Penetration Tester
Eliassen Group
Job Description
Job Description
Description:
Hybrid 2-3 days per week on-site in Alexandria, VA. The first 30 days of work will be full-time on-site. in Alexandria, VA
Our client seeks an experienced penetration testing professional to plan and execute comprehensive security assessments across applications, systems, and infrastructure in alignment with federal standards and industry best practices. The role will coordinate assessment scoping, develop and maintain testing procedures, conduct multi-team exercises, and produce clear reporting with prioritized remediation guidance to strengthen defensive posture and SOC effectiveness.
Due to federal security clearance requirements, applicant must be a United States Citizen. This is a contract to hire opportunity. Applicants must be willing and able to work on a w2 basis and convert to FTE following contract duration. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance.
Rate: $75.00 to $85.00/hr. w2
Responsibilities:- Coordinate and conduct Agency penetration testing on systems operated by and on behalf of NCUA, ensuring access occurs only through specified authentication methods and is limited to vetted personnel.
- Develop, maintain, and update the Penetration Testing CONOPS and SOPs aligned to NIST guidance, applicable Federal regulations, and industry best practices.
- Coordinate prior to each assessment to determine the appropriate assessment model and identify the technology to be tested.
- Draft Rules of Engagement and test-specific penetration testing documentation for each engagement.
- Perform testing and detection activities including red teaming, blue teaming, penetration testing, adversary emulation, purple teaming, and breach and attack simulation to improve SOC operations and defensive posture.
- Document findings and vulnerabilities with risk categorization, impact evaluation, and prioritized remediation, and provide regular status updates to stakeholders.
- Simulate APT scenarios by emulating adversary TTPs to evaluate system resilience and inform enhanced protective measures.
- Conduct red and blue team exercises with post-exercise reviews highlighting detections and areas for improvement.
- Execute the full assessment lifecycle including onboarding, active assessment, findings development, triage, detailed reporting, and patch validation.
- Draft and publish reports for each penetration test including results, findings, and proposed remediation.
- Maintain tracking of penetration testing activities across engagements.
- Integrate penetration testing with vulnerability assessments, threat modeling, event detection evaluation, continuous monitoring tool verification, incident response, and incident reporting compliance.
- US Citizenship required.
- Minimum of 5 years of experience conducting, supporting, or leading penetration tests across enterprise environments.
- Strong understanding of Windows and Linux/Unix operating systems and core networking protocols such as TCP/IP, DNS, and SMB.
- Ability to identify, validate, and exploit vulnerabilities across networks, systems, and applications.
- Working knowledge of web technologies and common vulnerability classes including the OWASP Top 10.
- Proficiency with tools such as Burp Suite, Metasploit, Nmap, Nessus, and Cobalt Strike or equivalents.
- Scripting or automation ability in Python, Bash, or PowerShell.
- Experience performing reconnaissance, vulnerability identification, exploitation, and post-exploitation per approved rules of engagement.
- Capability to develop and deliver findings reports that translate technical issues into business risk with prioritized remediation.
- Strong written communication skills for clear, organized findings reports for technical and non-technical stakeholders.
- Strong verbal communication skills to brief findings, risk ratings, and recommendations to leads, system owners, or client stakeholders.
- Problem-solving skills and ability to work independently or as part of a team under defined timelines.
- Sound judgment and professionalism when operating within sensitive or production environments.
- Desirable: Experience in regulated or federal environments aligned with NIST SP 800-53, SP 800-115, and RMF processes.
- Desirable: Familiarity with wireless and social engineering testing methodologies.
- Clearance: Ability to obtain and maintain a Public Trust.
- Bachelor of Science in Computer Science, Information Technology, Information Security, Cybersecurity, or related field.
- Must hold one or more certifications: OSCP, CEH, GPEN, GWAPT, PenTest+, or eCPPT.
Recruitment Transparency Notice
Eliassen Group values transparency in our recruitment practices. Please be advised that Eliassen Group utilizes artificial intelligence (AI) tools as part of its initial application screening and hiring process. You may receive email and SMS notifications from the Eliassen Virtual Recruiting Team ( View email address on ziprecruiter.com , View phone number on ziprecruiter.com) inviting you to complete a brief voice screening as part of your application process. These tools assist our hiring teams in different ways, including but not limited to, assistance in reviewing application materials to help identify candidates whose qualifications most closely match the requirements of the position. All AI-assisted evaluations and responses are reviewed by human recruiters before any hiring decisions are made. The use of AI in our process is intended to support fairness, efficiency, and consistency, and Eliassen Group takes measures to prevent bias or discrimination in connection with its hiring practices. By proceeding, you acknowledge, agree, and consent to Eliassen Group’s use of these tools, including AI tools, as part of the application and hiring process.
Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range. W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality. If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following:
· When you work with Eliassen Group, all email communication will come from an Eliassen.com address, never Gmail, Yahoo, etc.
· Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group.
If you have any indication of fraudulent activity, please contact View email address on ziprecruiter.com.
About Eliassen Group:
Eliassen Group is a strategic consulting firm that helps organizations reach further and achieve more through our technology, business advisory, and life sciences solutions. For nearly 40 years, we have combined exceptional people, deep domain expertise, and intelligent capabilities to expand our clients’ capacity and accelerate meaningful outcomes. We are driven by a purpose to positively impact the lives of our employees, clients, consultants, and the communities we serve.
Eliassen is committed to building a diverse and inclusive team from a variety of backgrounds, perspectives, and skills. We are an Equal Opportunity and Affirmative Action Employer and all employment decisions are based on merit, performance, and business needs. Eliassen does not discriminate on the basis of race, color, gender identity or expression, sexual preference or orientation, sex (including pregnancy, childbirth, and related medical conditions), marital status, creed, religion, physical or mental disability, genetic information, military or veteran status, age, ancestry, national origin, citizenship status, prohibited criminal record inquiries of applicants and employees, or any other category protected by federal, state, or local laws.
Don’t miss out on our referral program! If we hire a candidate that you refer us to then you can be eligible for a $1,000 referral check!
$86k - $138k
ResponsibilitiesPeraton is seeking an experienced Cyber Penetration Tester to become part of Peratons’ Federal Strategic Cyber programs. Location: Northern VA; Hybrid - flexible as long as person can come on-site as & when needed. In this role, you will: Support the Red...SuggestedContract workFlexible hoursShift work$90k - $130k
...Full-Time Clearance Requirement: TS/SCI Clearance Required Position Overview:Praescient Analytics is seeking a highly motivated Penetration Tester to join our cybersecurity team in Arlington, VA, supporting the Department of War (DoW) Chief Digital and Artificial...SuggestedFull timeWork at office- ...Subscribe to our RSS feeds to receive instant updates as new positions become available. Dynamo Technologies is seeking a Penetration Tester to support a Cybersecurity Program. Note: This role is for a proposal. Offer will be contingent upon proposal award. Estimated...Suggested
- ...Required Experience Minimum of 5 years’ experience in the conduct of, supporting the conduct of, or leading penetration tests. Key skills include a strong understanding of operating systems and networking protocols, strong understanding of how to identify and exploit...Suggested
$115k - $203k
...US-VA Arlington Full time R38903 Senior Penetration Tester Job Description Overview CoStar Group is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces. Included in the S&P 500 Index, CoStar...SuggestedHourly payFull timeWork at officeWork from homeMonday to Thursday- ...identifying candidates for the following position. Requisition Type:Full Time Position Status: Contingent Position Title: Penetration Tester Location:Arlington, VA Security Clearance:Secret Duties and Responsibilities The Penetration Testersupports...Full timeFor contractors
- ...tested leadership, and trusted results to enable national security missions worldwide.Job DescriptionOverviewSOSi is seeking a Penetration Tester III to support proactive cyber defense activities in alignment with our customer. This role is responsible for conducting...Contract workWork at officeWorldwideMonday to FridayWeekend workAfternoon shift
- DescriptionSAIC is seeking a highly motivated Penetration Tester. The successful candidate will provide support to the Cybersecurity Integrity Center (CIC) in the Department of State Bureau of Information Resource Management (IRM). Duties are in the Washington, D.C. metropolitan...Work at officeLocal areaShift work3 days per week
$104k - $166k
ResponsibilitiesPeraton is currently seeking to hire an experienced Penetration Tester for its Federal Strategic Cyber Group. Location: Chandler, AZ and Washington DC.Role and Responsibilities: We are seeking to hire an experienced and highly skilled Penetration Tester...Contract workCurrently hiringShift work$86.8k - $198k
Penetration TesterThe Opportunity:Conduct testing and analysis to identify vulnerabilities and potential threat vectors in systems and networks... ...Certified Professional (OSCP), HTB Certified Penetration Tester Specialist (CPTS), eLearnSecurity Junior Penetration Tester (...Full timeContract workPart timeWork at officeLocal areaRemote work$130k - $190k
...a legacy of protecting national interests and promoting peace and stability worldwide.Job SummaryWe are currently seeking a Penetration Tester. This position is a full-time opportunity located in Arlington, Virginia.Battelle's Mission Focused Tools Business Line is seeking...Full timeWork experience placementWork at officeLocal areaRemote workWorldwideFlexible hours- ...Principal Penetration Tester Altus Consulting seeks a seasoned cybersecurity professional to spearhead our penetration testing initiatives. As a key member of our elite team, you'll play a crucial role in safeguarding some of the world's most critical digital infrastructure...
- ...Reston, VA Contract On-Site Flexibility/Remote: 100% Penetration Tester Task description and/or any specific requirements: Highly skilled in web application testing, API testing, and network testing Prior experience with Burp Suite Professional, or other...Permanent employmentContract workInterim roleCasual workRemote work
$69.55k - $125.73k
Description We are currently seeking a Vulnerability Analyst to join the Compartmented Enterprise Services Office (CESO) effort. This program is establishing a modern secure web service (SWS) operation as part of a state-of-the-art, highly automated platform capable...Work at officeLocal areaImmediate start$152k - $261k
...would love to hear from you. What You Will Do Responsibilities will include, but not be limited to, the following: Perform penetration testing activities on web, mobile, API and network. Provide remediation guidelines and improvements to the issues identified...Full timeTemporary workWork experience placementWork at officeFlexible hours- ...protecting what matters. Advance how our customers operate while you advance your career. Join GDIT as an Ethical Hacker/Penetration Tester Sr Principal and build an impactful career in enterprise IT, collaborating with people who are driven and resourceful like you...Work experience placement
- ...TITLE : Penetration Tester WORK LOCATION : Falls Church, VA (Remote) Local only CLEARANCE : Candidates should have at least a Public Trust Clearance ( Active or Inactive ) SKILLS penetration testing, web application testing, Api testing, burp suite...Local areaRemote work
$155.36k - $264.13k
...The Senior Penetration Tester role at ASRC Federal Technology Solutions focuses on leading advanced security assessments while supporting strategy, automation, and technical guidance across a penetration testing program. This hybrid position is based in Washington, DC...3 days per week$155k - $170k
...Dark Wolf is actively seeking a Senior Penetration Tester to join our innovative team. This individual will play a critical role in assessing and enhancing the security of various products, including hardware, software, and embedded systems. This role demands a deep...Hourly payFor contractorsFor subcontractorRemote work- ...Federal Technology Solutions is seeking an experienced Senior Penetration Testerto lead advanced security assessments and contribute to... ...activities.Manage and mentor a small team of junior penetration testers; provide technical guidance and training.Build and lead a...3 days per week
- ...Job Title: Senior Penetration Tester Pay Type : SALARIED EXEMPT Location : Hybrid, Washington, DC US Citizenship : Required Summary Quzara LLC, a SBA Certified WOSB, EDWOSB, and 8(a) cybersecurity firm, specializes in compliance advisory, cloud security...Full timeWork experience placementRemote workMonday to FridayShift workNight shift
- ...speed, flexibility, and ingenuity to strengthen and protect our nation’s vital interests. Requisition #: 1749 Job Title: Penetration Tester III Location: Hybrid, Springfield, VA Clearance Level: Top Secret / SCI, Must Have Clearance to Start Required...For contractorsWork at office
$110k - $120k
Job Description Job Description Tetrad Digital Integrity (TDI) is a leading-edge cybersecurity firm with a mission to safeguard and protect our customers from increasing threats and vulnerabilities in this digital age. TDI is seeking a Vulnerability Analyst to join...Permanent employmentContract workWork at officeNight shiftDay shift$178.4k - $226.7k
...identity and access controls, incident response, mobile security, cloud computing and security, AI security, threat intelligence, and penetration testing experience- 5+ years of full secure software development life cycle, including coding standards, code reviews, source...InternshipFlexible hours$136k - $184k
...Engineering, Computer Science, or a related field- Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits or equivalent- Experience with web protocols, common security attacks, and remediation (...InternshipFlexible hoursShift work$136k - $184k
...Modelling: Identify attack vectors and security weaknesses in application architectures through structured threat modelling exercises.- Penetration Testing: Coordinate penetration testing to validate security controls and identify exploitable vulnerabilities.- Finding...InternshipFlexible hours$159.3k - $202.4k
Amazon is seeking qualified Security Engineers to join our innovative, high energy Information Security team. In this role you will work within the Amazon Security Incident Response Team (SIRT). SIRT Security Engineers respond to security events, conduct analysis of threats...InternshipFlexible hours$77k - $163k
Arlington, VA Full time JR101442 Nightwing provides technically advanced full-spectrum cyber, data operations, systems integration and intelligence mission support services to meet our customers' most demanding challenges. Our capabilities include cyber space operations...Full timeContract workImmediate start$112k - $179k
ResponsibilitiesPeraton is currently hiring Sr Industrial Control System Cyber Threat Intelligence Analyst for its Federal Strategic Cyber programs.Location: On-site role in Arlington, VA.In this role, you will:Fuse multiple intelligence sources to develop products, recommendations...Contract workCurrently hiringShift work$500 per month
...Become a Professional Game Tester We're looking for passionate gamers to join our elite team of mobile game testers. Get paid to play and test the latest games before they launch. $500+ Avg Monthly Pay 5-10 Hours/Week 100% Remote Position Requirements:...Remote work10 hours per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Penetration Tester. Be the first to apply!




