Penetration Tester Team Lead
$131.3k - $237.35kLeidos
The U.S. Department of Homeland Security (DHS), Customs and Border Protection (CBP) Security Operations Center (SOC) is a U.S. Government program responsible to prevent, identify, contain and eradicate cyber threats to CBP networks through monitoring, intrusion detection and protective security services to CBP information systems including local area networks/wide area networks (LAN/WAN), commercial Internet connection, public facing websites, wireless, mobile/cellular, cloud, security devices, servers and workstations. The CBP SOC is responsible for the overall security of CBP Enterprise-wide information systems, and collects, investigates, and reports any suspected and confirmed security violations. We are seeking a highly skilled and experienced Penetration Testing Team Lead to join our team supporting CBP. As the leader of this highly technical Penetration Testing Team supporting CBP, you will be responsible for managing the day-to-day operations of the team, coordinating efforts of the team, leading by example, and conducting comprehensive security assessments of CBP FISMA systems with the purpose of identifying vulnerabilities and providing actionable recommendations to enhance the security posture of CBP's critical systems and networks. This role requires a deep understanding of offensive cybersecurity techniques, strong analytical capabilities, detailed report writing skills and the ability to lead a team of skilled penetration testers. Primary Responsibilities: Responsible for managing the team of Penetration Testers, penetration tests, the scheduling and coordination of pentests, Lead and execute advanced penetration testing, purple team engagements, and red team engagements across complex enterprise environments, including internal/external network infrastructure, Active Directory domains, APIs, hybrid cloud architectures, and on-prem systems. Develop, coordinate and enforce Rules of Engagement (ROE) for penetration tests, lead stakeholder planning sessions to define scope and constraints of upcoming pentests, and deliver clear, actionable outbriefings on findings, impact, and remediation to technical and executive audiences. Develop, modify, and deploy custom exploits, payloads, and tooling, including scripting in Python, Ruby, PowerShell, Bash, and other languages to bypass security controls, automate attack paths, and enhance tradecraft. Conduct penetration testing activities aligned with CBP and industry best practices. Provide real-time technical mentorship during engagements, including paired testing, whiteboarding attack paths, and guiding junior testers through exploitation chains and industry best practices. Maintain accountability for engagement quality and technical depth, reviewing findings, validating exploit paths, and ensuring reports accurately reflect risk, attack feasibility, potential impacts, and recommended remediations. Conduct technical oversight and quality assurance across all engagements, reviewing testing approaches, validating exploit chains, and ensuring consistency in methodology, depth, and reporting standards across the team and engagements. Lead purple team collaboration efforts from the pentest perspective, working directly with the CBP SOC, detection engineering team, and Cyber Threat Hunt team to execute actions designed to validate detections, tune SIEM use cases, and improve defensive posture. Mentor and develop team members through structured and ad hoc technical coaching, raising the overall capability of the team while maintaining individual technical skillsets and experience. Utilize the MITRE ATT&CK framework to understand and emulate TTPs of adversaries, threat actors, APTs, and threats targeting CBP and map operations to ATT&CK techniques and sub-techniques. Create detailed reports listing vulnerabilities identified during pentests, with actionable mitigation recommendations following completion of pentest engagements. Stay actively engaged in emerging vulnerability research, exploit techniques, and adversary methodologies, rapidly integrating new capabilities into both personal and team operations. Foster a high-performance, technically rigorous team culture, driving continuous learning through labs, internal exercises, and knowledge-sharing sessions while nurturing cutting-edge offensive skillsets. Basic Qualifications: T5: Candidate shall have a minimum of a Bachelors and twelve (12) years of professional experience penetration testing, red teaming, or offensive security experience, with a minimum of four (4) years of experience directly leading a Penetration Testing Team. Additional years of experience can be accepted in lieu of degree. T6: Candidate shall have a minimum of a Bachelors and fifteen (15) years of professional experience penetration testing, red teaming, or offensive security experience, with a minimum of four (4) years of experience directly leading a Penetration Testing Team. Additional years of experience can be accepted in lieu of degree. Must have an active TS/SCI. Demonstrated expertise in multi-layer exploitation, with the ability to identify, chain, and execute attacks across network infrastructure, operating systems (Windows/Linux), web applications, APIs, and cloud platforms; proven capability to move from initial access through full domain or environment compromise. Proficiency with offensive security tooling and frameworks, including Cobalt Strike, Mythic, Sliver, Metasploit, Burp Suite Pro, BloodHound, Nmap, and similar tools with specific experience modifying and extending tools to evade controls. Strong understanding of enterprise networking and protocols with the ability to enumerate, pivot, and exploit across complex, segmented network environments. Hands-on experience with cloud and modern infrastructure security, familiarity with IAM abuse, privilege escalation, token theft, insecure configurations, and lateral movement within cloud-native services and hybrid environments. In-depth knowledge of operating systems and security controls, including Windows/Linux internals, endpoint protections, logging mechanisms, and common defensive controls with a demonstrated ability to bypass or evade these protections during engagements. Proven leadership and team management experience, including leading technical teams through complex engagements, mentoring junior and mid-level testers, conducting quality assurance on deliverables, and managing multiple concurrent assessments without sacrificing technical depth. Strong communication skills, with the ability to clearly articulate complex technical findings, attack paths, and risk implications to both technical stakeholders and executive leadership through written reports and verbal briefings Must be a US Citizen Must be able to travel to the Ashburn VA office location up to 5 days per week Core Certifications: At least one certification from the below list: OSCP OSCE OSWP OSEE GPEN GISF GXPN GWAPT Clearance: All CBP SOC employees are required to favorably pass a 5-year Background Investigation (BI) The candidate must currently possess a Top Secret Clearance with the ability to obtain a Top Secret/SCI Clearance Preferred Qualifications: Experience conducting full-scope red team operations and adversary emulation campaigns. Familiarity with MITRE ATT&CK framework and threat-informed testing methodologies. Knowledge of container and Kubernetes security testing. Prior experience supporting federal or regulated environments. If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares. Original Posting: June 4, 2026 For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above. Pay Range: Pay Range $131,300.00 - $237,350.00 The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law. Leidos Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $17.2 billion for the fiscal year ended January 2, 2026. For more information, visit Pay and Benefits Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available here. Securing Your Data Leidos will never ask you to provide payment-related information at any part of the employment application process. And Leidos will communicate with you only through emails that are sent from a Leidos.com email address. If you receive an email purporting to be from Leidos that asks for payment-related information or any other personal information, please report the email to View email address on click.appcast.io. Commitment and Diversity All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.
$131.3k - $237.35k
...experienced PenetrationTesting Team Leadto join our team... ...leader of this highly technical Penetration Testing Team supporting CBP,... ...coordinating efforts of the team, leading by example, andconducting comprehensive... ...teamofskilled penetration testers. Primary Responsibilities:...SuggestedWork at officeLocal areaImmediate start$87.1k - $157.45k
...investigates, and reports any suspected and confirmed securityviolations. Weareseekinga highly skilled and experienced Penetration Tester to join our team supportingtheCBP SOC. Thiscandidate willbe responsible forconducting comprehensive security...SuggestedLocal areaImmediate start- ...certification or equivalent experience (examples: CSC, CSSLP, GCSA, GSEC, Security+). Required experience and skills: Penetration testing, vulnerability assessment, red‑team, or offensive security experience. Practical skills in reconnaissance, exploitation, post‑exploitation, web...Suggested
- ...Overview CDT is looking for an experienced Penetration Tester/Red Team Security Engineer to support a government customer in Chantilly, VA. As a senior member of the Red Team, you will be responsible to lead in the design and execution of adversarial based security testing...SuggestedWork experience placement
- ...A leading consulting firm is seeking a Cyber Penetration Testing Professional in Herndon, Virginia. This role involves conducting security testing, mentoring team members, and developing solutions to security vulnerabilities. Candidates should have experience with operating...SuggestedFull timePart timeRemote work
$86.8k - $198k
...considerable direction, and mentors and supervises team members, as needed. You Have: 3+ years of experience with cyber penetration testing or developing risk and threat... ...Professional ( OSCP ) , HTB Certified Penetration Tester Spe cia list ( CPTS ) , eLearn Security...Full timeContract workPart timeLocal areaRemote work- ...A cybersecurity firm in Chantilly, VA, seeks a highly skilled Penetration Tester to join their team. The role involves identifying vulnerabilities and testing the security of networks, applications, and systems through simulated real-world attacks. Ideal candidates are...
- ...Job Title: Penetration Tester Location: Reston, VA Work Mode - Hybrid role, 2 days’ Work from Office (Wednesday and Thursday) Must have Skill Set – Red team pentester Job Description Network penetration testing and experience working with network infrastructure An understanding...Work at office
- ...Penetration Tester LOCATION Chantilly, VA 20151 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY... ...and proactive Penetration Tester to join our cybersecurity team. In this role, you will identify vulnerabilities and test the...Temporary workFor contractorsImmediate startFlexible hours
- A woman-owned IT solutions firm based in Virginia seeks a Penetration Tester to establish and execute penetration testing programs. The role involves developing testing plans and coordinating tests across applications and environments. Candidates should possess strong...
- ...Principal Penetration Tester Altus Consulting seeks a seasoned cybersecurity professional to... ...initiatives. As a key member of our elite team, you'll play a crucial role in safeguarding... ..., presentations, and industry forums Lead quality assurance initiatives for our...
$113.2k - $237.8k
...Job Title: Penetration Tester Job Category: Engineering Time Type: Full time Minimum Clearance Required to Start: TS/SCI with Polygraph... ...penetration security assessments in a cybersecurity red team environment. Be part of a department with an expanding range...Full timeContract workWork experience placementImmediate startFlexible hours- ...__ We are seeking a highly skilled and proactive Penetration Testing SME to join our Cybersecurity team. As a Penetration Testing SME, you will play a critical... ...Penetration Testing Expertise: Proven experience leading and conducting complex penetration tests in...Temporary workLocal areaImmediate start
$86.8k - $198k
...Job Number: R0233826 Penetration Tester The Opportunity : Conduct testing and analysis to identify vulnerabilities and potential threat... ...without considerable direction, and mentor and supervise team members, as needed. You Have: ~3+ years of experience...Full timeContract workPart timeWork at officeLocal areaRemote work$66k - $106k
...Penetration Tester, Journeyman Job Locations US-VA-Herndon Requisition ID... ...innovative Penetration Tester to join our team in the greater DMV area, supporting the... ...reaches of the galaxy. As the world's leading mission capability integrator and transformative...Contract workShift work- ...Cybersecurity Specialist in Herndon, Virginia, with a strong focus on penetration testing and vulnerability assessment. The ideal candidate will... ..., conducting security assessments, and collaborating with teams to enhance defenses. Candidates should possess practical skills...
- ...preferred Strong analytical and problem‑solving skills Excellent written and verbal communication skills Ability to work well in a team environment and collaborate across technical disciplines Knowledge of federal cybersecurity guidelines such as FISMA, HHS, DHS CISA...Temporary workRemote work
- ...offer exciting opportunities to work with leading industry experts, business consultants... ...current requirements, our recruitment team will contact you as soon as possible.... ...development assistance. YSI is seeking a Penetration Tester. The ideal candidate will be...Temporary workImmediate startRemote work
$45k - $65k
Blu Omega LLC seeks a Junior Vulnerability Analyst to support the NIH cybersecurity operations center. This remote role is responsible for assessing and mitigating cybersecurity vulnerabilities in critical healthcare and federal systems. Candidates should demonstrate a...Remote work- ...Orison-Solutions-LLC is looking for a skilled Penetration Tester for a hybrid work role based in Reston, VA. The candidate will conduct network... ...and evaluations. The ideal applicant will possess red team pentesting skills, familiarity with security tools like Nessus...
$103.8k - $218.1k
Job Title: ARNG Cyber Security Team Lead - M2 Job Category: Information Technology Time Type: Full time Minimum Clearance Required to Start: Secret Employee Type: Regular Percentage of Travel Required: Up to 10% Type of Travel: Local * * * The Opportunity: CACI’s Agile...Full timeContract workWork experience placementInterim roleLocal areaFlexible hours- ...RESPONSIBILITIES Under general supervision, perform penetration testing of applications, systems, and... ...briefings to leadership and technical teams. Support compliance-driven testing... ..., such as: Licensed Penetration Tester (LPT) Certified Expert Penetration...Full timeContract workTemporary workWork at officeLocal areaRemote workMonday to FridayWeekend workDay shiftAfternoon shift
- ...Sr. Penetration Tester Job Locations US ID 2026-4358 Category Defense Type Full Time Overview Amyx is seeking a Sr. Penetration Tester for our DOD client to work remotely. Responsibilities Independently performs...Full timeTemporary workFor contractorsRemote workFlexible hours
- ...Overview: CDT is looking for a Penetration Tester to This will be supporting a government customer onsite in Chantilly, VA. Candidates with... .... Experience in cyber security with a focus on red teaming, penetration testing, or threat hunting. Desired Qualifications...Work experience placement
- ...Arcfield is looking for a Penetration Tester (Level 4) to join their expanding Cyber programs in Chantilly, Virginia. The role involves conducting reconnaissance, performing penetration testing on NRO IT assets, and documenting security assessments. The ideal candidate...
$150k - $195k
...Overview VTG is looking for multiple levels (Level 2, 3 & 4) of a Penetration Tester in Chantilly VA and Aurora CO. (Note: position is contingent... ..., and developing more sophisticated exploitation techniques. Leads penetration tests, mentoring junior testers, and providing...Work experience placement- ...A cybersecurity firm in Reston, VA is seeking an experienced Penetration Tester to identify vulnerabilities and conduct security assessments. You will simulate real-world attacks and collaborate in enhancing security measures. Ideal candidates will have a Bachelor's Degree...
- ...Overview: CDT is looking for a Red Team Operator/ Cloud Penetration Tester to support a government customer onsite in Chantilly, VA. The ideal candidate... ...infrastructure, testing and validating capabilities, leading assessments from kick-off through remediation, and...
- 4305 Cyber Threat Intelligence Team Lead 4305 | Top Secret Job Description: OVERVIEW: We are looking for a talented Cyber Threat Intelligence Team Lead to join our team and support our mission critical customer in Reston, VA. This position leads a team...Contract work
- ...Team Leader Opportunity At CAVA At CAVA, we love what we do, and we try and make every day as fulfilling as the last. Our restaurants... ...culture built on five core values: Generosity First, Always: We lead with kindness. Our best work happens when we act in service of...Local areaShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Penetration Tester Team Lead. Be the first to apply!

