10 pentester jobs at 9 companies in Washington, DC

2mo
Save
Mark Applied
Hide
Senior Penetration Tester
Arlington, Virginia, United States
HybridFull Time
CoStar Group
CoStar GroupNASDAQ: CSGP: Provides global real estate information, analytics, and online marketplaces.
6+ YOE6+ years in a technical role; 3+ years in penetration testing; Bachelor's in CS/Cybersecurity or related; web/API pentesting experience; security reporting; scripting in Python/PowerShell; security certifications.
Burp Suite, OWASP ZAP, Nmap, Bloodhound, Metasploit, Cobalt Strike
3mo
Save
Mark Applied
Hide
Cybersecurity Engineer
Fort Meade, Maryland, United States
$193k-$213k/yr OnsiteFull Time
GovCIO
GovCIO: Provides technology and mission support services to federal agencies.
10+ YOEHigh school with 10+ years experience; TS/SCI CI Poly; 10 yrs DoD cybersecurity RMF; cloud and data security; pentesting; DoD 8570.01-M IAT Level II.
RMF, Penetration testing, Vulnerability assessment, Cloud security, Data protection
1mo
Save
Mark Applied
Hide
Senior Penetration Tester
Arlington, Virginia, United States
HybridFull Time
CoStar Group
CoStar GroupNASDAQ: CSGP: Global provider of commercial and residential real estate data.
6+ YOEBachelor's degree required; 6 years technical experience with at least 3 years in penetration testing; web/API pentesting, secure code review, scripting (Python/PowerShell), report writing, and security certifications (e.g., OSCP) required.
Burp Suite, OWASP ZAP, Nmap, Bloodhound, Metasploit, Cobalt Strike, Sliver, Mythic, Python, PowerShell, C#, Java, JavaScript, Go, Active Directory, AWS, Kubernetes, CI/CD, MITRE ATT&CK
2mo
Save
Mark Applied
Hide
IT Security Specialist - Penetration Tester
Silver Spring, Maryland, United States
$125k-$150k/yr HybridFull Time
AttainX
AttainX: Provides IT, cybersecurity, and program management services to federal agencies.
5+ YOEMinimum 5 years pentesting; AWS/Azure/On-Prem; 5+ years with security tools; CISSP/CISA/GCIH/GSNA/CEH/CGRC/SCNP/SCNA within 6 months; US citizen; Moderate Public Trust clearance.
Burp Suite, Metasploit, Wireshark, Tenable Security Center, ArcSight, IBM BigFix
1mo
Save
Mark Applied
Hide
Penetration Tester (Part Time & Remote)
Sterling or United States
$50-$85/hr RemotePart Time, Contract
TestPros
TestPros: Provides independent IT assessment and cybersecurity compliance services.
5+ YOEMinimum 5 years penetration testing experience; proficiency with CLI, scripting (Python, Bash, PowerShell, C/C++), commercial and open-source pentest tools; desired Security+, CEH, GPEN, OSCP, AWS certifications; strong communication and consulting skills.
Windows, macOS, Linux, Python, Bash, PowerShell, C/C++, Metasploit, Nikto, SQLMAP, Responder, Nessus, Netcat, Burp Suite, OWASP, OSSTMM, PTES, FedRAMP, NIST
4d
Save
Mark Applied
Hide
Cyber Blue Team Operator
Fort Belvoir, Virginia, United States
$105k-$130k/yr FieldFull Time
Applied Research Associates
Applied Research Associates: Provides scientific research and engineering solutions for complex problems.
2+ YOEBachelors or equivalent experience in cyber security, 2-4 years relevant defensive cyber experience, active Top Secret clearance with SCI eligibility, IAT II and CSSP Auditor certifications (Security+, CySA+, Pentest+), Linux and network analysis skills.
Red Hat, CentOS, Ubuntu, Perl, Python, C
2w
Save
Mark Applied
Hide
Penetration Testing Team Lead
Work from home, Virginia, United States
$170k-$190k/yr RemoteFull Time
ECS
ECSNYSE: ASGN: Provides advanced technology and engineering services to government agencies.
12+ YOEU.S. citizen with 12+ years offensive security experience, Public Trust 6c clearance (or ability to obtain), OSCP/OSCE/GXPN/CEH, network/web/AWS/API pentesting, MITRE ATT&CK and NIST SP 800-115 familiarity.
MITRE ATT&CK, NIST SP 800-115, DHS RVA, Burp Suite Professional, AWS GovCloud, Azure Government
1mo
Save
Mark Applied
Hide
Application Security Engineer
Washington, District of Columbia, United States
$180k-$200k/yr RemoteFull Time
Virtru
Virtru: Provides data-centric encryption and privacy control software for organizations.
4+ YOE4+ years in application security or secure development, strong cryptography and web security knowledge, experience with Node.js and Go, SAST/DAST/IAST/SCA tooling, vulnerability programs (bug bounty, pentest), and familiarity with cloud infra (GCP/AWS) and Kubernetes preferred.
Node.js, Go, Trusted Data Format (TDF), SAST, DAST, IAST, SCA, Burp, ZAP, Qualys, Nessus, GCP, AWS, Kubernetes, Slack, Zoom
3mo
Save
Mark Applied
Hide
Penetration Tester III
Washington, District of Columbia, United States
HybridFull Time
SOSi
SOSi: Provides technology and mission solutions for national security.
5+ YOE5-7 years pentest experience; red team; IoT/mobile/cloud testing; MITRE ATT&CK, OSSTMM, OWASP, NIST, PTES, ISSAF; Bachelor's; Certifications: GPEN or GXPN; CISA with AES HVA Lead/Technical Lead plus one of GRTP/CRTL/OSCP/CRTP/CMWAPT/CEPT/CPT/LPT; Secret clearance.
MITRE ATT&CK, OSSTMM, OWASP, NIST, PTES, ISSAF, GPEN, GXPN, CISA, GRTP, CRTL, OSCP, CRTP, CMWAPT, CEPT, CPT, LPT
1mo
Save
Mark Applied
Hide
Jr Cyber Penetration Tester
Arlington, Virginia, United States
$66k-$106k/yr HybridFull Time
Peraton
Peraton: National security and mission-critical government technology services provider.
1+ YOEBachelor's degree and 1 year of related experience or 4 additional years in lieu of degree; basic networking/security knowledge; evaluate configurations; identify vulnerabilities; use PenTesting tools (Metasploit, Burp Suite, Nmap); understand web vulnerabilities; perform root-cause analysis; able to work independently or in small teams; one of lis...
Metasploit, Burp Suite, Nmap, bash, Python, PowerShell, JavaScript