Penetration Tester
$87.1k - $157.45kLeidos
Description
Leidos is seeking experienced Penetration Tester to support the Defense Manpower Data Center (DMDC) CyberPRIMES program. Leidos is a major partner on the contract and will provide a substantial portion of the cybersecurity workforce supporting the Defense Human Resources Activity (DHRA) and DMDC.
The Penetration Tester will conduct Government-directed penetration testing and threat-hunting assessments across DHRA systems, networks, applications, and supporting technologies. This position will identify exploitable weaknesses, validate the effectiveness of defensive cybersecurity capabilities, and provide actionable findings that help system owners and cybersecurity teams reduce risk.
Work Location: Mark Center, Alexandria, Virginia
Mission Environment
DMDC supports the Defense Human Resources Activity within the Office of the Under Secretary of Defense for Personnel and Readiness (OUSD(P&R)) and maintains the Department of Defense’s largest and most comprehensive central repository of personnel, manpower, casualty, pay, entitlement, personnel security, identity, readiness, training, and related data. The DHRA Information Technology (IT) environment includes approximately 15,000 network and endpoint devices supporting more than 600 Government-Off-The-Shelf (GOTS) applications and approximately 100 Risk Management Framework (RMF) authorization boundaries managed through the Enterprise Mission Assurance Support Service (eMASS).
The penetration-testing team conducts Government-selected assessments of DHRA programs and also performs ad hoc testing with cybersecurity-tool administrators and Security Operations Center personnel to determine whether defensive capabilities are detecting and alerting as intended. Testing may span enterprise networks, web applications, applications, code, and other mission systems.
Primary Responsibilities:
Conduct Government-selected penetration-testing assessments and threat-hunting activities in accordance with established DMDC procedures and the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-115.
Develop assessment plans, methodologies, test objectives, rules of engagement, and technical approaches appropriate to the target environment.
Execute authorized penetration-testing activities against networks, systems, applications, web applications, and code.
Identify vulnerabilities, exploitable configurations, attack paths, and weaknesses that could be used by a malicious actor.
Assess the practical exploitability and potential mission impact of identified security weaknesses.
Research emerging and existing threats, attack techniques, vulnerabilities, and adversary behaviors that may affect DHRA systems.
Develop testing methodologies designed to identify areas of risk likely to be targeted by an intruder.
Conduct threat-hunting activities to identify suspicious or malicious activity that may not be detected through routine monitoring.
Perform cooperative testing with cybersecurity-tool administrators, Security Operations Center (SOC) analysts, incident-response personnel, and Security Information and Event Management (SIEM) content developers.
Validate whether enterprise cybersecurity tools properly detect, generate alerts for, and support analysis of authorized offensive activity.
Identify detection or alerting gaps discovered during testing and provide technical findings to the appropriate cybersecurity teams.
Support pre-audit penetration testing to identify exploitable weaknesses before formal assessments or reviews.
Apply established penetration-testing methodologies and approved commercial or open-source offensive-security tools.
Support Red Team and Blue Team activities designed to evaluate and improve enterprise cybersecurity defenses.
Document testing activities, technical evidence, vulnerabilities, exploitation results, and risk findings.
Develop post-assessment out-briefs and final assessment reports for Government stakeholders.
Provide technically actionable remediation recommendations based on assessment findings.
Coordinate findings with system owners, application teams, network engineers, cybersecurity personnel, SOC analysts, and incident responders.
Maintain Government-Furnished Equipment and approved penetration-testing systems, laptops, software, and tools required to perform assessments.
Protect assessment data, technical artifacts, credentials, exploit information, and other sensitive testing information in accordance with Government requirements.
Basic Qualifications:
Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical discipline and 4 – 8 years of prior relevant experience in order to operate within the scope contemplated by the level. Specific experience, education and training may be considered in lieu of degree.
Experience conducting penetration testing, vulnerability assessment, threat hunting, offensive security, or comparable cybersecurity assessment activities.
Experience assessing enterprise networks, systems, applications, web applications, or code for exploitable cybersecurity weaknesses.
Experience using commercial or open-source penetration-testing and offensive-security tools.
Understanding of common attack techniques, exploitation methods, network protocols, operating systems, and application-security concepts.
Experience developing penetration-testing methodologies, test plans, or technical assessment procedures.
Experience documenting vulnerabilities, technical evidence, exploitation results, and remediation recommendations.
Ability to distinguish theoretical vulnerabilities from weaknesses that present practical exploitation or mission risk.
Ability to communicate technical findings clearly to system owners, engineers, cybersecurity personnel, and Government stakeholders.
Ability to conduct authorized offensive-security activities within defined rules of engagement and Government-approved procedures.
U.S. Citizenship required.
Active Secret security clearance required.
Preferred Qualifications:
Experience conducting penetration testing within Department of Defense or Federal environments.
Experience applying National Institute of Standards and Technology Special Publication 800-115 testing methodologies.
Experience conducting network, web-application, application, and source-code security assessments.
Experience performing threat hunting or adversary-emulation activities.
Experience supporting Red Team and Blue Team exercises.
Experience working with Security Operations Center analysts and incident responders during cooperative testing.
Experience validating SIEM detections, security alerts, or cybersecurity-tool effectiveness using controlled offensive activity.
Experience conducting pre-audit or pre-authorization security assessments.
Experience researching emerging vulnerabilities, attack techniques, and adversary tradecraft.
Experience developing executive and technical penetration-testing out-briefs and assessment reports.
Familiarity with Department of Defense Risk Management Framework processes.
Familiarity with DHRA, DMDC, or comparable Department of Defense enterprise environments.
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.
Original Posting:
September 22, 2026
For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
Pay Range:
Pay Range $87,100.00 - $157,450.00
The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
About Leidos
Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit .
Pay and Benefits
Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at .
Securing Your Data
Beware of fake employment opportunities using Leidos’ name. Leidos will never ask you to provide payment-related information during any part of the employment application process (i.e., ask you for money), nor will Leidos ever advance money as part of the hiring process (i.e., send you a check or money order before doing any work). Further, Leidos will only communicate with you through emails that are generated by the Leidos.com automated system – never from free commercial services (e.g., Gmail, Yahoo, Hotmail) or via WhatsApp, Telegram, etc. If you received an email purporting to be from Leidos that asks for payment-related information or any other personal information (e.g., about you or your previous employer), and you are concerned about its legitimacy, please make us aware immediately by emailing us at View email address on click.appcast.io .
If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission ( .
Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.
REQNUMBER: R-00192817
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status. Leidos will consider qualified applicants with criminal histories for employment in accordance with relevant Laws. Leidos is an equal opportunity employer/disability/vet.
- ...benefits package. Required Experience Minimum of 5 years' experience in the conduct of, supporting the conduct of, or leading penetration tests. Key skills include a strong understanding of operating systems and networking protocols, strong understanding of how...Suggested
- ...Job Description: Dynamo Technologies is seeking a Penetration Tester to support a Cybersecurity Program. Note: This role is for a proposal. Offer will be contingent upon proposal award. Estimated timeline for role to begin is early 2027. Duties/ Responsibilities...Suggested
- ...Description Penetration Tester Xcelerate Solutions is seeking a Penetration Tester to support CyberPRIMES cybersecurity, privacy, records and information management, and related enterprise support for DHRA, including DMDC and OUSD(P&R). Come join our award-winning...Suggested
$106.3k - $221.1k
...more. Join us to drive positive, lasting change that moves missions and the government forward! Job Description The Penetration Tester will conduct comprehensive penetration tests on applications, networks, and systems. Identify and exploit security vulnerabilities...SuggestedLive inWork at officeLocal area$115k - $203k
...US-VA Arlington Full time R38903 Senior Penetration Tester Job Description Overview CoStar Group is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces. Included in the S&P 500 Index, CoStar...SuggestedHourly payFull timeWork at officeWork from homeMonday to Thursday- ...identifying candidates for the following position. Requisition Type:Full Time Position Status: Contingent Position Title: Penetration Tester Location:Arlington, VA Security Clearance:Secret Duties and Responsibilities The Penetration Testersupports...Full timeFor contractors
$117.37k
...are a top veteran employer and Certified Great Place to Work ASRC Federal Technology Solutions is seeking an experienced Penetration Tester to lead advanced security assessments and contribute to the development and execution of penetration testing strategies. This...For contractors3 days per week- ...Overview: Job Title: Penetration Tester Location: Reston, VA Work Mode - Hybrid role, 2 days' Work from Office (Wednesday and Thursday) Must have Skill Set - Red team pentester Job Description: Network penetration testing and experience working...Work at office
- ...The Judge Group is currently seeking a Penetration Tester with an active secret clearance to support a classified customer in Beltsville, MD. This position is onsite five days per week. Core Requirements Active Security Clearance Federal Contracting...
- ...Penetration Tester OCH Technologies is seeking a Penetration Tester to execute network, system, application, and specialized penetration tests against FAA infrastructure under the direction of the Penetration Testing Lead. The candidate will work within formal Rules...Temporary workFor contractorsLocal areaImmediate start
- ...Principal Penetration Tester Altus Consulting seeks a seasoned cybersecurity professional to spearhead our penetration testing initiatives. As a key member of our elite team, you'll play a crucial role in safeguarding some of the world's most critical digital infrastructure...
- ...Penetration Tester LOCATION Reston, VA 20190 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a highly skilled and proactive Penetration Tester to join our cybersecurity team. In this...Temporary workFor contractorsImmediate startFlexible hours
- ...solutions to government entities to deliver predictable, measurable impact for the American taxpayer and consumer. The Integration Tester is responsible for validating and testing integrations across Amazon Connect, AWS Bedrock, Amazon Kinesis, Salesforce, Verint, and...Full time
- ...The Integration Tester plays a critical role in ensuring the stability, accuracy, and reliability of Navy Mutual's enterprise applications and system integrations. This position is responsible for designing, executing, and continuously improving testing strategies across...
- ...We value our clients, integrity and employees and believe a single person can make a difference! We are seeking a Senior Penetration Tester for a Part-time opportunity. This opportunity requires travel to throughout the DMV area. The Senior Penetration Tester serves...Part timeWork at office
$124.54k - $180k
GovCIO is currently hiring for a Senior Pentration Tester with an active TS/SCI clearance to support DHS onsite in Washington, DC. Responsibilities The Senior Penetration Tester serves as Key Personnel responsible for leading advanced penetration testing and...Currently hiring- A leading cybersecurity consultancy is seeking a Cybersecurity Vulnerability Analyst based in Arlington, VA. The role requires an active Top Secret Security Clearance and 5+ years of experience, focusing on vulnerability analysis for federal clients. Candidates must exhibit...
- ..., and other cyber intelligence reports Required Skills Experience as a hands-on cybersecurity analyst (i.e. SOC Analyst or Penetration Tester) is required Experience with the analysis and characterization of cyber attacks Skilled in identifying different classes of...For contractors
$69.55k - $125.73k
Description We are currently seeking a Vulnerability Analyst to join the Compartmented Enterprise Services Office (CESO) effort. This program is establishing a modern secure web service (SWS) operation as part of a state-of-the-art, highly automated platform capable of...Work at officeLocal areaImmediate start- Job Summary: The Penetration Tester is responsible for conducting hands-on security testing to assess vulnerabilities across cloud, network, and application layers. This part-time remote role focuses on ensuring the integrity of evidence, thorough documentation, and reproducible...Contract workPart timeRemote workFlexible hours
- ...TITLE : Penetration Tester WORK LOCATION : Falls Church, VA (Remote) Local only CLEARANCE : Candidates should have at least a Public Trust Clearance ( Active or Inactive ) SKILLS : penetration testing, web application testing, Api testing, burp suite...Local areaRemote work
$90k - $130k
...Full-Time Clearance Requirement: TS/SCI Clearance Required Position Overview:Praescient Analytics is seeking a highly motivated Penetration Tester to join our cybersecurity team in Arlington, VA, supporting the Department of War (DoW) Chief Digital and Artificial...Full timeWork at office$86k - $138k
ResponsibilitiesPeraton is seeking an experienced Cyber Penetration Tester to become part of Peratons’ Federal Strategic Cyber programs. Location: Northern VA; Hybrid - flexible as long as person can come on-site as & when needed. In this role, you will: Support the Red...Contract workFlexible hoursShift work- ...DHS Suitability 5+ years of directly relevant experience Experience as a hands-on cybersecurity analyst (i.e. SOC Analyst or Penetration Tester) is required Experience with the analysis and characterization of cyber attacks Skilled in identifying different classes of...
$500 per month
...Become a Professional Game Tester We're looking for passionate gamers to join our elite team of mobile game testers. Get paid to play and test the latest games before they launch. $500+ Avg Monthly Pay 5-10 Hours/Week 100% Remote Position Requirements:...Part timeRemote work10 hours per week- NTT DATA seeks a Cybersecurity and Risk Analyst to join the VAPT team, identifying and mitigating cybersecurity risks across enterprise systems, networks, and applications. You will perform vulnerability assessments, risk evaluations, and threat simulations aligned with...
- Cyber Network Defense Analyst (CNDA) Our partner provides remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution using host-based, network-based and cloud-based cybersecurity analysis...Immediate startRemote work
$187k - $253k
Type of Requisition: Regular Clearance Level Must Currently Possess: Top Secret/SCI Clearance Level Must Be Able to Obtain: Top Secret SCI + Polygraph Public Trust/Other Required: None Job Family: IT Infrastructure and Operations Job Qualifications: Skills: Cyber ...Contract workTemporary workImmediate startRemote workWorldwideFlexible hours- Nightwing Group is seeking a Cyber Network Forensic Analyst IV in Arlington, VA to support onsite incident response for a U.S. Government customer. You will assist the government lead, coordinate teams, and drive investigations to assess breach severity and craft remediation...
- Raytheon Technologies is seeking a Cyber Network Forensic Analyst III to contribute to advanced cybersecurity operations. This role involves monitoring network activity to identify and analyze cyber threats, ensuring the protection of information systems. As part of a specialized...Remote job
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Penetration Tester. Be the first to apply!


