Penetration Tester - Lead Job at cFocus Software Incorporated, Washington DC

bUJFVTVESmI0Y2xQL29VSW5uNzZGZTRIVEE9PQ==
  • cFocus Software Incorporated
  • Washington DC

Job Description

Penetration Tester – Lead 

Position: Penetration Tester - Lead
Program: SBA Enterprise Cybersecurity Services (ECS)

Position Summary

The Penetration Tester – Lead supports the Small Business Administration (SBA) Enterprise Cybersecurity Services (ECS) program by leading advanced penetration testing, vulnerability assessment, adversarial simulation, and security validation activities supporting enterprise cybersecurity operations. 
The Penetration Tester – Lead performs expert-level offensive cybersecurity activities including network penetration testing, web application assessments, cloud security testing, wireless testing, red team operations, social engineering support, exploit validation, security control effectiveness testing, and advanced vulnerability analysis. The position provides technical leadership, testing strategy development, remediation validation, and risk-based recommendations to improve SBA’s cybersecurity posture and enterprise resilience.

Essential Duties and Responsibilities

  • Lead enterprise penetration testing and vulnerability assessment activities supporting SBA ECS cybersecurity initiatives.
  • Support Task Areas 3.5.4 and 3.5.4.7 by conducting advanced offensive security testing against enterprise systems, applications, cloud environments, networks, and security architectures.
  • Plan, coordinate, and execute internal and external penetration testing engagements in accordance with federal cybersecurity standards and approved Rules of Engagement (ROE).
  • Conduct application security testing against web applications, APIs, mobile applications, and cloud-hosted systems.
  • Perform network penetration testing, exploitation, lateral movement analysis, privilege escalation testing, and post-exploitation activities.
  • Execute adversarial emulation and red team exercises to evaluate security controls, monitoring capabilities, and incident response effectiveness.
  • Conduct vulnerability validation, exploit research, attack-path analysis, and risk prioritization activities.
  • Assess cloud security controls and configurations across Microsoft Azure, AWS, Microsoft 365, SaaS, and hybrid cloud environments.
  • Perform wireless security testing, password auditing, authentication testing, and identity management assessments.
  • Support phishing assessments, social engineering testing, and security awareness validation activities where authorized.
  • Develop detailed technical penetration testing reports, executive summaries, remediation guidance, and risk assessment documentation.
  • Provide technical recommendations for remediation of identified vulnerabilities, misconfigurations, and security gaps.
  • Validate remediation efforts and conduct follow-up testing to confirm resolution of identified findings.
  • Support development and refinement of penetration testing methodologies, procedures, testing standards, and operational playbooks.
  • Coordinate with security engineers, SOC analysts, ISSOs, system administrators, cloud engineers, and program managers during testing activities.
  • Assist with security architecture reviews, threat modeling, and attack surface analysis activities.
  • Use automated and manual testing techniques to identify vulnerabilities and validate exploitability.
  • Operate and maintain penetration testing toolsets, attack frameworks, vulnerability scanners, and security testing platforms.
  • Support compliance and assessment activities aligned with NIST RMF, NIST SP 800-53, FISMA, FedRAMP, and Zero Trust Architecture requirements.
  • Provide technical leadership and mentorship to junior penetration testers and cybersecurity analysts.
  • Participate in incident response support, forensic investigations, and threat hunting activities as required.
  • Support DevSecOps and secure software development initiatives through application security testing and code review support.
  • Ensure all testing activities comply with federal security policies, legal requirements, approved authorizations, and ethical hacking standards.

Minimum Qualifications

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, Information Systems, or related discipline. Relevant experience may substitute for degree requirements.
  • Minimum of 10 years of experience supporting penetration testing, vulnerability assessments, offensive cybersecurity operations, red teaming, or advanced cybersecurity engineering.
  • Extensive experience conducting penetration testing against enterprise networks, web applications, cloud environments, and operating systems.
  • Advanced knowledge of offensive security methodologies, exploitation frameworks, attack techniques, and adversarial tactics.
  • Experience using penetration testing and security assessment tools such as Metasploit, Burp Suite, Nessus, Nmap, Kali Linux, Cobalt Strike, BloodHound, Wireshark, and related platforms.
  • Strong understanding of network protocols, operating systems, identity management, authentication mechanisms, and cloud architectures.
  • Experience with scripting or programming languages such as Python, PowerShell, Bash, JavaScript, or Go.
  • Knowledge of NIST RMF, NIST SP 800-53, FISMA, FedRAMP, MITRE ATT&CK, and Zero Trust Architecture concepts.
  • Experience leading penetration testing teams, coordinating testing engagements, and presenting findings to technical and executive stakeholders.
  • Strong analytical, problem-solving, technical writing, and communication skills.
  • Experience supporting federal agencies or government cybersecurity environments preferred.

Preferred Certifications

  • Offensive Security Certified Professional (OSCP)
  • Offensive Security Experienced Penetration Tester (OSEP)
  • GIAC Penetration Tester (GPEN)
  • GIAC Exploit Researcher and Advanced Penetration Tester (GXPN)
  • Certified Ethical Hacker (CEH)
  • Certified Information Systems Security Professional (CISSP)
  • CompTIA PenTest+
  • GIAC Web Application Penetration Tester (GWAPT)
  • Certified Red Team Professional (CRTP)
  • AWS Certified Security – Specialty
  • Microsoft Certified: Azure Security Engineer Associate

Job Tags

Full time

Similar Jobs

All of Creation Pet Care, LLC

Dog Walker/Pet Sitter Job at All of Creation Pet Care, LLC

 ...for a temporary/seasonal job. All of Creation Pet Care is hiring dog walkers and pet-sitters in the South Riding/Aldie, Centreville/...  ...overnight stays. Availability for both dog walking and pet sitting is preferred. Requirements: Must have good communication... 

Medical University of South Carolina

UNIV Post Doctoral Scholar Pharmacology & Immunology Job at Medical University of South Carolina

 ...Job Description Additional Knowledge skill ability preferred: The ideal candidate is to have the research experience in immunology and molecular biology. Detailed-driven. Guideline and Supervision: ~ Detailed-driven. Job Duties: 1. Maintain... 

Baldwin & Obenauf, Inc.

Creative Agency Project Manager - Somerville NJ Job at Baldwin & Obenauf, Inc.

 ...Were a creative-driven, full-service boutique agency with big-name clients like Verizon, Mastercard and Johnson & Johnson. Youre a detail-oriented, planning, and organizational wizard ready for a new challenge. Job Description: At BNO, the Project Manager is the... 

Compass Group

MAINTENANCE TECHNICIAN (CARPENTRY) (FULL TIME) Job at Compass Group

 ...We are hiring immediately for a full time MAINTENANCE TECHNICIAN (CARPENTRY) position. Location : East Texas A&M Mn - 2600 South Neal Street, Commerce, TX 75428. (Openings at other locations within school district available) Note: online applications accepted... 

NBCUniversal

Entertainment, Lifestyle & Community MMJ - Telemundo T49 Fort Myers Job at NBCUniversal

NBCUniversal is one of the world's leading media and entertainment companies. We create world-class content, which we distribute across our portfolio of film, television, and streaming, and bring to life through our global theme park destinations, consumer products...