This position is no longer accepting applications
Closed on September 25, 2026.
This role is filled — get an email when new Information Security roles open on CybersecurityJobs.io:
Penetration Tester
Application Security
Burp Suite
Cobalt Strike
Cybersecurity Tools
Exploit Development
Information Security
InfoSec
Metasploit
Offensive Security
Security Clearance
Security Testing
Vulnerability Scanners
View similar jobs
Get alerted when similar jobs are posted — set up a New Information Security jobs on CybersecurityJobs.io alert.
See other roles at ASRC Federal.
Job Description
ASRC Federal is hiring a Penetration Tester for a hybrid role in Quantico, VA. Telework is available, with an onsite requirement of up to two (2) days a week at Quantico Marine Corps Base VA. This position supports hands-on testing across modern application, network, and cloud environments, with compensation in the range of USD 130,000 to 147,568 per year.
Responsibilities
- Plan, execute, and document penetration tests to identify vulnerabilities and recommend remediation.
- Conduct penetration testing across web applications, mobile applications, networks, cloud environments, and other in-scope systems.
- Use a range of tools and techniques to uncover vulnerabilities, including SQL injection, cross-site scripting (XSS), buffer overflows, and other common attack vectors.
- Perform reconnaissance to gather information about target systems and networks.
- Develop and run exploit code to demonstrate the impact of identified vulnerabilities.
- Bypass security controls and evade detection during authorized testing.
- Conduct vulnerability assessments using automated scanning tools and manual techniques.
- Analyze scan results to identify false positives and prioritize findings.
- Develop custom scripts and tools to automate vulnerability assessment tasks.
- Produce detailed reports covering vulnerabilities, exploitation methods, and remediation recommendations.
- Present findings to stakeholders, including technical teams and management.
- Create and maintain documentation for penetration testing methodologies, tools, and techniques.
- Provide guidance and technical assistance to system owners and developers during remediation.
- Validate remediation efforts and conduct retests to verify the effectiveness of implemented security controls.
- Stay current on evolving threats, vulnerabilities, and attack techniques.
- Research and evaluate new penetration testing tools and methodologies, and improve testing capabilities through custom tooling.
- Contribute to security policies and procedures.
- Collaborate with cybersecurity professionals, including security architects, incident responders, and security engineers, and share knowledge with team members.
- Participate in security training and awareness programs.
- Perform all activities legally and ethically, following established rules of engagement; protect sensitive data confidentiality and integrity and respect user privacy.
Requirements
- Minimum 5 to 7 years of experience in security principles, including attack frameworks, threat landscapes, and attacker tactics, techniques and procedures.
- Proven experience conducting penetration tests of web applications, networks, and other systems.
- Experience with a variety of penetration testing tools and techniques, including Rapid7 Nexpose, Appspider Pro, Metasploit, Cobalt Strike, and/or Burp Suite.
- Active Top-Secret Clearance REQUIRED, eligible to be upgraded to TS/SCI.
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field, or equivalent experience.
- Must meet 8570 certification requirements at the time of hire. IAT II Information Assurance Baseline (for example: CASP+ CE, CCMP Security, CISA, CISSP, GCED, GCIH, Security+ CE, CCSP).
- A CSSP Auditor certification is preferred (examples include: CEH, CySA+, CISA, GSNA, CFR, PenTest).
Benefits
- Health care
- Dental
- Vision
- Life insurance
- 401(k)
- Education assistance
- Paid time off including PTO
- Holidays
- Any other paid leave required by law
Work Environment and Physical Demands
- Primarily a Telework position with onsite requirements up to two (2) days a week.
- If the alternate worksite is other than DCSA facilities or corporate office space, the role requires reliable communication over voice (cell phone preferred) and a stable, capable internet connection.
- Must be able to communicate complex technical ideas to a diverse customer base verbally and in written form.