CybersecurityJobs.io
← Back to all jobs

Job Description

The Penetration Tester supports the AO CMM program by conducting security, penetration, and vulnerability assessments prior to Authority to Operate (ATO). This role ensures applications built with React, NodeJS, and AWS meet federal security standards.

Responsibilities

  • Conduct penetration testing across applications, APIs, and cloud components within CMM systems before ATO submission.
  • Execute security testing for web, mobile, API, and microservices using industry standard tools and manual exploitation methods.
  • Carry out AWS cloud penetration testing within approved boundaries, focusing on IAM, S3, Lambda, API Gateway, ECS/EKS, and networking.
  • Perform static and dynamic analysis, including secure code reviews, to identify vulnerabilities.
  • Run credentialed and uncredentialed scans, test privilege escalation, and assess lateral movement paths.
  • Verify implementation of NIST 800-53 controls across AC, AU, IA, SC, SI, and CM families.
  • Support RMF Step 3 security assessments and contribute evidence for ATO packages.
  • Identify vulnerabilities across application layers, cloud infrastructure, and CI/CD pipelines.
  • Collaborate with developers, cloud engineers, and DevSecOps teams to validate remediations and retest findings.
  • Provide actionable remediation guidance aligned with secure coding and cloud security best practices.
  • Document findings in Jira or equivalent systems and ensure closure before ATO milestones.
  • Prepare Security Assessment Reports, penetration test summaries, and risk findings for AO stakeholders.
  • Document exploitation steps, proofs of concept, and risk severity using federal scoring methodologies.
  • Contribute to System Security Plans, Plans of Actions and Milestones, and ATO evidence packages.
  • Support pre-ATO readiness reviews, including control validation and security walkthroughs.
  • Participate in tabletop exercises, threat modeling, and architecture reviews.
  • Validate system resilience through stress tests, failover scenarios, and adversarial resilience testing.
  • Ensure compliance with federal standards such as NIST, FISMA, and AO-specific guidelines.
  • Work with development teams to integrate security testing into Agile sprints.
  • Provide security insights during sprint planning, backlog refinement, and release readiness reviews.
  • Support secure CI/CD pipeline enhancements, including automated security scanning.

Requirements

  • 8+ years of experience in penetration testing, application security, or ethical hacking roles.
  • Experience documenting test plans, procedures, and detailed security findings.
  • Experience supporting federal security assessments or enterprise-scale security testing.
  • Hands-on experience performing penetration tests on web applications, APIs, microservices, and cloud environments.
  • Strong proficiency with Burp Suite, OWASP ZAP, Metasploit, Nmap, Nessus, Nikto, K6 Security, or custom scripts.
  • Experience testing applications built with NodeJS, ReactJS, REST APIs, and microservices.
  • Strong understanding of AWS security, including IAM, VPC, S3, Lambda, API Gateway, ECS/EKS, CloudTrail, and CloudWatch.
  • Experience with NIST 800-53, RMF, FedRAMP, or federal ATO processes.
  • Ability to interpret logs, metrics, and security telemetry to identify attack paths.
  • Familiarity with SIEM and monitoring tools such as Datadog, ELK, CloudWatch, Grafana.
  • Experience with container security including Docker, Kubernetes, and OpenShift.
  • Understanding of network security, distributed tracing, and adversarial testing techniques.
  • Strong analytical, communication, and documentation skills.

Technologies

  • Burp Suite, OWASP ZAP, Metasploit, Nmap, Nessus, Nikto
  • Python, JavaScript, NodeJS, ReactJS, REST APIs
  • AWS services: IAM, VPC, S3, Lambda, API Gateway, ECS/EKS, CloudTrail, CloudWatch
  • GuardDuty, Datadog, ELK Stack, Prometheus, Grafana
  • Jenkins, GitLab CI/CD, GitHub Actions
  • SAST/DAST tools such as SonarQube, Checkmarx, Fortify
  • Jira, Confluence, SharePoint, MS Teams
  • Power BI, Grafana dashboards
  • Docker, Kubernetes, OpenShift

Tools and Technologies

  • Burp Suite, OWASP ZAP, Metasploit, Nmap, Nessus, Nikto
  • K6 Security, custom Python/JavaScript tools
  • AWS CloudWatch, CloudTrail, GuardDuty
  • Datadog, ELK Stack, Prometheus, Grafana
  • Jenkins, GitLab CI/CD, GitHub Actions
  • SAST/DAST tools: SonarQube, Checkmarx, Fortify
  • Jira, Confluence, SharePoint, MS Teams
  • Power BI, Grafana dashboards
  • Docker, Kubernetes, OpenShift

Work Requirements

  • 8+ years of related experience
  • May vary based on technical training or degree
  • AWS Certified Security - Specialty is preferred

Certifications

  • OSCP, OSWE, GWAPT, GPEN, or similar offensive security certifications
  • AWS Security Specialty
  • SAFe, DevSecOps, or Agile certifications are beneficial

Salary and Benefits

The annual salary range for this role is USD 123,250 to 166,750. This figure is not a guaranteed offer and will be set based on experience, location, and contractual requirements. Details about benefits and our total rewards program are available.

Identity Verification

As part of the hiring process, the company utilizes an identity verification process that may involve biometrics and artificial intelligence. Candidates are expected to be on camera during virtual interviews, and the organization may capture biometric data to verify identity and prevent fraud.

About Our Work

We are GDIT, a global technology and professional services provider delivering solutions to government, defense, and intelligence communities. With thousands of experts across numerous disciplines, we support mission-critical technology initiatives worldwide and operate across more than 50 countries, focusing on AI, cloud, cyber, and software development.

Similar Jobs