Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Penetration Tester

ANALYGENCE Inc

Description

Tharros is seeking a Senior Penetration Testing, Software Assurance and Vulnerability Assessment Engineer to support a DHS Intelligence and Analysis cybersecurity program in the National Capital Region.


This role will support advanced penetration testing, software assurance, vulnerability assessment, cyber supply chain risk management, secure cloud and hybrid engineering, and cross-domain security assessment activities. The ideal candidate is a senior technical assessor who can go beyond automated scanning to identify systemic weaknesses, validate exploitability, assess operational impact, and provide clear remediation recommendations for complex mission environments.


Responsibilities:

  • Conduct penetration testing, vulnerability assessments, software assurance, and cyber supply chain risk management activities for Federal mission systems.
  • Perform full-scope security testing using established methodologies such as MITRE ATT&CK, OWASP, NIST 800-115, and related Federal or IC assessment practices.
  • Support pre-engagement planning, rules of engagement, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting.
  • Use approved automated and manual testing methods to identify vulnerabilities, validate exploitability, and assess potential business and operational impacts.
  • Identify vulnerabilities commonly missed by automated tools through manual, expert-driven testing techniques.
  • Assess SOC detection and response capabilities through controlled testing activities.
  • Produce penetration testing reports, vulnerability assessment reports, software assurance recommendations, and corrective action guidance.
  • Support software assurance through vulnerability and compliance testing, source code review, static/dynamic analysis, dependency review, and software supply chain risk identification.
  • Conduct vulnerability assessments and interpret results to recommend corrective actions and mitigation strategies.
  • Support secure cloud, hybrid, DevSecOps, application, identity, API, microservices, CI/CD, Zero Trust, and cross-domain assessment activities.
  • Maintain secure testing kits and assessment tooling, including patching, configuration updates, and approved tool management.
  • Update and maintain penetration testing, SCRM, and vulnerability assessment procedures.
  • Support audits, working groups, and stakeholder briefings related to penetration testing, software assurance, vulnerability assessment, and cyber supply chain risk.
  • Identify opportunities to improve testing processes, automate assessment workflows, strengthen reporting, and produce useful metrics for leadership and technical stakeholders.
  • Translate assessment findings into actionable remediation plans, risk insights, POA&M inputs, dashboards, and decision-ready reporting.
Requirements
  • Active TS/SCI w Poly
  • 10+ years of related cybersecurity assessment, penetration testing, software assurance, vulnerability assessment, or cyber supply chain risk experience.
  • 2+ years of recent experience in each of the following areas: software assurance, penetration testing with automated tools, vulnerability assessment, security patch management, secure cloud and hybrid engineering, and
  • Cross Domain Solutions.
  • CEH and CISSP certifications, or comparable demonstrable experience.
  • Experience conducting penetration testing, vulnerability assessments, software assurance, source code review, SCRM, and cyber supply chain management activities.
  • Experience using both automated tools and manual testing processes to identify, validate, and document vulnerabilities.
  • Experience producing technical reports, corrective action recommendations, mitigation strategies, and executive-ready summaries.
  • Strong understanding of vulnerability management, exploitability, secure configuration, remediation validation, and operational risk.
  • Strong written and verbal communication skills.
  • Ability to work onsite at a government-approved location as required.
Preferred Qualifications:
  • Prior DHS, Intelligence Community, DoD, CISA, classified red team, software assurance, SCRM, CVPA, vulnerability research, or national security cyber assessment experience.
  • Experience with MITRE ATT&CK, OWASP, NIST 800-115, IC "Raise the Bar," NIST SP 800-161, CNSSI 1253, DHS 4300C, or related Federal/IC cybersecurity frameworks.
  • Experience testing cloud, application, identity, API, microservices, CI/CD, DevSecOps, Zero Trust, cross-domain, and hybrid TS/SCI environments.
  • Experience with SBOM analysis, static/dynamic code analysis, dependency review, source code review, exploit validation, secure configuration, and remediation validation.
  • Experience with GRC platforms such as Archer, eMASS, or Xacta, including the ability to translate findings into POA&Ms, dashboards, scorecards, and remediation workflows.
Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the Senior Penetration Tester in Washington DC vacancy
  • $124.54k - $180k

    GovCIO is currently hiring for a Senior Pentration Tester with an active TS/SCI clearance to support DHS onsite in Washington, DC.ResponsibilitiesThe Senior Penetration Tester serves as Key Personnel responsible for leading advanced penetration testing and vulnerability... 
    Senior
    Currently hiring

    Govcio

    Washington DC
    1 day ago
  • $110k - $160k

     ...Full-Time Clearance Requirement: TS/SCI Clearance Required Position Overview:Praescient Analytics is seeking a highly motivated Penetration Tester to join our cybersecurity team in Arlington, VA, supporting the Department of War (DoW) Chief Digital and Artificial... 
    Senior
    Full time
    Work at office

    Praescient Analytics

    Arlington, VA
    4 days ago
  •  ...primary responsibility will be to plan, execute, and report on penetration tests targeting high-impact applications, platforms, and...  ...peer reviews of penetration test reports and mentoring junior testers. ~ Continuous learner who keeps up with the latest offensive... 
    Senior

    Chase

    Washington DC
    1 day ago
  • $115k - $203k

     ...Senior Penetration Tester Job Description Overview CoStar Group is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces. Included in the S&P 500 Index, CoStar Group is on a mission to digitize the... 
    Senior
    Hourly pay
    Full time
    Work at office
    Work from home
    Monday to Thursday

    CoStar Group

    Arlington, VA
    5 days ago
  • DescriptionSAIC is seeking a highly skilled Senior Vulnerability Analyst with a strong technical background to join our team in support of a critical US government agency in the National Capital Region. This is an exciting opportunity to work with a team responsible for... 
    Senior
    2 days per week

    Science Applications International Corporation

    Washington DC
    2 days ago
  • $160k - $205k

     ...of the bank’s applications to malicious hacking activity.This senior technical role is responsible performing and leading ethical hacking...  ...use scripting/coding techniques, proficiently execute common penetration testing tools, triage, and support incidents, and produce high... 
    Senior
    Full time
    Work at office
    Shift work
    Day shift

    Bank of America

    Washington DC
    2 days ago
  • $104.8k - $192.2k

     ...wherever you want it to go. Join EY and help to build a better working world.Government and Public Sector - Cybersecurity - Penetration Tester - Senior ConsultantFrom strategy to execution, the Government & Public Sector practice (“GPS”) of Ernst & Young provides a full... 
    Senior
    For contractors
    Summer holiday
    Work at office
    Local area
    Flexible hours

    EY (Ernst & Young)

    McLean, VA
    3 days ago
  • A leading cybersecurity consultancy is seeking a Cybersecurity Vulnerability Analyst based in Arlington, VA. The role requires an active Top Secret Security Clearance and 5+ years of experience, focusing on vulnerability analysis for federal clients. Candidates must exhibit...
    Senior

    Node.Digital

    Arlington, VA
    4 days ago
  • $104k - $166k

    ResponsibilitiesPeraton is currently seeking a Senior Risk and Vulnerability Analyst.Location: Chandler, AZ or Washington DCRole and Responsibilities: The Senior Risk and Vulnerability Analyst supports a 24x7 Security Operations Center (SOC) by identifying, analyzing,... 
    Senior
    Contract work
    Shift work

    Peraton Corporation

    Washington DC
    2 days ago
  • Digital Global Connectors is seeking an experienced Penetration Tester / Red Team Operator to support a Federal information security program. The role conducts authorized assessments across enterprise systems, cloud environments, applications, wireless networks, and supporting... 
    Senior

    Digital Global Connectors

    Mc Lean, VA
    3 days ago
  • $145k - $185k

     ...GovCIO LLC seeks a Senior Penetration Tester to lead advanced offensive security assessments for federal customers. You will plan and execute web, network, API, cloud, and mobile penetration tests; perform red teaming, social engineering, and adversary emulation; and deliver... 
    Senior
    Washington DC
    6 hours ago
  •  ...Job Description Job Description Quzara is hiring Penetration Testers across multiple experience levels, with a primary focus on mid-level and senior professionals. During the selection process, candidates will be assessed and placed at the level that best reflects... 
    Senior
    Full time
    Work experience placement
    Remote work
    Monday to Friday
    Shift work
    Night shift

    Quzara LLC

    Washington DC
    5 days ago
  • Digital Global Connectors (DGC) is seeking an experienced Penetration Tester / Red Team Operator to support a Federal information security program. The role involves testing enterprise systems, clouds, and applications, with emphasis on adversary emulation and red team... 
    Senior

    Digital Global Connectors

    Mc Lean, VA
    4 days ago
  •  ...for Top Secret due to classified threat intelligence. Citizenship: US Citizen (MUST) Key Responsibilities : Lead SBA’s penetration, offensive, and adversarial testing services, including gray/black box testing, red teaming, API testing, and DevSecOps code... 
    Senior
    Local area
    Remote work

    eTelligent Group LLC

    Washington DC
    more than 2 months ago
  • $104k - $166k

    Responsibilities The Vulnerability Management Analyst will support the Federal Aviation Administration (FAA) under the BNATCS contract, providing specialized cybersecurity and risk management services to help protect National Airspace System (NAS) systems, enterprise infrastructure...
    Senior
    Contract work
    Local area
    Remote work
    Shift work

    Peraton

    Bethesda, MD
    5 days ago
  •  ...Application Penetration Tester We are seeking a highly skilled and experienced Application Penetration Tester to join our dynamic team. This role is ideal for someone with a passion for cybersecurity, a deep understanding of application security, and the ability to... 

    OnDefend

    Washington DC
    1 day ago
  • $178.4k - $226.7k

    AHAS reduces the risk of human and operator access to AWS production systems and customer environments. As the Senior Security Engineer embedded with an AHAS software development team, you own the security design decisions for the operator-access tooling this team builds... 
    Senior
    Internship
    Remote work
    Flexible hours

    Amazon

    Arlington, VA
    3 days ago
  • $86.8k - $198k

     ...remediation. As needed, assist the Vulnerability Management Team lead with providing metrics and KPIs to other operational teams and senior leadership.Join us. The world can't wait.You Have:4+ years of experience in a vulnerability analyst role including identifying and... 
    Senior
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    9 hours ago
  • $130k - $190k

     ...a legacy of protecting national interests and promoting peace and stability worldwide.Job SummaryWe are currently seeking a Penetration Tester. This position is a full-time opportunity located in Arlington, Virginia.Battelle's Mission Focused Tools Business Line is seeking... 
    Full time
    Work experience placement
    Work at office
    Local area
    Remote work
    Worldwide
    Flexible hours

    Battelle Memorial Institute

    Washington DC
    1 day ago
  • $104k - $166k

    ResponsibilitiesPeraton is currently seeking to hire an experienced Penetration Tester for its Federal Strategic Cyber Group. Location: Chandler, AZ and Washington DC.Role and Responsibilities: We are seeking to hire an experienced and highly skilled Penetration Tester... 
    Contract work
    Currently hiring
    Shift work

    Peraton Corporation

    Washington DC
    2 days ago
  • $86k - $138k

    ResponsibilitiesPeraton is seeking an experienced Cyber Penetration Tester to become part of Peratons’ Federal Strategic Cyber programs. Location...  ....Demonstrated ability to lead a penetration test and guide Senior/Junior Penetration Testers.U.S. citizenship required. An... 
    Contract work
    Flexible hours
    Shift work

    Peraton Corporation

    Arlington, VA
    2 days ago
  • DescriptionSAIC is seeking a highly motivated Penetration Tester. The successful candidate will provide support to the Cybersecurity Integrity Center (CIC) in the Department of State Bureau of Information Resource Management (IRM). Duties are in the Washington, D.C. metropolitan... 
    Work at office
    Local area
    Shift work
    3 days per week

    Science Applications International Corporation

    Beltsville, MD
    2 days ago
  •  ...missions worldwide.Job DescriptionOverviewSOSi is seeking a Penetration Tester III to support proactive cyber defense activities in alignment...  ...for any reason.SummaryType: Full-timeFunction: OtherExperience level: Mid-Senior LevelIndustry: Information Technology And Services
    Contract work
    Work at office
    Worldwide
    Monday to Friday
    Weekend work
    Afternoon shift

    SOSi

    Washington DC
    1 day ago
  • ASRC Federal Technology Solutions is seeking an experienced Penetration Testerto lead advanced security assessments and contribute to the...  ....Manage and mentor a small team of junior penetration testers; provide technical guidance and training.Build and lead a Purple... 
    3 days per week

    ASRC Federal Holding Company

    Washington DC
    4 days ago
  • Vexterra Group is looking for a Digital Forensic Analyst to conduct comprehensive forensic examinations, support technical exploitation and generate professional reports for diverse stakeholders. The ideal candidate will have extensive experience and must possess active...
    Senior

    Vexterra Group

    Bethesda, MD
    2 days ago
  • $104k - $166k

    Responsibilities Peraton is currently seeking a Senior Digital Forensic Analyst to support Federal Strategic Cyber programs in the Cyber & Intelligence sector.Location: On-site, Arlington, VAIn this role, you will: Conduct forensic examinations of digital data from... 
    Senior
    Contract work
    Interim role
    Local area
    Shift work

    Peraton Corporation

    Arlington, VA
    4 days ago
  • $101k - $152k

     ...Applied Information Sciences, Inc in Alexandria, Virginia is seeking a Senior Security Engineer to conduct comprehensive digital forensic examinations across various systems. This role includes responsibility for incident management, malware analysis, and deep investigations... 
    Senior
    Contract work

    Applied Information Sciences

    Alexandria, VA
    4 days ago
  •  ...The Cyber Security Analyst (Senior) provides expert-level cybersecurity support for Navy systems, ensuring compliance with DoD and Department of the Navy security requirements. This role leads Risk Management Framework (RMF) activities, supports system authorization... 
    Senior
    Full time

    Tln Worldwide Enterprises Inc

    Washington DC
    1 day ago
  •  ...cybersecurity, a strong analytical background, and the ability to work collaboratively across locations. Required skills include network security knowledge and hands-on experience as a SOC Analyst or Penetration Tester. #J-18808-Ljbffr kozmetickesluzby.vecnakraska.sk - Jobboard
    Senior

    kozmetickesluzby.vecnakraska.sk - Jobboard

    Arlington, VA
    2 days ago
  • The Johns Hopkins University Applied Physics Laboratory (APL) is seeking a Cyber and Information Systems Security Analyst to design and operate national security systems within classified environments. You will join a team of cybersecurity specialists dedicated to supporting...
    Senior

    The Johns Hopkins University Applied Physics Laboratory

    Laurel, MD
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Penetration Tester. Be the first to apply!