CybersecurityJobs.io
← Back to all jobs

Job Description

Leidos is seeking an experienced Penetration Tester to support the Defense Manpower Data Center (DMDC) CyberPRIMES program in Alexandria, VA (onsite). In this role, you will conduct Government-directed penetration testing and threat-hunting across DMDC systems, helping translate assessment results into actionable remediation guidance for mission stakeholders.

What you’ll work on

Testing will span enterprise networks, systems, applications, web applications, code, and supporting technologies. You will plan and execute authorized offensive security activities aligned to established DMDC procedures and NIST Special Publication (SP) 800-115, producing documentation that captures vulnerabilities, exploitation outcomes, and risk findings.

Responsibilities

  • Conduct Government-selected penetration-testing assessments and threat-hunting activities in accordance with DMDC procedures and NIST SP 800-115.
  • Develop assessment plans, methodologies, test objectives, rules of engagement, and technical approaches for the target environment.
  • Execute authorized penetration-testing activities against networks, systems, applications, web applications, and code.
  • Identify vulnerabilities, exploitable configurations, attack paths, and weaknesses that could be used by a malicious actor.
  • Assess practical exploitability and potential mission impact of identified security weaknesses.
  • Research emerging and existing threats, attack techniques, vulnerabilities, and adversary behaviors that may affect DHRA systems.
  • Develop testing methodologies intended to identify risk areas likely to be targeted by an intruder.
  • Perform cooperative testing with cybersecurity-tool administrators, SOC analysts, incident-response personnel, and SIEM content developers.
  • Validate whether enterprise cybersecurity tools properly detect, generate alerts for, and support analysis of authorized offensive activity.
  • Identify detection or alerting gaps found during testing and provide technical findings to the appropriate cybersecurity teams.
  • Support pre-audit penetration testing to identify exploitable weaknesses before formal assessments or reviews.
  • Apply approved penetration-testing methodologies and use approved commercial or open-source offensive-security tools.
  • Support Red Team and Blue Team activities focused on evaluating and improving enterprise defenses.
  • Document testing activities, technical evidence, vulnerabilities, exploitation results, and risk findings.
  • Create post-assessment out-briefs and final assessment reports for Government stakeholders.
  • Provide technically actionable remediation recommendations based on assessment findings.
  • Coordinate findings with system owners, application teams, network engineers, cybersecurity personnel, SOC analysts, and incident responders.
  • Maintain Government-Furnished Equipment and approved penetration-testing systems, laptops, software, and tools needed to perform assessments.
  • Protect assessment data, technical artifacts, credentials, exploit information, and other sensitive testing information in accordance with Government requirements.

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical discipline, and 4 to 8 years of prior relevant experience to operate within the scope contemplated by the level.
  • Specific experience, education, and training may be considered in lieu of degree.
  • Experience conducting penetration testing, vulnerability assessment, threat hunting, offensive security, or comparable cybersecurity assessment activities.
  • Experience assessing enterprise networks, systems, applications, web applications, or code for exploitable cybersecurity weaknesses.
  • Experience using commercial or open-source penetration-testing and offensive-security tools.
  • Understanding of common attack techniques, exploitation methods, network protocols, operating systems, and application-security concepts.
  • Experience developing penetration-testing methodologies, test plans, or technical assessment procedures.
  • Experience documenting vulnerabilities, technical evidence, exploitation results, and remediation recommendations.
  • Ability to distinguish theoretical vulnerabilities from weaknesses that present practical exploitation or mission risk.
  • Ability to communicate technical findings clearly to system owners, engineers, cybersecurity personnel, and Government stakeholders.
  • Ability to conduct authorized offensive-security activities within defined rules of engagement and Government-approved procedures.
  • U.S. Citizenship required.
  • Active Secret security clearance required.

Technologies

  • NIST Special Publication (SP) 800-115
  • SIEM
  • Enterprise Mission Assurance Support Service (eMASS)
  • Risk Management Framework (RMF)

Benefits

  • Competitive compensation
  • Health and Wellness programs
  • Income Protection
  • Paid Leave and Retirement

Mission environment

DMDC supports the Defense Human Resources Activity within the Office of the Under Secretary of Defense for Personnel and Readiness (OUSD(P&R)). DMDC maintains the Department of Defense’s largest and most comprehensive central repository of personnel, manpower, casualty, pay, entitlement, personnel security, identity, readiness, training, and related data. The DHRA IT environment includes approximately 15,000 network and endpoint devices supporting more than 600 Government-Off-The-Shelf (GOTS) applications and approximately 100 RMF authorization boundaries managed through eMASS. Testing may span enterprise networks, web applications, applications, code, and other mission systems.

Pay Range: $87,100.00 - $157,450.00 per year

Similar Jobs