Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Penetration Tester [Remote]

Gdit

Remote
  • Remote job
Public Trust: Other
Requisition Type: Regular
Your Impact

Own your opportunity to work alongside federal civilian agencies. Make an impact by providing services that help the government ensure the well being and support of U.S. citizens.

Job Description

The Penetration Tester supports the Case Management Modernization (CMM) Program for the Administrative Office of the U.S. Courts (AO) by conducting security, penetration, and vulnerability assessments required prior to Application ATO (Authority to Operate). This role ensures that CMM applications—built using React, NodeJS, AWS cloud services, and microservices—meet federal security standards and demonstrate resilience against real‑world cyber threats.

Working within Agile DevSecOps teams, the Penetration Tester performs hands‑on exploitation, validates security controls, identifies weaknesses, and collaborates with engineering teams to remediate findings. This role is critical to ensure that CMM systems comply with NIST 800‑53, RMF, and AO security requirements before production authorization.

Key Responsibilities:

  • Perform application, API, and cloud penetration tests on CMM systems prior to ATO submission.
  • Conduct web, mobile, API, and microservices security testing using industry‑standard tools and manual exploitation techniques.
  • Execute AWS cloud penetration testing within approved boundaries (IAM, S3, Lambda, API Gateway, ECS/EKS, networking).
  • Perform static and dynamic analysis, including code review for security vulnerabilities.
  • Conduct credentialed and uncredentialed scans, privilege escalation testing, and lateral movement analysis.
  • Validate implementation of NIST 800‑53 controls, including AC, AU, IA, SC, SI, and CM families.
  • Support RMF Step 3 (Security Assessment) activities and provide evidence for ATO packages.
  • Identify vulnerabilities across application layers, cloud infrastructure, and CI/CD pipelines.
  • Work with developers, cloud engineers, and DevSecOps teams to validate fixes and retest vulnerabilities.
  • Provide detailed remediation guidance aligned with secure coding and cloud security best practices.
  • Track findings in Jira or equivalent tools and ensure closure prior to ATO milestones.
  • Prepare Security Assessment Reports (SAR), penetration test summaries, and risk findings for AO stakeholders.
  • Document exploitation steps, proof‑of‑concepts, and risk severity aligned with federal scoring methodologies.
  • Contribute to System Security Plans (SSP), POA&Ms, and ATO evidence packages.
  • Support pre‑ATO readiness reviews, including control validation and security walkthroughs.
  • Participate in tabletop exercises, threat modeling sessions, and architecture reviews.
  • Validate system resilience through stress, failover, and adversarial resilience testing.
  • Ensure compliance with federal security standards, including NIST, FISMA, and AO-specific guidelines.
  • Work closely with development teams to integrate security testing into Agile sprints.
  • Provide security insights during sprint planning, backlog refinement, and release readiness reviews.
  • Support secure CI/CD pipeline enhancements, including automated security scanning.

REQUIREMENTS:

  • 8+ years of experience in penetration testing, application security, or ethical hacking security roles.
  • Experience documenting test plans, test procedures, and detailed security findings.
  • Experience supporting federal security assessments or enterprise-scale security testing.
  • Hands-on experience performing penetration tests on web applications, APIs, microservices, and cloud environments.
  • Strong proficiency with tools such as Burp Suite, OWASP ZAP, Metasploit, Nmap, Nessus, Nikto, K6 Security, or custom scripts.
  • Experience testing applications built with NodeJS, ReactJS, REST APIs, and microservices.
  • Strong understanding of AWS security, including IAM, VPC, S3, Lambda, API Gateway, ECS/EKS, CloudTrail, and CloudWatch.
  • Experience with NIST 800‑53, RMF, FedRAMP, or federal ATO processes.
  • Ability to interpret logs, metrics, and security telemetry to identify attack paths.
  • Familiarity with SIEM and monitoring tools such as Datadog, ELK, CloudWatch, Grafana.
  • Experience with container security (Docker, Kubernetes, OpenShift).
  • Understanding of network security, distributed tracing, and adversarial testing techniques.
  • Strong analytical, communication, and documentation skills.

QUALIFICATIONS:

  • 8+ years of general experience in information systems with BS/BA Degree, or 6+ years with MA/MS Degree
  • 6+ years experience with in integration, regression, and system testing using automated testing tools in web-based applications
  • Experience in writing test cases, test plans, executing test scripts, reporting defects and preparing test results reports
  • Experience in the entire QA Life Cycle, to include designing, developing and execution on the entire QA process and documentation of test plans, test cases, test procedures and test scripts
  • Experience may be considered in lieu of degree

CERTIFICATIONS:

  • OSCP, OSWE, GWAPT, GPEN, or similar offensive security certifications.
  • AWS Security Specialty
  • SAFe, DevSecOps, or Agile certifications beneficial.

TOOLS & TECHNOLOGIES:

  • Burp Suite, OWASP ZAP, Metasploit, Nmap, Nessus, Nikto
  • K6 Security, custom Python/JavaScript tools
  • AWS CloudWatch, CloudTrail, GuardDuty
  • Datadog, ELK Stack, Prometheus, Grafana
  • Jenkins, GitLab CI/CD, GitHub Actions
  • SAST/DAST tools (SonarQube, Checkmarx, Fortify)
  • Jira, Confluence, SharePoint, MS Teams
  • Power BI, Grafana dashboards

COMMUNICATION & ORGANIZATIONAL

  • Excellent presentation and communication (oral and written) skills.
  • Consultant mindset with the ability to work with high level customer stakeholders and build excellent customer relationship.
  • Experience identifying and applying industry tools, solutions, methods best practices, and emerging technologies.
  • Strong analytical skills and problem-solving skills with the ability to formulate and communicate recommendations for improvement.
  • Demonstrated ability to work effectively, independently, and as part of a team.

Work Requirements

Years of Experience

8 + years of related experience

* may vary based on technical training, certification(s), or degree

Certification

AWS Certified Security - Specialty | Amazon Web Services (AWS) - Amazon Web Services (AWS)

Travel Required

None

Vacancy posted 28 days ago
Similar jobs that could be interesting for youBased on the Penetration Tester [Remote] in Remote vacancy
  • $122.57k - $204.25k

     ...opportunity to help evolve LPL’s offensive security capabilities.Job OverviewAs a member of the Cyber Security team, the Senior Penetration Tester, Offensive Security, is responsible for the scheduling, scoping, and execution of internal penetration testing, with a... 
    Suggested
    Full time
    Work from home

    LPL Financial

    Austin, TX
    3 days ago
  • $90k - $130k

     ...Full-Time Clearance Requirement: TS/SCI Clearance Required Position Overview:Praescient Analytics is seeking a highly motivated Penetration Tester to join our cybersecurity team in Arlington, VA, supporting the Department of War (DoW) Chief Digital and Artificial... 
    Suggested
    Full time
    Work at office

    Praescient Analytics

    Arlington, VA
    1 day ago
  • $86.8k - $198k

    Penetration TesterThe Opportunity:Conduct testing and analysis to identify vulnerabilities and potential threat vectors in systems and networks...  ...Certified Professional (OSCP), HTB Certified Penetration Tester Specialist (CPTS), eLearnSecurity Junior Penetration Tester (... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Herndon, VA
    2 days ago
  •  ...requirement to be onsite up to two (2) days a week at Quantico Marine Corps Base VA.Position Description: The Cybersecurity Penetration Tester is a hands-on technical role responsible for conducting simulated attacks on systems and networks to identify vulnerabilities... 
    Suggested
    Work at office
    Remote work
    2 days per week

    ASRC Federal Holding Company

    Quantico, VA
    3 hours ago
  • $62k - $141k

    Application Penetration TesterThe Opportunity:Work with a wide variety of clients, including Fortune 100 companies, to validate security controls and incident response through offensive security operations, including application penetration testing. Perform web application... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Chantilly, Loudoun County, VA
    1 day ago
  • $104.8k - $192.2k

     ...wherever you want it to go. Join EY and help to build a better working world.Government and Public Sector - Cybersecurity - Penetration Tester - Senior ConsultantFrom strategy to execution, the Government & Public Sector practice (“GPS”) of Ernst & Young provides a full... 
    For contractors
    Summer holiday
    Work at office
    Local area
    Flexible hours

    EY (Ernst & Young)

    McLean, VA
    4 days ago
  •  ...Penetration Tester / Offensive Security Consultant Location : Remote (US or Canada) Company : Control Gap, a CyberGuard Advantage company About Us CyberGuard Advantage is a modern cybersecurity compliance and risk advisory firm backed by Atlantic Street Capital. We help... 
    Remote work

    Control Gap Inc.

    New York, NY
    3 days ago
  • $40 per hour

    A cybersecurity solutions provider is seeking experienced cybersecurity professionals for a remote role focusing on evaluating AI-generated content and solving technical cybersecurity problems. Candidates will have the flexibility to choose projects and work on their own...
    Hourly pay
    Remote work

    DataAnnotation

    Columbia, SC
    2 days ago
  • $40 per hour

     ...directly shapes the next generation of AI security models Qualifications ~2+ years of hands‑on experience in cybersecurity (e.g., penetration testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat intelligence, or similar) ~ Some... 
    Hourly pay
    Full time
    Part time
    Remote work

    DataAnnotation

    Wyoming, OH
    2 days ago
  • $122.4k - $228k

     ...regulators, and the business.Depth over volumeFocus on deep, manual penetration testing (Network, Cloud, and AI with human in the loop)—not...  ...in USA within EST or CST time zones.The Senior Penetration Tester reports to the Sr. Manager of Penetration Testing and leads the... 
    Full time
    Contract work
    Part time
    Work experience placement
    Local area
    Remote work

    BMO Bank

    Texas
    6 hours ago
  • $40 per hour

    A leading AI cybersecurity firm is seeking experienced cybersecurity professionals to evaluate AI-generated security content and solve technical problems. The ideal candidate will possess over 2 years of hands-on experience in cybersecurity and strong analytical and writing...
    Hourly pay
    Remote work
    Flexible hours

    DataAnnotation

    Raleigh, NC
    2 days ago
  • A cybersecurity solutions company is seeking experienced professionals to train AI models through evaluating and improving AI-generated security content. Responsibilities include assessing technical cybersecurity problems, providing feedback for AI systems, and contributing...
    Remote work
    Flexible hours

    DataAnnotation

    Madison, WI
    2 days ago
  • $40 per hour

    A technology company is seeking experienced cybersecurity professionals to join their remote team. The ideal candidates will have 2+ years of hands-on experience in various cybersecurity domains and coding experience. Responsibilities include evaluating AI-generated security...
    Hourly pay
    Remote work

    DataAnnotation

    Boston, MA
    2 days ago
  • $40 per hour

    A leading AI development company is seeking experienced cybersecurity professionals to join their remote team. The role involves evaluating AI-generated security content, solving technical cybersecurity problems, and offering critical feedback to enhance AI models. We require...
    Hourly pay
    Remote work
    Flexible hours

    DataAnnotation

    Honolulu, HI
    2 days ago
  • $40 per hour

    A leading cybersecurity firm is seeking experienced cybersecurity professionals to evaluate AI-generated security content. In this role, you will analyze threats, design solutions for AI training, and provide feedback. This position offers the flexibility of working remotely...
    Hourly pay
    Remote work

    DataAnnotation

    Little Rock, AR
    2 days ago
  • $40 per hour

    A cybersecurity firm is seeking experienced professionals to join their team in a fully remote role. You will evaluate AI-generated security content, solve technical cybersecurity problems, and provide essential feedback to enhance AI's understanding of real-world threats...
    Hourly pay
    Remote work
    Flexible hours

    DataAnnotation

    Madison, WI
    2 days ago
  • $71.6k - $119.4k

    Are you a collaborative Penetration Tester looking to work for a mission driven global organization?About the role - This role supports the offensive security function within Elsevier's Security Engineering team. You will perform hands-on security testing and peer review... 
    Full time
    Local area
    Work from home

    RELX Group

    Connecticut
    3 days ago
  •  ...years. Help us transform our workforce of the future, today.We are seeking a highly skilled and driven Cybersecurity Red Team-Penetration Tester to join our offensive security team. In this role, you will think like an adversary to proactively identify, exploit, and... 
    Work at office
    Work from home
    Flexible hours
    3 days per week

    Zions Bancorporation

    Midvale, UT
    3 days ago
  • $130k - $150k

    Dallas, TexasOpen to RemoteFull Time$130k - $150k A cybersecurity consulting company is looking for a Mid to Senior Network Penetration Tester who has extensive experience with manual network pentesting experience and NSA/nation state. This is a high performing, collaborative... 
    Remote work

    Motion Recruitment

    Dallas, TX
    2 days ago
  • $103.6k - $155.4k

     ...only part of history, they're making history.Northrop Grumman Mission Systems (NGMS) is seeking a Principal/Sr. Principal Cyber Penetration Tester to join our team of qualified, diverse individuals conducting cybersecurity test activities in San Antonio, TX.In this role,... 
    Full time
    Remote work
    Relocation package
    Shift work

    Northrop Grumman

    San Antonio, TX
    3 hours ago
  •  ...primary responsibility will be to plan, execute, and report on penetration tests targeting high-impact applications, platforms, services,...  ...peer reviews of penetration test reports and mentoring junior testers.Continuous learner who keeps up with the latest offensive... 
    Remote work

    JP Morgan Chase

    Chicago, IL
    5 days ago
  • $122.4k - $228k

    Role Description Be among the first dedicated AI Penetration Testers at BMO and help shape how AI systems are secured, challenged, and trusted at enterprise scale. As part of BMO's Security Testing Team, you'll play a key role in building and advancing our AI Security Testing... 
    Full time
    Remote work
    Flexible hours

    BMO

    Remote
    5 days ago
  •  ...language models, AI agents, and AI-powered applications. Qualifications ~5+ years of offensive security experience performing penetration tests, red team engagements, or application security assessments ~Experience assessing AI/LLM-powered applications for... 
    Full time
    Immediate start
    Remote work

    Bishop Fox

    Remote
    6 days ago
  •  ...client sites four days per week and work remotely one day. A member of our recruitment team will provide more details.Job Summary:The Penetration Testing Lead (Vice President) serves as the senior hands‑on leader and standard bearer for the internal penetration testing... 
    Full time
    Temporary work
    Work at office
    Local area
    Remote work
    1 day per week

    MUFG

    Jersey City, NJ
    4 days ago
  •  ...or equivalent years of experience directly related to the duties and responsibilities specified* 3+ years’ experience in hands on penetration testing* 1+ year experience in web application penetration testing* Ability to work well independently, within a team and with... 
    Contract work
    Work experience placement
    Local area
    Immediate start
    Remote work
    Flexible hours

    Schellman & Company

    New York, NY
    2 days ago
  • In the position of Software Integration Tester, you will lead our efforts in the delivery of high quality Infotainment software experiences for our customers. The person in this software test position is passionate about the validation and verification of new Infotainment... 
    Work experience placement
    Immediate start
    Flexible hours

    Ford

    Dearborn, MI
    5 days ago
  • $85.5k - $150.77k

    Reference: 732537BRPosted: 2026-06-22Location: COLORADO SPRINGS, ColoradoSalary: $85,500 - $150,765Clearance: Top SecretCompany: Lockheed MartinDescription:What We’re DoingOur team, Command and Control, Battle Management and Communications (C2BMC)- Global team at Lockheed...
    Full time
    Temporary work
    Work experience placement
    Work at office
    Remote work
    Flexible hours

    Lockheed Martin

    Colorado Springs, CO
    6 hours ago
  •  ...expertise with a clear understanding of the rapidly evolving AI-driven threat landscape—including AI-powered red teaming, automated penetration testing, and novel attack vectors. The analyst will ensure that remediation recommendations are current, actionable, and aligned... 
    Contract work
    Work from home

    Headway Tek Inc

    Mckinney, TX
    5 days ago
  •  ...Information Technology, Information Assurance, and Information Security). Relevant experience must be in vulnerability analysis, penetration testing, and/or computer forensics. In addition, may include computer or information systems design/development, programming,... 
    Local area
    Work from home
    Flexible hours

    Power3 Solutions

    Maryland
    17 hours ago
  •  ...suggest improvements, discuss implementation, etc. Requirements: Practical experience in conducting vulnerability assessments and/or penetration tests. Experience in system and network administration. Familiarity with security concerns and vulnerabilities common in an... 
    Temporary work
    Remote work

    Boston Government Services

    Los Alamos, NM
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Penetration Tester [Remote]. Be the first to apply!