Type of Requisition:
Regular
Clearance Level Must Currently Possess:
Top Secret SCI + Polygraph
Clearance Level Must Be Able to Obtain:
None
Public Trust/Other Required:
None
Job Family:
Cyber and IT Risk Management
Job Qualifications:
Skills:
Data Reporting, Networks, Risk Management
Certifications:
None
Experience:
8 + years of related experience
US Citizenship Required:
Yes
Job Description:
- Conduct internal penetration testing and vulnerability assessment of servers, web applications, web services, and databases
- Manually exploit and compromise operating systems, web applications, and databases
- Examine results of web/OS scanners, scans and static source code analysis
- Identify vulnerabilities, misconfigurations, and compliance issues
- Write final reports, defend all findings to include the risk or vulnerability, mitigation strategies, and references
- Ability to meet and coordinate with various audiences to include developers, system administrators, project managers, and senior government stakeholders
- Provide security recommendations for developers, system administrators, project managers, and senior government stakeholders
- Report vulnerabilities identified during security assessments
- Write penetration testing Rules of Engagements (RoE), Test Plans, and Standard Operating Procedures (SOP)
- Conduct security reviews, technical research, and provided reporting to increase security defense mechanisms
- Make recommendations to the IC CISO or designee for improving TTPS for better cyber threat protection.
WHAT YOU’LL NEED TO SUCCEED
Bring your technology expertise and drive for innovation to GDIT. The Ethical Hacker/Penetration Tester Sr Principal must have:
- Education: Bachelor’s degree in computer engineering, Computer Science, Electrical Engineering, Information systems, Information Technology, Cybersecurity, or a closely related discipline.
- A Master’s degree in an applicable discipline be substituted for three years of demonstrated work experience
- Experience: 8+ years of related experience
- Security clearance level: TS/SCI with Polygraph
- US citizenship required
DESIRED SKILLS
- Certifications: CEH – Certified Ethical Hacker Certification, CPT – Certified Penetration Tester
- Strong writing skills
- Experience with NIST 800-53 and Risk Management Framework
- Knowledge of system and application security threats and vulnerabilities
- Knowledge of network access, identity, and access management e.g. public key infrastructure (PKI).
- Knowledge of network protocols such as Transition Control Protocol/Internet Protocol (TCP/IP), Dynamic Host Configuration, Domain Name System (DNS), and directory Services.
- Ability to assess the robustness of security systems and designs.
- Knowledge of cybersecurity principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).
- Write final reports and defend all findings, including risk or vulnerability, mitigation strategies, and references.
- Report vulnerabilities identified during security assessments.
- Conducted security reviews, technical research and provided reporting to increase security defense mechanisms.
- Travel Domestic 0-25%.
#WeAreGDIT
#JET
#VA_2026Alumni
The likely salary range for this position is $172,144 - $232,900. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
Scheduled Weekly Hours:
40
Travel Required:
Less than 10%
Telecommuting Options:
Onsite
Work Location:
USA MD Bethesda
Additional Work Locations:
Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.
Our Identity Verification Process:
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.