Senior Penetration Tester / Vulnerability Assessment Engineer
Job Description
Tharros is seeking a Senior Penetration Tester / Vulnerability Assessment Engineer to support the Department of Homeland Security (DHS) with vulnerability identification, assessment, and validation across both cloud and on-premise environments. The position focuses on expert-driven, manual testing and requires on-site work within a Government SCIF in Washington, DC.
This role covers the full lifecycle of penetration testing and vulnerability assessment activities, from executing engagements through exploitation and post-exploitation, to producing actionable reporting and updating security procedures.
Responsibilities
- Conduct penetration tests across the DHS IE portfolio using established methodologies (including MITRE ATT&CK and OWASP), covering rules of engagement through exploitation, post-exploitation, and reporting.
- Apply manual techniques to identify vulnerabilities that automated tools commonly miss.
- Validate SOC incident response procedures through controlled testing.
- Perform software assurance activities through vulnerability and compliance testing of software requests, including providing approval recommendations.
- Carry out source code reviews using both automated tooling and manual review approaches.
- Execute vulnerability assessments and perform supply chain risk management (SCRM) reviews.
- Maintain the security posture of the penetration testing kit used for engagements.
- Update penetration testing, SCRM, and vulnerability assessment SOPs.
Requirements
- BS degree in Information Technology, Cybersecurity, Information Systems, or Computer Science, or minimum of 10 years’ experience in IT or cybersecurity.
- Minimum of 7 years’ experience in penetration testing or vulnerability assessment.
- Active TS/SCI clearance and U.S. citizenship; willingness to undergo a DHS counterintelligence-scope polygraph.
- Knowledge of penetration testing methodologies and frameworks, including MITRE ATT&CK, OWASP, and PTES.
- Knowledge of software assurance and secure code review practices.
- Knowledge of common attack vectors across network, application, and cloud layers.
- Ability to perform manual exploitation using tools such as Burp Suite, Metasploit, or Core Impact.
- Skill in static code analysis using tools such as SonarQube or Fortify.
- Ability to write clear penetration test reports, including recommended corrective actions.
- Proficiency in Microsoft Office Suite, including Teams or similar workplace chat and videoconferencing tools.
- Excellent written and oral communications skills.
Technologies
- MITRE ATT&CK, OWASP, PTES
- Burp Suite, Metasploit, Core Impact
- SonarQube, Fortify
- Microsoft Office Suite, Teams
- AWS, Azure
Desired
- OSCP, GPEN, GWAPT, CEH, or CISSP certification.
- Cloud (AWS, Azure) or Cross Domain Solution testing experience.
Location: Washington, DC (onsite)