PowerView, Impacket, NetExec, Certipy/Certify, Wireshark/tcpdump, and other customer-approved tools.
• Strong manual testing capabilities, including exploit validation, attack path development, evidence preservation, and safe proof-of-concept creation.
• Ability to generate technically precise assessment reports and present to both technical and senior customer audiences.
• One or more recognized hands-on certifications, such as OSCP, OSEP/OSCE, OSWE, GPEN, GXPN, GWAPT, PNPT, CPTS, or equivalent.
• Desired: Eight or more years of offensive-security experience across various enterprise assessment domains.
• Desired: Experience as a CISA AES/HVA Assessment Lead or Technical Lead, or equivalent leadership in federal high-value asset assessments.
• Desired: Advanced experience in AWS/Azure, Kubernetes/container, mobile, IoT, wireless, database, or source-code security testing.
• Desired: Experience in ICS/OT, critical infrastructure, restricted networks, or air-gapped assessments.
• Desired: Experience in creating reusable assessment playbooks, report templates, test harnesses, automation, or internal training programs.
• Flexible time off benefit.
• Comprehensive learning resources.
• Healthcare benefits.
• Wellness benefits.
• Financial benefits.
• Retirement benefits.
• Family support benefits.
• Continuing education benefits.
• Time off benefits.
• Competitive compensation.
• Opportunities for learning and development.
Incubator Lab
Gather AI
Knowtion Health
Perkbox
Get handpicked remote jobs straight to your inbox weekly.