Penetration Tester
Job Description
Penetration Tester at Accenture Federal Services, onsite in San Antonio, TX, designs, coordinates, and executes a modern, scalable pen-testing program across network, application, and cloud environments, with governance, standardized reporting, and AI-assisted testing within the Agentic AI security architecture.
Responsibilities
- Consolidate ad hoc penetration-testing efforts into a unified enterprise pen-testing program with standard methodologies, processes, and reporting.
- Establish and maintain Rules of Engagement (ROE) for all testing activities, defining scope, communication protocols, safety constraints, escalation paths, and evidence-handling guidelines.
- Coordinate and supervise all test execution activities, including internal teams, contractors, and third-party assessors.
- Plan and execute network, application, and cloud penetration tests under the approved ROE.
- Combine manual tradecraft with AI-assisted offensive-security tooling to increase depth and coverage of assessments.
- Produce detailed evidence packages, exploitation artifacts, and findings reports that support remediation and root-cause analysis.
- Work with product teams, system owners, and DevSecOps/Cloud teams to validate findings and retest fixes.
- Integrate penetration-testing tools, automation frameworks, and exploit-development workflows into the Agentic AI security architecture.
- Recommend tooling enhancements, AI-driven analysis approaches, and automation opportunities.
- Conduct technical risk assessments across systems to determine likelihood, impact, and exploitation feasibility.
- Analyze risk vectors to prioritize vulnerabilities and perform triage across multiple findings sources (manual, automated, AI-assisted, third-party).
- Partner with vulnerability-management, SOC, threat-intelligence, and engineering teams to drive remediation activities.
Requirements
- Two years of Penetration-Testing experience.
- Penetration testing experience across at least two of the following domains: network, cloud, web application, identity, or containerized environments.
- Experience operating within defined Rules of Engagement.
- Proficiency with common offensive-security tools (e.g., Burp Suite, Cobalt Strike, Metasploit, BloodHound).
- Ability to produce high-quality technical documentation, findings reports, and remediation guidance.
Technologies
- Burp Suite
- Cobalt Strike
- Metasploit
- BloodHound
- Agentic AI security architecture