Penetration Testers - Senior (Lead)
Koniag
Koniag Data Solutions, LLC, a Koniag Government Services company , is seeking a Penetration Testers - Senior (Lead) to support KDS and our government customer in Washington, DC. This position requires the candidate to be able to obtain a Public Trust.
We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more. Koniag Data Solutions, a Koniag Government Services company, is seeking an experienced Senior Lead Penetration Tester to support the U.S. Small Business Administration (SBA). The ideal candidate is a highly skilled offensive security professional with extensive experience planning, leading, and executing advanced penetration testing and red team operations across complex federal IT environments. This individual will serve as the technical lead for SBA's penetration testing program, providing expert guidance on adversary simulation, vulnerability exploitation, and security control validation to help the agency identify and remediate security weaknesses before they can be exploited by real-world adversaries.The Senior Lead Penetration Tester will serve as the primary technical lead for all penetration testing and offensive security activities supporting SBA's cybersecurity program, overseeing the full lifecycle of penetration testing engagements, red team operations, and adversary simulation exercises across SBA's enterprise environment. This individual will bring deep technical expertise, strong leadership capabilities, and a comprehensive understanding of adversary TTPs to drive a high-quality, mission-focused penetration testing program that meaningfully strengthens SBA's security posture.
Principal responsibilities will include but are not limited to:
- Lead the end-to-end planning, scoping, coordination, execution, and reporting of advanced penetration testing engagements across all components of SBA's enterprise IT environment, including network infrastructure, web applications, mobile applications, APIs, cloud environments, and supporting systems and services.
- Design and execute sophisticated red team operations and adversary simulation exercises that realistically emulate the tactics, techniques, and procedures (TTPs) of advanced persistent threat (APT) actors, nation-state adversaries, and other sophisticated threat actors known to target federal civilian agencies.
- Conduct advanced exploitation of vulnerabilities identified during penetration testing engagements, including privilege escalation, lateral movement, persistence establishment, credential harvesting, and data exfiltration, to accurately demonstrate the real-world impact and exploitability of identified security weaknesses.
- Develop and maintain a comprehensive, documented penetration testing methodology, program charter, and rules of engagement (ROE) for SBA's penetration testing program, ensuring alignment with industry best practices and federal security requirements including NIST SP 800-115 and applicable CISA guidance.
- Produce detailed, high-quality penetration test reports and executive-level briefings documenting engagement scope, methodologies, technical findings, exploitation evidence, risk ratings, attack narratives, and prioritized, actionable remediation recommendations tailored to both technical and non-technical SBA audiences.
- Collaborate with SBA security leadership, the Cybersecurity Architect, SOC teams, and system owners to communicate penetration testing findings, validate remediation efforts through retesting activities, and provide expert guidance on the prioritization and resolution of identified vulnerabilities and security control gaps.
- Conduct web application penetration testing in accordance with industry frameworks and standards including the OWASP Testing Guide and OWASP API Security Top 10, identifying and exploiting vulnerabilities including injection flaws, broken authentication, cross-site scripting (XSS), insecure direct object references (IDOR), business logic flaws, and other advanced application security vulnerabilities.
- Perform cloud penetration testing and security configuration assessments across AWS, Azure, and/or GCP environments, evaluating the security of cloud service configurations, IAM policies, storage services, network controls, serverless functions, and container environments.
- Develop and utilize custom exploitation tools, offensive scripts, and proof-of-concept (PoC) code to demonstrate the exploitability of identified vulnerabilities and support penetration testing operations in scenarios where commercial tools are insufficient or inappropriate.
- Lead social engineering assessments, including phishing and spear-phishing campaigns, vishing exercises, and physical penetration testing activities, to evaluate SBA's human and physical security controls and the effectiveness of the agency's security awareness program.
- Support and validate vulnerability management activities by providing expert-level analysis of vulnerability scan results, assessing real-world exploitability and risk in the context of SBA's environment, and advising on remediation prioritization strategies based on actual exploitation risk.
- Stay current with the latest offensive security research, vulnerability disclosures, exploit development techniques, and adversary TTPs, continuously applying new knowledge to improve the quality, realism, and effectiveness of SBA's penetration testing program.
- Mentor and provide senior technical leadership to junior and mid-level penetration testers, fostering professional growth, knowledge transfer, and the continuous development of the offensive security team's technical capabilities.
- Ensure all penetration testing and offensive security activities are conducted in strict compliance with SBA's approved rules of engagement, applicable federal laws and regulations, and the ethical standards governing offensive security research and testing.
- Coordinate and lead purple team exercises in collaboration with SBA's blue team, SOC, and incident response teams, designing realistic attack scenarios to validate detection and response capabilities and drive measurable improvements in SBA's defensive posture.
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field from an accredited college or university.
- 8+ years of progressive experience in offensive security, with at least 4 years of dedicated experience leading and executing advanced penetration testing and red team operations in a senior or lead capacity.
- Demonstrated experience conducting advanced penetration testing and red team operations within a federal government or large enterprise IT environment.
- One or more of the following certifications:
- Offensive Security Certified Professional (OSCP)
- Offensive Security Experienced Penetration Tester (OSEP)
- Offensive Security Web Expert (OSWE)
- GIAC Penetration Tester (GPEN)
- GIAC Web Application Penetration Tester (GWAPT)
- GIAC Exploit Researcher and Advanced Penetration Tester (GXPN)
- Certified Penetration Testing Engineer (CPTE)
- Certified Red Team Professional (CRTP)
- Master's degree in Cybersecurity, Computer Science, or a related field.
- 10+ years of offensive security experience, with a strong background supporting federal government or defense contracting penetration testing and red team programs.
- Exceptional communication skills in English - both written and oral - with the ability to clearly articulate complex offensive security findings, exploitation narratives, and remediation recommendations to both technical and non-technical audiences, including senior SBA leadership and government contracting officials.
- Advanced expertise in penetration testing methodologies and industry frameworks, including PTES, OWASP, NIST SP 800-115, and MITRE ATT&CK, with demonstrated ability to apply these frameworks across diverse target environments, assessment types, and engagement scopes.
- Deep proficiency in network penetration testing, including all phases of the engagement lifecycle: reconnaissance, scanning and enumeration, exploitation, privilege escalation, lateral movement, persistence, and post-exploitation techniques across both Windows and Linux environments.
- Advanced experience in web application and API penetration testing, including the identification and exploitation of OWASP Top 10 and beyond vulnerabilities in modern web application architectures, RESTful and SOAP APIs, and web services.
- Strong hands-on experience with industry-standard penetration testing tools and offensive security platforms, including Metasploit Framework, Burp Suite Professional, Cobalt Strike, BloodHound, Mimikatz, Impacket, Nmap, Nessus, Nikto, SQLMap, Responder, and equivalent utilities.
- Proficiency in scripting and programming languages, including Python, PowerShell, Bash, and/or Ruby, for the development of custom exploitation tools, offensive automation scripts, and proof-of-concept code tailored to specific penetration testing objectives.
- Experience planning, designing, and executing full-scope red team operations and adversary simulation exercises, including the realistic emulation of APT TTPs using the MITRE ATT&CK framework to comprehensively assess the effectiveness of SBA's defensive controls and detection capabilities.
- Demonstrated expertise in cloud penetration testing across AWS, Azure, and/or GCP environments, including the assessment of cloud-native services, IAM misconfigurations, storage security, network controls, serverless functions, and container and Kubernetes environments.
- Experience planning and conducting social engineering assessments, including phishing campaign design and execution, vishing exercises, and physical penetration testing activities, with the ability to document findings and provide actionable awareness and control improvement recommendations.
- Strong knowledge of Active Directory architecture and common Active Directory attack techniques, including Kerberoasting, AS-REP Roasting, Pass-the-Hash, Pass-the-Ticket, DCSync, Golden Ticket, and Silver Ticket attacks, and the tools and methods used to execute and defend against these techniques.
- Ability to produce high-quality, comprehensive penetration test reports and executive-level briefings that clearly communicate engagement scope, methodology, technical findings, exploitation evidence, risk ratings, and prioritized remediation recommendations.
- Knowledge of federal cybersecurity frameworks and compliance requirements, including NIST SP 800-53, NIST SP 800-115, FISMA, and applicable CISA guidance, and their relationship to offensive security and penetration testing activities within a federal civilian agency environment.
- Ability to obtain and maintain a Public Trust Clearance.
- Prior experience supporting SBA or other federal civilian agency penetration testing or red team programs, with demonstrated knowledge of SBA's IT environment, system portfolio, and applicable security requirements.
- Experience conducting hardware and firmware penetration testing, including the assessment of IoT devices, embedded systems, network appliances, and physical access control systems.
- Familiarity with mobile application penetration testing for iOS and Android platforms, including the identification and exploitation of mobile-specific vulnerabilities and insecure data storage practices.
- Experience with advanced exploit development and vulnerability research, including binary exploitation techniques, reverse engineering of compiled code, and the development of custom shellcode or exploits targeting identified vulnerabilities.
- Knowledge of operational security (OPSEC) principles and their application in red team and adversary simulation operations to realistically emulate threat actor behaviors and evade detection by SOC teams and defensive controls.
- Offensive Security Exploitation Expert (OSEE) or Offensive Security Defense Analyst (OSDA) certification.
- Demonstrated experience leading and facilitating purple team exercises, collaborating with blue team analysts and SOC personnel to design realistic attack scenarios, validate detection and response capabilities, and drive measurable improvements in defensive posture.
- Familiarity with the CDM (Continuous Diagnostics and Mitigation) program tools, their security implications, and their potential relevance as targets or intelligence sources during penetration testing engagements within a federal civilian agency environment.
- Experience with container security assessments and Kubernetes penetration testing, including the identification and exploitation of misconfigurations, insecure container images, and privilege escalation paths within containerized environments.
- Knowledge of adversarial machine learning techniques and their potential application in offensive security operations targeting AI/ML-enabled systems and decision-making processes.
- Experience conducting penetration testing within FedRAMP authorized cloud environments, with familiarity with FedRAMP authorization boundaries, inherited controls, and the security requirements applicable to penetration testing activities within FedRAMP boundaries.
- Familiarity with bug bounty program management and responsible disclosure practices, and experience contributing to or managing vulnerability disclosure programs within a federal or enterprise environment.
Our Equal Employment Opportunity Policy The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment. The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website, please get in touch with Heaven Wood via e-mail at View email address on click.appcast.io or by calling View phone number on click.appcast.io to request accommodations. Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Penetration Testers - Senior (Lead) in Washington DC vacancy
$139.78k
...Koniag Data Solutions, LLC, a Koniag Government Services company , is seeking a Penetration Testers - Senior (Lead) to support KDS and our government customer in Washington, DC. This position requires the candidate to be able to obtain a Public Trust. We offer competitive...SeniorLocal areaFlexible hours- ...eligibility for Top Secret due to classified threat intelligence. Citizenship: US Citizen (MUST) Key Responsibilities : Lead SBA’s penetration, offensive, and adversarial testing services, including gray/black box testing, red teaming, API testing, and DevSecOps...SeniorLocal areaRemote work
$124.54k - $180k
GovCIO is currently hiring for a Senior Pentration Tester with an active TS/SCI clearance to support DHS onsite in Washington, DC.ResponsibilitiesThe Senior Penetration Tester serves as Key Personnel responsible for leading advanced penetration testing and vulnerability...SeniorCurrently hiring$110k - $160k
...Full-Time Clearance Requirement: TS/SCI Clearance Required Position Overview:Praescient Analytics is seeking a highly motivated Penetration Tester to join our cybersecurity team in Arlington, VA, supporting the Department of War (DoW) Chief Digital and Artificial...SeniorFull timeWork at office- ...primary responsibility will be to plan, execute, and report on penetration tests targeting high-impact applications, platforms, services,... ...peer reviews of penetration test reports and mentoring junior testers. ~ Continuous learner who keeps up with the latest offensive...SeniorRemote work
- ...Description Tharros is seeking a Senior Penetration Testing, Software Assurance and Vulnerability Assessment Engineer to support a DHS Intelligence and Analysis cybersecurity program in the National Capital Region. This role will support advanced penetration...Senior
$106.3k - $221.1k
...more. Join us to drive positive, lasting change that moves missions and the government forward! Job Description The Penetration Tester will conduct comprehensive penetration tests on applications, networks, and systems. Identify and exploit security vulnerabilities...SeniorLive inWork at officeLocal area- ...Apogee Global RMS is seeking a Senior Cybersecurity Engineer / Offensive Security Lead to support high‑visibility federal and IC programs. This role is designed for operators who bring hands‑on offensive tradecraft, current certifications, and recent red‑team experience...SeniorFull time
$95.86k - $208.27k
...opportunities, a world-class training facility, and leading market tools, we help our people continue to grow... ...career in Advisory. KPMG is currently seeking a Senior Specialist, MAST Application Penetration Tester to join our Managed Services practice. Responsibilities...SeniorH1bLocal area$90.3k - $189.6k
Job Title: Lead Senior Information System Security OfficerJob Category: Information TechnologyTime Type: Full timeMinimum Clearance Required to Start: NoneEmployee Type: RegularPercentage of Travel Required: NoneType of Travel: None* * *The Opportunity:CACI is searching...SeniorContract workWork experience placementWork at officeFlexible hours- ...A leadership consulting firm based in Alexandria is looking for a Principal to lead long-term transformational engagements with senior executives. The role demands a proven record of managing large programs, strong client relationship skills, and the ability to mentor...Senior
$117.2k - $313.7k
...through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of...SeniorFull time$160k - $205k
...applications to malicious hacking activity.This senior technical role is responsible performing and leading ethical hacking assessments of the bank's technologies... .../coding techniques, proficiently execute common penetration testing tools, triage, and support incidents, and...SeniorFull timeWork at officeShift workDay shift- DescriptionSAIC is seeking a highly skilled Senior Vulnerability Analyst with a strong technical background to join our team in support... ...maintaining a strong security posture for our client.Key Responsibilities:Lead and manage technical projects with a focus on analytics and...Senior2 days per week
- ...future of Navy support. ICI Services—a 100% employee-owned company proudly celebrating 26 years ofexcellence—is seeking Senior LPD Financial Team Lead toimmediately support our PMS 377 Team at the Naval Sea Systems Command (NAVSEA) in Washington, DC.At ICI Services, our...SeniorFor contractors
$50.23k
...Maryland Environmental Service has multiple openings for Inspectors at the Senior to Lead level within our Technical and Environmental Services Group (TES). These positions will support the Department of Housing and Community Development (DHCD) at their offices in Lanham...SeniorFull timeFor contractorsWork at officeNight shiftWeekend work- ...EmergencyMD is seeking a Lead Incident Responder for a potential government client. This role will involve leading incident response operations, managing complex threats, and ensuring compliance with federal cybersecurity frameworks. The candidate must have a Bachelor...Senior
$80k - $161k
Washington, DCAdministrative and Logistics Support /Full Time On-Site /On-siteLegislative/Legal Research Lead (LRL) - Senior Work Location: Washington, DC Employment Type: Full-Time, Senior-Level Department: Administrative and Logistics Support CGS is seeking a skilled...SeniorFull time$130k - $170k
You will define and lead the strategy and operations for our content acquisitions function, focused on sourcing, developing, and managing relationships with tax and legal subject matter experts. You will oversee teams responsible for acquiring high-quality expert content...SeniorFull timeShift work- ...the built environment. This isn’t just a job, it’s a chance to lead innovation, engineer impact, and build a legacy of excellence.Each... ...only in your community, but around the world. In the role of Senior CAD/BIM Lead, we'll count on you to:Perform non-routine and complex...SeniorContract workWork at office
- Barbaricum is a rapidly growing government contractor providing leading-edge support to federal customers, with a particular focus on... ...challenges. Join our team.Barbaricum is seeking an experienced Senior External Stakeholder Lead to lead external stakeholder engagement...SeniorContract workFor contractorsLocal area
- ...A government services firm in Washington, D.C. is seeking a Senior Billing Specialist responsible for the coordination of the e-billing and payment cycle. The role involves managing billing reports, supervising staff, and ensuring compliance with e-billing processes....Senior
$135k - $216k
ResponsibilitiesAs Senior Intelligence Team Lead, the candidate will be responsible for the day-to-day management of the contract including staffing, financial management, as well as technical and programmatic reporting. They will be responsible for overseeing employees...SeniorContract workFor subcontractorShift work$200k
...amplify your impact and a culture that backs your ambition, you won’t just contribute. You’ll make things happen-fast.As the Senior Team Lead, Customer Onboarding - Enterprise & Strategic Accounts, you will oversee a team of Onboarding and Delivery Managers responsible...SeniorContract workWork at officeWorldwide$104.8k - $192.2k
...working world.Government and Public Sector - Cybersecurity - Penetration Tester - Senior ConsultantFrom strategy to execution, the Government &... ...training and coaching to develop your skills. As EY is a global leading service provider in this space, you will be working with...SeniorFor contractorsSummer holidayWork at officeLocal areaFlexible hours$176k - $282k
ResponsibilitiesThe Senior Intelligence Team Lead is responsible for the day-to-day management of the contract, including staffing, financial oversight, and technical and programmatic reporting. This role oversees both employees and subcontractors and requires proficiency...SeniorContract workFor subcontractorShift work- ...Guidehouse is seeking an experienced Information Security Systems Officer (ISSO) to lead RMF, ATO, and continuous monitoring for a major federal initiative. You will mentor staff and guide system owners through cloud and on‑premises security in hybrid environments. In...Senior
$165k - $190k
.... Join our team as the expert you are now and create your future.We are seeking an experienced Workday Extend Solution Architect to lead the design, development, and delivery of scalable Workday Extend solutions. This role will serve as the primary technical authority...SeniorFull timeLocal area- ...Technology & Processes, LLC is seeking a Cybersecurity Analyst V (Senior) based in Washington, DC. The candidate must have at least 10... ...in Cybersecurity or a related field. Responsibilities include leading RMF lifecycle execution, coordinating Security Authorization Packages...Senior
- ...Graceconsulate is seeking a Senior Volunteer Component Relations Manager to lead volunteer engagement efforts remotely. The role involves managing committee assignments, maintaining a volunteer database, and coordinating with internal teams to enhance governance activities...SeniorRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Penetration Testers - Senior (Lead). Be the first to apply!
Related searches
- ethical hacker Washington DC
- vulnerability analyst Washington DC
- penetration tester Washington DC
- senior operations associate Washington DC
- senior safety specialist Washington DC
- senior technology project manager Washington DC
- remote senior business analyst Washington DC
- senior manager clinical operations Washington DC
- senior supervisor Washington DC
- senior leadership Washington DC



