Senior Penetration Tester
Visual Lease Services Inc
Senior Penetration Tester
Overview
CoStar Group (NASDAQ: CSGP) is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces. Included in the S&P 500 Index and the NASDAQ 100, CoStar Group is on a mission to digitize the world’s real estate, empowering all people to discover properties, insights and connections that improve their businesses and lives.
We have been living and breathing the world of real estate information and online marketplaces for over 35 years. This extensive experience gives us the perspective to create truly unique and valuable offerings to our customers. We’ve continually refined, transformed, and perfected our approach to our business. Creating a language that has become standard in our industry, for our customers, and even our competitors. We continue that effort today and are always working to improve and drive innovation. This is how we deliver for our customers, our employees, and investors. By equipping the brightest minds with the best resources available, we provide an invaluable edge in real estate.
Evolve our security pentesting capabilities to test our internal and external facing processes, infrastructure, and applications. This position will be tasked with developing test plans to validate identified vulnerabilities and demonstrate the exploitation of the vulnerabilities. The ability to explain the exploit to senior level management is key to success in this role. Stay current with trends, techniques, and tools used by adversaries. This position is located in Arlington, VA and is in office Monday through Thursday with work from home on Friday.
Responsibilities
- Lead penetration tests on web applications and underlying infrastructure for vulnerabilities using both manual and automated techniques.
- Develop test plans that validate identified vulnerabilities and demonstrate exploitability to engineering teams, security peers, and senior leadership.
- Collaborate with detection engineering and incident response on purple team exercises, validating that preventative and detective controls behave as expected against realistic adversary techniques.
- Grow the team's pentesting capabilities in infrastructure and cloud-native domains, including CI/CD pipelines, Active Directory, AWS, and Kubernetes.
- Recommend remediations that address root causes, including code changes, architectural improvements, and control adjustments.
- Stay current with attacker tradecraft. Share knowledge with the broader security team and mentor engineers on offensive techniques and how to think like an attacker.
Basic Qualifications
- Bachelor’s Degree required from an accredited, not for profit, in‑person university or college (preferably in Computer Science, Cybersecurity, or related field).
- A track record of commitment to prior employers.
- 6 years of total experience in a technical role such as security, software development, or systems engineering, with at least 3 years focused on penetration testing or offensive security.
- Demonstrated experience with web application and API penetration testing, including identifying and exploiting attack chains across complex application logic, authentication, and authorization flows.
- Experience writing reports that clearly demonstrate vulnerability risk, business impact, and remediation paths to developers and senior leadership.
- Ability to perform secure code review and identify vulnerabilities in source code, including authentication, authorization, injection, and business logic flaws.
- Scripting and programming proficiency in Python, PowerShell, or similar, with the ability to read and understand application code in languages like C#, Java, JavaScript, or Go.
- Understanding of defense‑in‑depth principles and ability to recommend layered mitigations beyond fixing individual findings.
- Security certifications such as OSCP, OSWE, OSEP, GPEN, GXPN, or similar.
Preferred Qualifications and Skills
- In‑depth experience with offensive security tools such as Burp Suite, OWASP ZAP, Nmap, Bloodhound, and Metasploit.
- Familiarity with Active Directory exploitation tools and techniques.
- Familiarity with C2 frameworks such as Cobalt Strike, Sliver, or Mythic.
- Experience planning and executing red team and purple team scenarios.
- Experience with adversary emulation methodologies and frameworks (MITRE ATT&CK).
- Experience testing modern applications in cloud‑native tech stacks.
- Experience with mobile application penetration testing.
- Familiarity with AI and LLM security testing, including prompt injection, indirect prompt injection, agentic system risks, and MCP server assessment.
- Hands‑on experience implementing security tools into CI/CD pipelines.
- Working knowledge of network, system, and database administration concepts as they relate to attack surface analysis.
- Strong communication skills with both technical teams and senior leadership, particularly translating technical exploits into business risk.
- Experience coordinating with application teams to drive security by design principles.
- Ability to mentor and train team members on offensive techniques and risk prioritization.
- A self‑starter who follows ideas through to completion and drives offensive security work forward independently.
What’s in it for You
When you join CoStar Group, you’ll experience a collaborative and innovative culture working alongside the best and brightest to empower our people and customers to succeed. We offer you generous compensation and performance‑based incentives. CoStar Group also invests in your professional and academic growth with internal training, and tuition reimbursement.
Benefits package includes (but is not limited to):
- Comprehensive healthcare coverage: Medical / Vision / Dental / Prescription Drug
- Life, legal, and supplementary insurance
- Virtual and in‑person mental health counseling services for individuals and family
- Commuter and parking benefits
- 401(K) retirement plan with matching contributions
- Employee stock purchase plan
- Paid time off
- Tuition reimbursement
- On‑site fitness center and/or reimbursed fitness center membership costs (location dependent), with yoga studio, Peloton, personal training, group exercise classes
- Access to CoStar Group’s Employee Resource Groups
- Complimentary gourmet coffee, tea, hot chocolate, fresh fruit, and other healthy snacks
CoStar Group is an Equal Employment Opportunity Employer; we maintain a drug‑free workplace and perform pre‑employment substance abuse testing.
#J-18808-Ljbffr$155.36k - $264.13k
...The Senior Penetration Tester role at ASRC Federal Technology Solutions focuses on leading advanced security assessments while supporting strategy, automation, and technical guidance across a penetration testing program. This hybrid position is based in Washington, DC....Senior3 days per week$110k - $160k
...Full-Time Clearance Requirement: TS/SCI Clearance Required Position Overview:Praescient Analytics is seeking a highly motivated Penetration Tester to join our cybersecurity team in Arlington, VA, supporting the Department of War (DoW) Chief Digital and Artificial...SeniorFull timeWork at office$86.8k - $198k
Enterprise Cybersecurity Penetration TesterThe Opportunity: As a member of the Booz Allen internal Red Team, you'll lead enterprise and system-focused network and penetration assessments to identify security risks across applications, security controls, network infrastructure...SuggestedFull timeContract workPart timeLocal areaRemote work$102k - $127k
Job DescriptionECS is seeking a TS-cleared Senior Information Systems Security Officer (ISSO) to support one of our mission critical programs for the Department of Justice in Washington, DC.Please Note: This position is contingent upon contract award.Salary Range: $102...SeniorContract work- Solutions³ LLC is supporting our prime contractor and their U.S. Government customer on a large mission critical development and sustainment program for on and offsite incident response to Government agencies and critical infrastructure owners who experience cyber-attacks...SeniorFor contractors
- Galapagos Federal Systems LLC is seeking an Information Systems Security Officer to oversee cybersecurity and IA for classified engineering and operational networks. The role ensures compliance with ICD 503, RMF, NIST SP 800-53, 800-37, 800-39, 800-30, CNSSI 1253, and ...Senior
$156k - $195k
...OnTrac is hiring a Senior Manager of IT & Cyber Security ! Are you eager to join a dynamic and expanding company where you can both learn and make a meaningful impact? If you possess a strong sense of empathy, enjoy assisting others, thrive in a fast-paced environment...SeniorContract workTemporary workImmediate startRemote workFlexible hoursShift work- Leidos is seeking a Tier 3 Cyber Threat Intelligence Analyst to join our team supporting DHS NOSC services. You will identify and investigate high-priority threat campaigns, track adversaries and TTPs, and deliver actionable intelligence to improve cyber resiliency across...Senior
- Allyon is seeking a Cyber Threat Intelligence Analyst in Arlington, VA to support DHS mission-critical CTI by analyzing and identifying threats. The role requires an active TS/SCI clearance and U.S. citizenship, with 5+ years of relevant experience. The position is full...SeniorFull time
$77.6k - $176k
...request and propose your own, coordinate with analysts on our team and across the intelligence community (IC), and brief warfighters, senior policymakers, and IC members on our analytic lines.Join us. The world can't wait.You Have: Knowledge of analytic tradecraft...SeniorFull timeContract workPart timeLocal areaRemote work- ...Responsibility Summary: Serve as the primary point of contact for cybersecurity matters and the overall lead for TeAM's ISSO support. The Lead Senior ISSO will own a dedicated portfolio of systems while reserving approximately 30% capacity for enterprise quality assurance,...SeniorContract work
- Business Computers Management Consulting Group, LLC (BCMC) is seeking an experienced Incident Manager to proactively gather and analyze CTI for vulnerability management and operational decision support. You will identify emerging threats, coordinate with stakeholders, ...Senior2 days per week3 days per week
- ...Seize your opportunity to make a personal impact as a Penetration Tester supporting customer activities. GDIT is your place to make meaningful... ...developers, system administrators, project managers, and senior government stakeholders Provide security recommendations for...
- ...General Dynamics Information Technology, Inc. is seeking a Penetration Tester to join our Cyber Security team at the McLean, VA client site. You will perform internal and external evaluations of networks, applications, databases, and cloud services, and articulate...
- BCMC is seeking a seasoned Incident Manager to support cyber threat intelligence efforts for a critical VM program. The role focuses on gathering and analyzing CTI to guide operational decisions, identify emerging threats and collaborate with stakeholders to implement ...Senior
- ...Information System Security Officer to work with application leads, system administrators, database administrators, developers, and testers to ensure assigned systems are security compliant and achieve or maintain Authority to Operate (ATO). The role includes...Senior
- Groundswell is seeking an experienced Appian Principal Developer Consultant in McLean, VA. You will lead implementation teams, guide clients, and support various technical projects. Ideal candidates will have 5+ years of experience with Appian solutions, strong problem-...SeniorFlexible hours
- ...TITLE : Penetration Tester WORK LOCATION : Falls Church, VA (Remote) Local only CLEARANCE : Candidates should have at least a Public Trust Clearance ( Active or Inactive ) SKILLS : penetration testing, web application testing, Api testing, burp suite...Local areaRemote work
$160k
...Senior Information Systems Security Officer (ISSO) About Us AGE Solutions is a premier technology and professional services company, providing in-depth consulting, advanced technology solutions, and essential services throughout the U.S. government, defense, and...SeniorContract workFor contractorsWork at officeLocal areaRemote work$105.4k - $207.8k
Position Summary Cyber Palo Alto Networks Security Engineer/ Senior Consultant, Strategy, Growth, and TransformationDeloitte’s Cyber business is passionate about making an impact with lasting change. Delivering our industry leading services requires fresh thinking...SeniorWork experience placementLocal areaRemote work- ...identifying candidates for the following position. Requisition Type:Full Time Position Status: Contingent Position Title: Penetration Tester Location:Arlington, VA Security Clearance:Secret Duties and Responsibilities The Penetration Testersupports...Full timeFor contractors
- Purpose and Impact: Amentum is seeking Senior Cyber Intelligence Analysts to support our U.S. Department of Energy contract. Positions will be based in the Washington, D.C area.Work Schedule: 5 days, 8 hrsEssential Responsibilities: Provide a wide range of Cyber Intelligence...SeniorContract workFor contractors
$163.4k - $322.1k
...intelligence, investigations, emergency communications, case and incident management, and physical security technology. The Physical Security Senior Manager works with client stakeholders to design and enhance integrated, risk-based security programs that support physical...SeniorLocal areaVisa sponsorship$170k - $250k
...the dependencies — facility, network, tooling, and personnel — that determine whether those dates hold.Represent Shield AI as the senior security authority with Authorizing Officials, SCAs, government program security officers, and DCSA or cognizant SAPCO representatives...SeniorFull timeTemporary workPart timeWorldwide- ...Associate Vice President (AVP) in Cyber Foundry, you will provide senior leadership to our diverse teams of passionate and expert... ..., network- and host-based firewalls, threat intelligence, and penetration testing - Bachelor’s degree in computer science, information systems...SeniorLocal areaVisa sponsorship
$170k - $250k
...program management; manage dependencies that affect whether dates hold (facility, network, tooling, personnel). Serve as Shield AI’s senior security authority with Authorizing Officials , SCAs , government program security officers, and DCSA or cognizant SAPCO...SeniorTemporary work- Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century’s most innovative companies to the defense industry...SeniorFull timeWork experience placementImmediate start
- ...that help drive positive outcomes for our communities. Learn more. Professional development From entry-level employees to senior leaders, we believe there’s always room to learn. We offer opportunities to build new skills, take on leadership opportunities and...SeniorContract workLocal areaVisa sponsorship
$180k - $220k
The Senior Cyber Engineer plays a critical role in ensuring that acquisitions programs... ...commercial equivalents) or experience performing penetration testing and exploit analysis.Version... ...Researcher & Advanced Penetration Tester (GXPN), GIAC Red Team Professional (GRTP...SeniorContract work- Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century’s most innovative companies to the defense industry...SeniorFull timeWork experience placementImmediate start
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Penetration Tester. Be the first to apply!
- senior manager customer operations Arlington, VA
- senior software engineer ruby on rails Arlington, VA
- sr finance manager Arlington, VA
- sr marketing manager Arlington, VA
- senior customer service Arlington, VA
- senior business manager Arlington, VA
- senior account executive Arlington, VA
- senior accounts receivable analyst Arlington, VA
- senior account director Arlington, VA
- senior director of development Arlington, VA




