Senior Penetration Tester
Job Description
Govcio LLC is seeking a Senior Penetration Tester to lead advanced security testing efforts within TS/SCI environments, delivering hands-on assessments and remediation guidance for DHS-related work in Washington, DC. The role blends deep technical expertise with leadership responsibilities to strengthen security across systems, networks, cloud resources, and web applications.
Responsibilities
- Plan, lead, and supervise penetration testing across on‑premises systems, networks, cloud resources, and web applications within a TS/SCI environment.
- Carry out thorough vulnerability assessments and software assurance reviews, clearly documenting findings and guiding remediation strategies.
- Perform in‑depth analysis of security weaknesses, including buffer overflows, SQL injection, CSRF, XSS, TOCTOU race conditions, XXE, encryption flaws, and authentication bypass issues.
- Evaluate security considerations during software acceptance activities, defining criteria, assessing risk acceptance, reviewing documentation, and applying independent validation approaches.
- Apply advanced defense functions such as encryption, access control, and identity management to reduce exploitation risks, including supply chain concerns.
- Provide threat intelligence and vulnerability research aligned with NIST 800‑53 and MITRE ATT&CK to inform cloud security architecture decisions.
- Develop new or enhanced penetration testing methodologies to identify emerging vulnerabilities and expand organizational capability.
- Act as a senior technical advisor and mentor to the penetration testing team, ensuring consistency, quality, and rigor in testing efforts.
- Represent the penetration testing function in discussions with leadership, engineering teams, and mission stakeholders as required for Key Personnel roles.
Requirements
- Bachelor’s degree and 12+ years of penetration testing experience, or equivalent.
- Minimum 8 years supporting enterprise security architectures and cloud platforms (AWS, Azure, Google Cloud).
- Proven, extensive experience as a Penetration Tester in complex or classified environments.
- Advanced knowledge of penetration testing methodologies, offensive security techniques, and industry tools.
- Experience with AWS, Azure, RHEL, Linux, and Tenable.
- Hands‑on experience with Kali Linux, Burp Suite Pro, and Metasploit.
- Strong analytical and problem‑solving skills with the ability to think like an attacker.
- Excellent communication skills for delivering clear, actionable findings to technical and executive stakeholders.
- Preferred certifications: CEH, OSCP, or equivalent offensive security credentials.
- Active TS/SCI clearance is required.
Technologies
- AWS
- Azure
- Google Cloud
- RHEL
- Linux
- Tenable
- Kali Linux
- Burp Suite Pro
- Metasploit
- MITRE ATT&CK
- NIST 800-53
Overview
Govcio LLC is seeking a Senior Penetration Tester with an active TS/SCI clearance to support DHS onsite in Washington, DC.
Similar Jobs
J
S