108 penetration testing jobs at 68 companies in Washington, DC

2mo
Save
Mark Applied
Hide
Penetration Testing Lead
Washington or Atlantic City or Warrenton or Melbourne or Oklahoma City or Leesburg
OnsiteFull Time
Koniag Government Services
Koniag Government Services: Providing technical and professional services to federal agencies.
8+ YOE5+ MgmtEight years of penetration testing experience with five years in management; bachelor's degree; recent leadership experience; red/blue team certifications; federal or regulated environment preferred.
1mo
Save
Mark Applied
Hide
Penetration Testing Lead
Washington, District of Columbia, United States
HybridFull Time
OCH Technologies
OCH Technologies: Provides IT and cybersecurity services for federal government agencies.
15+ YOE5+ Mgmt15+ years cybersecurity experience with 5+ years leading penetration testing; bachelor's degree in a technical field; Public Trust eligibility; security certifications (OSCP, CEH, GPEN, etc.); proficiency with Metasploit, Burp Suite, Nmap and testing methodologies.
Metasploit, Burp Suite, Nmap, Cobalt Strike, Sliver, Mythic, BloodHound, Impacket, Nuclei, Pacu, AzureHound, HackRF, NIST SP 800-115, PTES, OWASP
2w
Save
Mark Applied
Hide
Senior Penetration Testing, Software Assurance and Vulnerability
Washington, District of Columbia, United States
$115k-$185k/yr OnsiteFull Time
Def-Logix
Def-Logix: Cybersecurity research, software development, and technical services firm.
10+ YOE10+ years cybersecurity experience; 2+ years recent experience in software assurance, penetration testing with automated tools, vulnerability assessment, patch management, secure cloud/hybrid engineering, and Cross Domain Solutions; CEH and CISSP or comparable experience.
3w
Save
Mark Applied
Hide
LEAD CYBER SECURITY ENG SPEC (Penetration Testing Engineer)
Washington, District of Columbia, United States
OnsiteFull Time
Concurrent Technologies Corporation
Concurrent Technologies Corporation: Conducts applied research and development for national security.
10+ YOEActive TS/SCI with FRD/RD/NATO eligibility, 10+ years cybersecurity experience, bachelor\u0002s degree or equivalent, CEH and CISSP, 2+ years hands-on in penetration testing, software assurance, vulnerability assessment, patch management, cloud, and CDS.
Risk Management Framework (RMF), NIST 800-53, DISA STIGs, Cross Domain Solutions (CDS), DevSecOps
1mo
Save
Mark Applied
Hide
Penetration Tester
Washington or United States
$123k-$167k/yr RemoteFull Time
GDIT
GDITNYSE: GD: Delivers IT and mission services to government agencies.
8+ YOE8+ years penetration testing/application security experience; AWS cloud and federal security (NIST/RMF/FISMA) knowledge; familiarity with web, API, microservices, container, and cloud testing and reporting.
Burp Suite, OWASP ZAP, Metasploit, Nmap, Nessus, Nikto, K6 Security, Python, JavaScript, AWS CloudWatch, AWS CloudTrail, AWS GuardDuty, Datadog, ELK Stack, Prometheus, Grafana, Jenkins, GitLab CI/CD, GitHub Actions, SonarQube, Checkmarx, Fortify, Jira, Confluence, Microsoft SharePoint, Microsoft Teams, Microsoft Power BI
1w
Save
Mark Applied
Hide
Vulnerability Assessment & Penetration Testing Specialist ? Level III (DC, Washington)
Washington, District of Columbia, United States
OnsiteFull Time
RiVidium
RiVidium: Provides cybersecurity software and IT services to federal agencies.
7+ YOEActive TS/SCI clearance, 7+ years penetration testing and vulnerability assessment experience in federal/IC environments, CEH and CISSP required, bachelor\u0002s in relevant discipline, secure code review and cloud security experience.
MITRE ATT&CK, OWASP, NIST, PTES, Burp Suite Professional, Nessus, ACAS, Nmap, Metasploit Framework, Wireshark, Kali Linux, WebInspect, Nikto, SonarQube, GitLab Security, Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), DISA Security Technical Implementation Guides (STIGs), Docker, Kubernetes, AWS, Azure, Google Cloud
1mo
Save
Mark Applied
Hide
Penetration Testing, Software Assurance and Vulnerability Assessment Engineer
Washington, District of Columbia, United States
OnsiteFull Time
One Federal Solution
One Federal Solution: Provides professional and technical services to federal government agencies.
10+ YOEMinimum 10 years related experience, 2+ years recent experience in software assurance, penetration testing, vulnerability assessment, patch management, secure cloud/hybrid engineering, and CDS. CEH and CISSP required or comparable experience.
Cross Domain Solution (CDS)
1mo
Save
Mark Applied
Hide
Penetration Tester
Fort Meade, Maryland, United States
$87k-$198k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
3+ YOESecret clearance required; 3+ years experience with MITRE ATT&CK, penetration testing, Linux/Windows environments, exploit development, network security analysis, and test planning; HS diploma or GED required.
MITRE ATT&CK, Atomic Red Team, Scythe, Mandiant ASV, AttackIQ, Java, Ruby, Python, JavaScript, Rust, C, Linux, Windows
3w
Save
Mark Applied
Hide
Penetration Tester
Chantilly, Virginia, United States
OnsiteFull Time
LV8D Solutions
LV8D Solutions: Providing engineering and cybersecurity services for government defense agencies.
Perform reconnaissance and vulnerability scanning, design and conduct penetration tests, document findings, develop tools and remediation guidance; US citizenship and TS/SCI clearance required.
3w
Save
Mark Applied
Hide
Penetration Tester
Reston or United States
HybridFull Time
SecureIT
SecureIT: Cybersecurity compliance advisory and assessment services firm.
Experience in web application, network, API and AI penetration testing and red teaming; client-facing experience; relevant certifications such as OSCP, OSWA, OSEP, OSWE, OSEE preferred.
6d
Save
Mark Applied
Hide
Penetration Tester
Alexandria, Virginia, United States
OnsiteFull Time
VMD Corp
VMD Corp: Provides airport security screening and federal IT services.
3+ YOEBachelor’s degree, three years of experience, U.S. citizenship, and active Secret clearance required. Experience with penetration testing, threat hunting, offensive tools, networks, applications, and code.
NIST SP 800-115, SIPRNet, SIEM
1mo
Save
Mark Applied
Hide
Penetration Testing Team Lead
Work from home, Virginia, United States
$170k-$190k/yr RemoteFull Time
ECS
ECSNYSE: ASGN: Provides advanced technology and engineering services to government agencies.
12+ YOEU.S. citizen with 12+ years offensive security experience, Public Trust 6c clearance (or ability to obtain), OSCP/OSCE/GXPN/CEH, network/web/AWS/API pentesting, MITRE ATT&CK and NIST SP 800-115 familiarity.
MITRE ATT&CK, NIST SP 800-115, DHS RVA, Burp Suite Professional, AWS GovCloud, Azure Government
2mo
Save
Mark Applied
Hide
Penetration Tester
New York or Washington or Chicago or Wilmington or Jersey City or Brooklyn or Tampa or Atlanta or McLean or Plano or Houston or Columbus
$152k-$260k/yr OnsiteFull Time
JPMorgan Chase
JPMorgan ChaseNYSE: JPM: Global financial services firm providing banking and investment solutions.
5+ YOE5+ years penetration testing experience across web, API, cloud, infrastructure, thick-client, and mobile; strong manual testing skills, reporting ability, and knowledge of OWASP/NIST frameworks; relevant offensive security certifications preferred.
Burp Suite, Nmap, Metasploit, AWS, Azure, GCP, OWASP Top Ten, NIST Cybersecurity Framework, Python, Java, Rust, Android, iOS, Windows, Unix
15h
Save
Mark Applied
Hide
Penetration Tester
Alexandria, Virginia, United States
OnsiteFull Time
GuidePoint Security
GuidePoint Security: Provides cybersecurity consulting, managed services, and integrated technology solutions.
5+ YOEBachelor's degree or equivalent experience, 5 years leading penetration testing, custom exploit scripting, and ability to obtain and maintain Public Trust clearance. Federal red-team experience preferred.
OWASP, NIST, Meterpreter Pro, Nessus, Cobalt Strike, Greenhouse Software, Zoom Scheduler
1w
Save
Mark Applied
Hide
Penetration Tester
Leesburg, Virginia, United States
$125k-$155k/yr RemoteFull Time
Fortreum
Fortreum: Provides cybersecurity compliance and technical auditing services for regulated industries.
3+ YOE3+ years web and network penetration testing, 2+ years professional services, bachelor's degree or 4 years equivalent, proficiency with scripting (bash, python, PowerShell, ruby), and knowledge of security frameworks.
bash, python, PowerShell, ruby, OWASP, MITRE ATT&CK, OSSTMM, PTES
1mo
Save
Mark Applied
Hide
Penetration Tester
Fort Meade, Maryland, United States
$87k-$198k/yr HybridFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
3+ YOE3+ years performing penetration testing, MITRE ATT&CK-based assessments, network/security analysis, and operating in Linux/Windows/virtual platforms; Secret clearance and HS diploma/GED required.
MITRE ATT&CK, Linux, Windows, Atomic Red Team, Scythe, Mandiant ASV, AttackIQ, Java, Ruby, Python, JavaScript, Rust, C
3w
Save
Mark Applied
Hide
Penetration Tester
Quantico, Virginia, United States
HybridFull Time
ASRC Federal
ASRC Federal: Provides engineering and IT services to federal government agencies.
5+ YOE5+ years security experience, conduct penetration tests across apps/networks/cloud, active Top-Secret clearance, IAT II baseline certs, bachelor's degree or equivalent, strong reporting and remediation skills.
Assured Compliance Assessment Solution (ACAS), Rapid7 Nexpose, Appspider Pro, Metasploit, Cobalt Strike, Burp Suite
2mo
Save
Mark Applied
Hide
Penetration Tester
Fort Meade, Maryland, United States
$160k-$235k/yr OnsiteFull Time
M2 Technology Group
M2 Technology Group: Providing specialized cybersecurity and engineering services for government agencies.
12+ YOESenior RMF subject matter expert with 12+ years experience, DoD 8570 IAT/IAM Level III, CEH, vendor OS certification, active security clearance with polygraph, advanced penetration testing and regulatory expertise.
1w
Save
Mark Applied
Hide
Senior Penetration Testing, Software Assurance and Vulnerability
Washington, District of Columbia, United States
$175k-$215k/yr OnsiteFull Time
CDO Technologies
CDO Technologies: Provides IT systems integration and engineering design services.
10+ YOE10+ years related experience with at least 2 years recent experience in software assurance, automated penetration testing, vulnerability assessment, patch management, secure cloud/hybrid engineering, and Cross Domain Solutions; CEH and CISSP or comparable experience.
4w
Save
Mark Applied
Hide
AVP, Penetration Tester
Fort Mill or Charlotte or New York or Washington or San Diego or Austin
$123k-$204k/yr OnsiteFull Time
LPL Financial
LPL FinancialNASDAQ: LPLA: Provides independent financial advisory and wealth management services.
8+ YOE8+ years penetration testing experience across applications, APIs, networks; 6+ years vulnerability identification and remediation; 3+ years leading engagements; experience with AI/LLM testing and tooling.
Burp Suite, Kali Linux, Nessus, Accunetix, Metasploit, AutoSploit, Cobalt Strike, MITRE ATT&CK, MITRE ATLAS, OWASP Top 10, OWASP Top 10 for LLMs, Claude, .NET, JavaScript, Python, Java, PowerShell, Perl, Ruby, Bash, Linux, macOS, Windows, AWS, Azure, Kubernetes, microservices