Penetration Tester

Leidos Holding • $87K — $157K *
Aerospace & Defense
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, IT, Engineering, or related field with 4-8 years of experience.
  • Experience with penetration testing, vulnerability assessment, and threat hunting.
  • Knowledge of enterprise networks, applications, and code security assessments.
  • Proficient with penetration-testing tools and methodologies.
  • Ability to document and communicate technical findings effectively.
  • Must possess U.S. Citizenship and Active Secret Security Clearance.

Responsibilities

  • Conduct penetration tests and threat-hunting assessments per DMDC and NIST guidelines.
  • Develop assessment plans and technical test methodologies suited to the target environment.
  • Execute tests on various systems including networks, applications, and code.
  • Identify exploitable weaknesses and assess their potential impact on the mission.
  • Conduct threat-hunting activities to detect undetected malicious actions.
  • Collaborate with cybersecurity teams to validate detection capabilities of tools.
  • Document testing results and provide actionable remediation recommendations.

Benefits

  • Support for continuing education and professional development.
  • Health, dental, and vision insurance options available.
  • 401(k) retirement plan with company match.
  • Flexible work hours and potential for remote work.
  • Paid time off and holidays.
Full Job Description
Leidos is seeking experienced Penetration Tester to support the Defense Manpower Data Center (DMDC) CyberPRIMES program. Leidos is a major partner on the contract and will provide a substantial portion of the cybersecurity workforce supporting the Defense Human Resources Activity (DHRA) and DMDC.

The Penetration Tester will conduct Government-directed penetration testing and threat-hunting assessments across DHRA systems, networks, applications, and supporting technologies. This position will identify exploitable weaknesses, validate the effectiveness of defensive cybersecurity capabilities, and provide actionable findings that help system owners and cybersecurity teams reduce risk.

Work Location: Mark Center, Alexandria, Virginia

Mission Environment

DMDC supports the Defense Human Resources Activity within the Office of the Under Secretary of Defense for Personnel and Readiness (OUSD(P&R)) and maintains the Department of Defense's largest and most comprehensive central repository of personnel, manpower, casualty, pay, entitlement, personnel security, identity, readiness, training, and related data. The DHRA Information Technology (IT) environment includes approximately 15,000 network and endpoint devices supporting more than 600 Government-Off-The-Shelf (GOTS) applications and approximately 100 Risk Management Framework (RMF) authorization boundaries managed through the Enterprise Mission Assurance Support Service (eMASS).

The penetration-testing team conducts Government-selected assessments of DHRA programs and also performs ad hoc testing with cybersecurity-tool administrators and Security Operations Center personnel to determine whether defensive capabilities are detecting and alerting as intended. Testing may span enterprise networks, web applications, applications, code, and other mission systems.

Primary Responsibilities:
  • Conduct Government-selected penetration-testing assessments and threat-hunting activities in accordance with established DMDC procedures and the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-115.
  • Develop assessment plans, methodologies, test objectives, rules of engagement, and technical approaches appropriate to the target environment.
  • Execute authorized penetration-testing activities against networks, systems, applications, web applications, and code.
  • Identify vulnerabilities, exploitable configurations, attack paths, and weaknesses that could be used by a malicious actor.
  • Assess the practical exploitability and potential mission impact of identified security weaknesses.
  • Research emerging and existing threats, attack techniques, vulnerabilities, and adversary behaviors that may affect DHRA systems.
  • Develop testing methodologies designed to identify areas of risk likely to be targeted by an intruder.
  • Conduct threat-hunting activities to identify suspicious or malicious activity that may not be detected through routine monitoring.
  • Perform cooperative testing with cybersecurity-tool administrators, Security Operations Center (SOC) analysts, incident-response personnel, and Security Information and Event Management (SIEM) content developers.
  • Validate whether enterprise cybersecurity tools properly detect, generate alerts for, and support analysis of authorized offensive activity.
  • Identify detection or alerting gaps discovered during testing and provide technical findings to the appropriate cybersecurity teams.
  • Support pre-audit penetration testing to identify exploitable weaknesses before formal assessments or reviews.
  • Apply established penetration-testing methodologies and approved commercial or open-source offensive-security tools.
  • Support Red Team and Blue Team activities designed to evaluate and improve enterprise cybersecurity defenses.
  • Document testing activities, technical evidence, vulnerabilities, exploitation results, and risk findings.
  • Develop post-assessment out-briefs and final assessment reports for Government stakeholders.
  • Provide technically actionable remediation recommendations based on assessment findings.
  • Coordinate findings with system owners, application teams, network engineers, cybersecurity personnel, SOC analysts, and incident responders.
  • Maintain Government-Furnished Equipment and approved penetration-testing systems, laptops, software, and tools required to perform assessments.
  • Protect assessment data, technical artifacts, credentials, exploit information, and other sensitive testing information in accordance with Government requirements.


Basic Qualifications:
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical discipline and 4 - 8 years of prior relevant experience in order to operate within the scope contemplated by the level. Specific experience, education and training may be considered in lieu of degree.
  • Experience conducting penetration testing, vulnerability assessment, threat hunting, offensive security, or comparable cybersecurity assessment activities.
  • Experience assessing enterprise networks, systems, applications, web applications, or code for exploitable cybersecurity weaknesses.
  • Experience using commercial or open-source penetration-testing and offensive-security tools.
  • Understanding of common attack techniques, exploitation methods, network protocols, operating systems, and application-security concepts.
  • Experience developing penetration-testing methodologies, test plans, or technical assessment procedures.
  • Experience documenting vulnerabilities, technical evidence, exploitation results, and remediation recommendations.
  • Ability to distinguish theoretical vulnerabilities from weaknesses that present practical exploitation or mission risk.
  • Ability to communicate technical findings clearly to system owners, engineers, cybersecurity personnel, and Government stakeholders.
  • Ability to conduct authorized offensive-security activities within defined rules of engagement and Government-approved procedures.
  • U.S. Citizenship required.
  • Active Secret security clearance required.


Preferred Qualifications:
  • Experience conducting penetration testing within Department of Defense or Federal environments.
  • Experience applying National Institute of Standards and Technology Special Publication 800-115 testing methodologies.
  • Experience conducting network, web-application, application, and source-code security assessments.
  • Experience performing threat hunting or adversary-emulation activities.
  • Experience supporting Red Team and Blue Team exercises.
  • Experience working with Security Operations Center analysts and incident responders during cooperative testing.
  • Experience validating SIEM detections, security alerts, or cybersecurity-tool effectiveness using controlled offensive activity.
  • Experience conducting pre-audit or pre-authorization security assessments.
  • Experience researching emerging vulnerabilities, attack techniques, and adversary tradecraft.
  • Experience developing executive and technical penetration-testing out-briefs and assessment reports.
  • Familiarity with Department of Defense Risk Management Framework processes.
  • Familiarity with DHRA, DMDC, or comparable Department of Defense enterprise environments.


Original Posting:
September 22, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:
Pay Range $87,100.00 - $157,450.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

About Leidos Holding

Leidos Holding Careers

Joining Leidos Holding presents an unparalleled opportunity to advance one's career with a leader in innovation and technology. The company offers a plethora of job opportunities aimed at fostering professional growth and development in a diverse and inclusive environment.

Explore Career Opportunities

Leidos Holding is actively seeking skilled professionals who are passionate about leveraging their expertise to drive innovation and leadership in their fields. With a variety of open positions, Leidos Holding provides a platform for individuals to challenge themselves in a dynamic work environment.

Innovation and Professional Growth

At Leidos Holding, innovation is at the core of everything they do. Employees are encouraged to think creatively and push boundaries. The company supports this drive for innovation through comprehensive professional development and diversity training programs that are designed to enhance skills and foster leadership.

Commitment to Diversity and Inclusion

Leidos Holding is committed to creating a workplace where diversity is not only recognized but celebrated. With a culture that values and promotes diversity, Leidos Holding ensures that all team members have the opportunity to contribute, learn, and grow.

Internship Programs

For those starting their career, Leidos Holding offers internship programs that provide a robust foundation in the industry. Internships are a great way to develop essential skills, gain valuable work experience, and build professional networks.

Benefits and Culture

Employees at Leidos Holding enjoy a range of benefits designed to support their professional and personal lives. The company culture is built on a foundation of respect and integrity, providing a supportive and collaborative environment where every team member is valued.

Join the Team

Leidos Holding is hiring! Explore job opportunities that match your skills and interests. Leidos Holding looks for driven, curious, and innovative individuals to join their team. Positions are available across various disciplines and experience levels.

Stay Connected

Stay informed with the latest career tips, industry insights, and company news from Leidos Holding. Subscribe to receive updates and be the first to know about new job opportunities, company developments, and more.

Prepare for Your Interview

To prepare for an interview at Leidos Holding, candidates should familiarize themselves with the company's missions and values, update their resumes, and be ready to discuss how their background and skills align with the position they are applying for.

Networking and Career Advancement

Leidos Holding encourages its employees to engage in networking within the company to discover new opportunities for career advancement. The leadership team at Leidos Holding is dedicated to supporting employees in their career paths with ample opportunities for networking and growth.

Explore Leidos Holding Jobs and Careers

Discover the exciting career opportunities at Leidos Holding today. With a commitment to employee growth, innovation, and diversity, Leidos Holding is the perfect place to advance your career. Check out the latest job listings and find your perfect fit at Leidos Holding.

SEARCH LEIDOS HOLDING JOBS

READ CAREERS BLOG

Job Alert Emails

Customize your subscription to receive job alerts and insider tips tailored to your preferences from Leidos Holding. See what exciting and rewarding opportunities await in your professional journey.
Learn more about Leidos Holding

Similar Jobs

More Jobs at Leidos Holding

  • Virtualization Engineer
    $107K — $195K *
    Arlington, VA 22204 (Arlington County)
    Information Technology
    In-Person
  • CSWO
    $87K — $157K *
    Washington, DC 20011 (District Of Columbia County)
    Aerospace & Defense
    In-Person
  • Penetration Tester
    $87K — $157K *
    Alexandria, VA 22304 (Alexandria City County)
    Aerospace & Defense
    In-Person
  • Data Scientist
    $131K — $237K *
    Chantilly, VA 20152 (Loudoun County)
    Aerospace & Defense
    In-Person
  • Shipboard Installer V
    $59K — $106K *
    Norfolk, VA 23503 (Norfolk City County)
    Aerospace & Defense
    In-Person

More Aerospace & Defense Jobs

Find similar Penetration Tester jobs: