Senior Penetration Tester
GovCIO · Washington, DC, US
Apply directly on GovCIO’s careers site — no account needed.
About the role
The Senior Penetration Tester serves as Key Personnel responsible for leading advanced penetration testing and vulnerability assessment activities within a TS/SCI environment. This role ensures mission‑critical security assurance across enterprise systems, applications, and cloud infrastructures by applying deep technical expertise, zero‑trust principles, and attacker‑focused methodologies. The Senior Penetration Tester guides technical direction, ensures rigorous execution, and provides authoritative recommendations to strengthen security posture across sensitive environments.
Lead, plan, and oversee penetration testing operations for systems, networks, cloud resources, and web‑based applications in a TS/SCI environment
Execute comprehensive vulnerability assessments and software assurance evaluations; authoritatively document findings and drive remediation strategies
Conduct deep technical analysis of vulnerabilities including buffer overflows, SQL injection, CSRF, XSS, race conditions (TOCTOU), XXE, encryption weaknesses, authentication bypass, and similar issues
Assess and advise on security considerations during software acceptance activities, including criteria definition, risk acceptance evaluation, documentation review, and independent validation approaches
Apply advanced security defense functions (encryption, access control, identity management) to reduce exploitation risks, including those related to supply chain considerations
Provide threat intelligence insights and vulnerability research aligned with frameworks such as NIST 800‑53 and MITRE ATT&CK to inform cloud security architecture decisions
Develop new or enhanced penetration testing methodologies to identify emerging vulnerabilities and expand organizational capability
Serve as a senior technical advisor and mentor to penetration testing staff; ensure consistency, quality, and rigor in testing execution
Represent the penetration testing function in discussions with leadership, engineering teams, and mission stakeholders as required for Key Personnel roles
- Bachelor's with 12+ years of penetration testing experience (or commensurate experience)
Minimum of 8 years of experience supporting enterprise security architectures and cloud platforms (AWS, Azure, Google Cloud)
Proven, extensive experience as a Penetration Tester in complex or classified environments
Advanced knowledge of penetration testing methodologies, offensive security techniques, and industry tools
Experience with AWS, Azure, RHEL, Linux, and Tenable
Hands-on experience with tools including Kali Linux, Burp Suite Pro, and Metasploit
Strong analytical and problem‑solving skills with an ability to think like an attacker
Excellent communication skills to deliver clear, actionable findings to both technical and executive stakeholders
Preferred certifications: CEH, OSCP, or equivalent offensive security certifications
- Clearance Required: Active TS/SCI clearance
Description sourced from the public Indeed listing — this role isn't indexed from the company's career page yet.
Skills
- AWS
- Azure
- GCP
- Linux
- Penetration Testing
- Kubernetes
Never be applicant #200 again
Every job here is indexed straight from company career pages — often hours after it opens, before it reaches the big boards. Create a free account and get your best matches in a twice-daily digest.
- Your best matches, twice a day
- No duplicates, no ghost jobs, no recruiter spam
- Every job free to browse — pay only when you apply
Free account — no card required
93 115 live jobs · 17 643 companies tracked · 111 added today