Penetration Tester, Level 3 (FORECASTED)
Independent Software
- Fort Meade, MD
- Permanent
- Full-time
- Conduct vulnerability and penetration testing across networks and applications using industry-standard tools and techniques
- Evaluate the effectiveness of security controls by simulating real-world attacks
- Research and analyze emerging technologies relevant to offensive security
- Interpret and apply federal and organizational security regulations to inform testing strategies
- Collaborate with security analysts, engineers, and system owners to support the Risk Management Framework (RMF) lifecycle
- Prepare detailed reports and briefings on findings and recommendations
- Perform both automated and manual testing to identify weaknesses in protocols, configurations, or custom applications
- Advise on mitigation strategies and assist in remediation planning
- Contribute to the development of internal testing protocols and continuous improvement of red team capabilities
- Strong knowledge of penetration testing methodologies and tools
- Hands-on experience in testing both network and application-level systems
- Familiarity with operating systems, networking protocols, and security configurations
- Ability to analyze and interpret scan results, exploit vulnerabilities, and document technical findings
- Strong communication skills to convey complex security issues to both technical and nontechnical audiences
- Ability to work independently and as part of a collaborative security team
- Minimum of eight years of experience as a Penetration Tester performing both network and application-level testing
- Bachelor’s degree in Computer Science, Information Technology Engineering, or a related technical field
- In lieu of a bachelor’s degree, an additional four years of relevant penetration testing experience may be substituted
- Must meet applicable DoD 8570.01-M certification requirements
- Relevant certifications may include but are not limited to:
- Offensive Security Certified Professional (OSCP)
- GIAC Penetration Tester (GPEN)
- Certified Ethical Hacker (CEH)
- CompTIA PenTest+
- Must possess an active TS/SCI with appropriate Polygraph to be considered for this role