Expert Penetration Tester
Job Description
Amatriot Group, LLC is hiring an Expert Penetration Tester to lead advanced security assessments and help strengthen security across systems and applications. This full-time role is hybrid in Washington, DC (with 3 days per week onsite), and the position supports a high-impact mission where clear findings, actionable remediation, and strong execution matter.
The role requires an active DOE Q-Clearance or Top Secret (TS) equivalent (or eligibility to obtain). If you have deep penetration testing experience and can translate technical results into guidance for technical teams and executive stakeholders, this position is built for that work.
Responsibilities
- Lead and perform advanced security assessments, including hands-on penetration testing of systems and applications.
- Identify vulnerabilities, evaluate risk, and provide clear, actionable remediation recommendations.
- Develop and maintain assessment plans aligned with NIST SP 800-53 and FedRAMP Cloud Security Controls.
- Execute assessments per approved plans and document findings accurately and promptly.
- Design, develop, and maintain tools and scripts to automate and improve penetration testing activities.
- Manage and mentor a small team of junior penetration testers, including technical guidance and training.
- Build and lead a Purple Team for joint red/blue team exercises with customer sites.
- Communicate technical findings effectively to technical teams and executive stakeholders.
- Support secure systems operations and maintenance through security validation and accreditation activities.
- Analyze and mitigate threats across the lifecycle, including risk assessments and implementation of security engineering controls.
- Support compliance needs related to business continuity, operations security, insider threat detection, physical security analysis, and regulatory requirements.
Requirements
- Bachelor’s degree in a related field.
- 8+ years of relevant experience in cybersecurity and penetration testing (or an equivalent combination of education and experience).
- Active DOE Q-Clearance or Top Secret (TS) equivalent, or eligibility to obtain.
Required Technical Skills
- Strong proficiency in vulnerability analysis, risk remediation, and reporting.
- Ability to replicate vulnerabilities and provide practical mitigation steps.
- Familiarity with Linux, Tenable Nessus, Forescout, Carbon Black, Invicti, Scythe, Rubrik, and Fidelis.
- Excellent written and verbal communication, including presenting findings to executive audiences.
Certifications (Preferred)
- OSCP (Offensive Security Certified Professional)
- OSCE (Offensive Security Certified Expert)
- CEH (Certified Ethical Hacker)
- CISSP (Certified Information Systems Security Professional)
Compensation: USD 200,000 - 215,000 per year.
Location: Hybrid, Washington, DC (3 days per week onsite).