591 penetration jobs at 357 companies in United States

1w
Save
Mark Applied
Hide
Penetration Tester
United States
RemoteFull Time
SecureIT
SecureIT: Cybersecurity compliance advisory and assessment services firm.
Experience in web application, network, API and AI penetration testing and red teaming; client-facing experience and relevant offensive security credentials preferred.
1w
Save
Mark Applied
Hide
Penetration Tester
Herndon, Virginia, United States
$87k-$198k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
3+ YOE3+ years penetration testing experience on Linux/Windows/virtual platforms, hands-on exploitation and network analysis, TS/SCI with polygraph required, strong communication and mentoring skills.
Linux, Windows, Java, Ruby, Python, JavaScript, Rust, C, Google Chrome, Mozilla Firefox, Microsoft Edge, Apple Safari, Opera Browser, Blackberry Browser, Artificial Intelligence (AI)
2d
Save
Mark Applied
Hide
Penetration Tester
Herndon, Virginia, United States
OnsiteFull Time
Bespoke Technologies
Bespoke Technologies: Provides technical engineering and data solutions for national security.
Active polygraph required. Experienced in penetration testing, adversarial tactics, network and system exploitation across Linux, Windows, and virtual platforms; risk analysis and mitigation; communicating technical results.
Linux, Windows, hypervisors
2mo
Save
Mark Applied
Hide
Penetration Tester
United States
RemoteFull Time
Aerstone
Aerstone: A cybersecurity services delivering risk assessments and penetration testing.
5+ YOE5+ years of penetration testing experience; Bachelor's degree; strong Linux knowledge; various security tool experience; cloud and network assessment skills; ability to lead testing and produce reports.
Kali Linux, Metasploit, Burp Suite, ZAP, Nessus, Linux, Windows, Unix, Cloud assessment tools
2w
Save
Mark Applied
Hide
Penetration Tester
Washington or United States
$123k-$167k/yr RemoteFull Time
GDIT
GDITNYSE: GD: Delivers IT and mission services to government agencies.
8+ YOE8+ years penetration testing/application security experience; AWS cloud and federal security (NIST/RMF/FISMA) knowledge; familiarity with web, API, microservices, container, and cloud testing and reporting.
Burp Suite, OWASP ZAP, Metasploit, Nmap, Nessus, Nikto, K6 Security, Python, JavaScript, AWS CloudWatch, AWS CloudTrail, AWS GuardDuty, Datadog, ELK Stack, Prometheus, Grafana, Jenkins, GitLab CI/CD, GitHub Actions, SonarQube, Checkmarx, Fortify, Jira, Confluence, Microsoft SharePoint, Microsoft Teams, Microsoft Power BI
3w
Save
Mark Applied
Hide
Penetration Tester
Fort Meade, Maryland, United States
$87k-$198k/yr HybridFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
3+ YOE3+ years performing penetration testing, MITRE ATT&CK-based assessments, network/security analysis, and operating in Linux/Windows/virtual platforms; Secret clearance and HS diploma/GED required.
MITRE ATT&CK, Linux, Windows, Atomic Red Team, Scythe, Mandiant ASV, AttackIQ, Java, Ruby, Python, JavaScript, Rust, C
3mo
Save
Mark Applied
Hide
Penetration Tester
Washington or San Antonio or Cleveland or California or Colorado or Hawaii or Illinois or Maine or Maryland or Massachusetts or Minnesota or New Jersey or New York or Vermont or Virginia or Washington
$126k-$243k/yr HybridFull Time
Accenture Federal Services
Accenture Federal ServicesNYSE: ACN: Provides technology and consulting services to U.S. federal agencies.
2+ YOE2+ years penetration-testing experience across at least two domains (network, cloud, web app, identity, containers); proficiency with offensive-security tools and producing technical reports; experience with Rules of Engagement.
Burp Suite, Cobalt Strike, Metasploit, BloodHound
2w
Save
Mark Applied
Hide
Penetration Tester
United States
RemoteFull Time
Schellman
Schellman: Provides IT compliance, cybersecurity, and attestation services.
Hands-on penetration testing and project execution, knowledge of security domains and professional standards, strong communication and time management, proficiency with Microsoft Office and service delivery applications, pursuing/maintaining security or audit certifications.
Microsoft Word, Microsoft Excel, Microsoft PowerPoint
3d
Save
Mark Applied
Hide
Penetration Tester
Quantico, Virginia, United States
HybridFull Time
ASRC Federal
ASRC Federal: Provides engineering and IT services to federal government agencies.
5+ YOE5+ years security experience, conduct penetration tests across apps/networks/cloud, active Top-Secret clearance, IAT II baseline certs, bachelor's degree or equivalent, strong reporting and remediation skills.
Assured Compliance Assessment Solution (ACAS), Rapid7 Nexpose, Appspider Pro, Metasploit, Cobalt Strike, Burp Suite
2mo
Save
Mark Applied
Hide
Penetration Tester
Ogden, Utah, United States
OnsiteFull Time
Dark Wolf Solutions
Dark Wolf Solutions: Provides cybersecurity and software development services to defense agencies.
3+ YOE3+ years in penetration testing, red team, vulnerability assessment; strong Windows, Linux, mobile; cloud (AWS/Azure/GCP); scripting; onsite work in Ogden, UT; US Citizenship with TS/SCI clearance.
AWS, Azure, Google Cloud Platform, Kubernetes, DevSecOps tools
3w
Save
Mark Applied
Hide
Penetration Tester
United States
RemoteFull Time
A-LIGN
A-LIGN: Provides cybersecurity compliance and audit services.
2+ YOE2+ years performing network and application penetration tests, OSCP certification, Bachelor’s or Master’s in cybersecurity/MIS/CS, familiarity with Kali Linux, nMap, Nano/Vi, SSH, Bash scripting, and strong communication skills.
Kali Linux, Nano, Vi, nMap, Bash, SSH
2mo
Save
Mark Applied
Hide
Penetration Tester
Fort Meade, Maryland, United States
$160k-$235k/yr OnsiteFull Time
M2 Technology Group
M2 Technology Group: Providing specialized cybersecurity and engineering services for government agencies.
12+ YOESenior RMF subject matter expert with 12+ years experience, DoD 8570 IAT/IAM Level III, CEH, vendor OS certification, active security clearance with polygraph, advanced penetration testing and regulatory expertise.
1mo
Save
Mark Applied
Hide
Penetration Tester
United Kingdom or London or San Francisco or New Hampshire
RemoteFull Time
Bugcrowd
Bugcrowd: Provides a crowdsourced platform for security vulnerability testing.
0.5+ YOE6+ months equivalent penetration testing experience, familiarity with BurpSuite and Nmap, strong written/spoken English (C1+), ability to follow methodologies, and willingness to work UK core hours (09:00-17:30 GMT).
BurpSuite, Nmap
1mo
Save
Mark Applied
Hide
Penetration Tester
New York or Washington or Chicago or Wilmington or Jersey City or Brooklyn or Tampa or Atlanta or McLean or Plano or Houston or Columbus
$152k-$260k/yr OnsiteFull Time
JPMorgan Chase
JPMorgan ChaseNYSE: JPM: Global financial services firm providing banking and investment solutions.
5+ YOE5+ years penetration testing experience across web, API, cloud, infrastructure, thick-client, and mobile; strong manual testing skills, reporting ability, and knowledge of OWASP/NIST frameworks; relevant offensive security certifications preferred.
Burp Suite, Nmap, Metasploit, AWS, Azure, GCP, OWASP Top Ten, NIST Cybersecurity Framework, Python, Java, Rust, Android, iOS, Windows, Unix
3w
Save
Mark Applied
Hide
Penetration Tester
United States
RemoteFull Time
A-LIGN
A-LIGN: Provides cybersecurity audits and compliance assessments for global businesses.
2+ YOEPerform internal, external, wireless, web app, and social engineering penetration tests; run vulnerability scans; write client reports; use Kali Linux command line and Bash; reimage devices; familiarity with text editors, Nmap, SSH.
Kali Linux, Bash, Nano, Vi, Nmap, SSH
2w
Save
Mark Applied
Hide
Penetration Tester, AVP
Whippany, New Jersey, United States
$169k-$170k/yr HybridFull Time
Barclays
BarclaysLondon Stock Exchange: BARC: Global bank providing retail, corporate, and investment financial services.
Perform and lead penetration tests across web, mobile, infrastructure and cloud; analyze and report vulnerabilities; collaborate with stakeholders and develop testing methodologies.
1mo
Save
Mark Applied
Hide
Senior Penetration Tester
Leesburg, Virginia, United States
HybridFull Time
Foxhole Technology
Foxhole Technology: A cybersecurity and IT support provider delivering mission-focused solutions for federal civilian and defense agencies.
7+ YOE7+ years experience, BS degree (or equivalent experience), prior penetration testing and SOC/network security experience, strong analytic and communication skills; Security+ preferred.
2mo
Save
Mark Applied
Hide
Senior Penetration Tester
Arlington, Virginia, United States
HybridFull Time
CoStar Group
CoStar GroupNASDAQ: CSGP: Provides global real estate information, analytics, and online marketplaces.
6+ YOE6+ years in a technical role; 3+ years in penetration testing; Bachelor's in CS/Cybersecurity or related; web/API pentesting experience; security reporting; scripting in Python/PowerShell; security certifications.
Burp Suite, OWASP ZAP, Nmap, Bloodhound, Metasploit, Cobalt Strike
2w
Save
Mark Applied
Hide
Senior Penetration Tester
Washington, District of Columbia, United States
OnsiteFull Time
Tharros
Tharros: Provides specialized cybersecurity defense and vulnerability research services.
10+ YOEActive TS/SCI clearance, 10+ years cybersecurity assessment experience, CEH or CISSP, expertise in penetration testing, software assurance, vulnerability assessment, cloud/DevSecOps, and producing technical and executive reports.
MITRE ATT&CK, OWASP, NIST 800-115, NIST SP 800-161, CNSSI 1253, DHS 4300C, SBOM, Archer, eMASS, Xacta, CI/CD, DevSecOps
5d
Save
Mark Applied
Hide
Senior Penetration Tester
Washington, District of Columbia, United States
$125k-$180k/yr OnsiteFull Time
GovCIO
GovCIO: Provides technology and mission support services to federal agencies.
12+ YOEActive TS/SCI clearance, bachelor\u0002s degree with 12+ years penetration testing experience, 8+ years supporting enterprise/cloud (AWS, Azure, Google Cloud), hands-on with offensive tools and methodologies.
AWS, Azure, Google Cloud, RHEL, Linux, Tenable, Kali Linux, Burp Suite Pro, Metasploit, NIST 800-53, MITRE ATT&CK