Penetration Tester Mid-Level
Job Description
Onsite role in Ashburn, VA supporting CBP Cyber Security Directorate activities. This mid-level penetration testing position combines hands-on assessment work across a wide range of environments and the chance to drive meaningful improvements through documented findings and retesting cycles.
Compensation for the role is USD 107,744 - 129,375 per year. U.S. citizenship is required, and the position is designated with Public Trust: BI Full 6C (T4).
What you’ll do
- Run hands-on penetration tests across networks, applications, endpoints, cloud workloads, and mission systems to identify exploitable security weaknesses.
- Apply industry-standard offensive tooling to uncover issues such as misconfigurations, privilege escalation paths, insecure protocols, and application-level vulnerabilities.
- Conduct both credentialed and non-credentialed testing, covering reconnaissance, enumeration, exploitation, post-exploitation analysis, and vulnerability validation.
- Assess vulnerabilities for exploitability, impact, and potential operational risk, supporting clear prioritization decisions.
- Analyze complex, cross-domain environments including hybrid cloud, containerized platforms, mobile, and legacy systems to identify security gaps.
- Create detailed technical assessment reports that include vulnerability descriptions, exploitation steps, affected assets, and prioritized remediation recommendations.
- Support follow-up assessments and retesting cycles to confirm remediation completeness and sustained risk reduction.
Tools you’ll use
Work will involve technologies such as Nmap, NESSUS, Metasploit, Burp Suite, CANVAS, and Kismet, along with other offensive frameworks as needed.
What you bring
- 3+ years of penetration testing or offensive security experience.
- Strong understanding of exploit development concepts, offensive tooling, and common security control weaknesses.
- Experience conducting network, application, and wireless assessments using modern red-team methodologies.
- Ability to produce structured documentation with clear technical writing and effective communication to both technical and non-technical audiences.
- Preferred certifications: CompTIA PenTest+, eJPT / eCPPT, OSCP (highly valued), GIAC Penetration Tester (GPEN).
- Education preference: Bachelor’s degree in information technology, computer science, cybersecurity, or a related field.
- Preferred: Previous or current CBP Background Investigation.
Work requirements & eligibility
- Travel: Less than 10%
- Citizenship: U.S. Citizenship Required
- Clearance level: None listed
- Public Trust: BI Full 6C (T4)
Identity verification
The hiring process may include virtual interview steps where you are expected to be on camera. The employer reserves the right to take a picture to verify your identity and help prevent fraud.