Qualifications
Responsibilities
Benefits
GovCIO is currently hiring for a Senior Pentration Tester with an active TS/SCI clearance to support DHS onsite in Washington, DC.
ResponsibilitiesThe Senior Penetration Tester serves as Key Personnel responsible for leading advanced penetration testing and vulnerability assessment activities within a TS/SCI environment. This role ensures missioncritical security assurance across enterprise systems, applications, and cloud infrastructures by applying deep technical expertise, zerotrust principles, and attackerfocused methodologies. The Senior Penetration Tester guides technical direction, ensures rigorous execution, and provides authoritative recommendations to strengthen security posture across sensitive environments.
Lead, plan, and oversee penetration testing operations for systems, networks, cloud resources, and webbased applications in a TS/SCI environment
Execute comprehensive vulnerability assessments and software assurance evaluations; authoritatively document findings and drive remediation strategies
Conduct deep technical analysis of vulnerabilities including buffer overflows, SQL injection, CSRF, XSS, race conditions (TOCTOU), XXE, encryption weaknesses, authentication bypass, and similar issues
Assess and advise on security considerations during software acceptance activities, including criteria definition, risk acceptance evaluation, documentation review, and independent validation approaches
Apply advanced security defense functions (encryption, access control, identity management) to reduce exploitation risks, including those related to supply chain considerations
Provide threat intelligence insights and vulnerability research aligned with frameworks such as NIST 80053 and MITRE ATT&CK to inform cloud security architecture decisions
Develop new or enhanced penetration testing methodologies to identify emerging vulnerabilities and expand organizational capability
Serve as a senior technical advisor and mentor to penetration testing staff; ensure consistency, quality, and rigor in testing execution
Represent the penetration testing function in discussions with leadership, engineering teams, and mission stakeholders as required for Key Personnel roles
Minimum of 8 years of experience supporting enterprise security architectures and cloud platforms (AWS, Azure, Google Cloud)
Proven, extensive experience as a Penetration Tester in complex or classified environments
Advanced knowledge of penetration testing methodologies, offensive security techniques, and industry tools
Experience with AWS, Azure, RHEL, Linux, and Tenable
Hands-on experience with tools including Kali Linux, Burp Suite Pro, and Metasploit
Strong analytical and problemsolving skills with an ability to think like an attacker
Excellent communication skills to deliver clear, actionable findings to both technical and executive stakeholders
Preferred certifications: CEH, OSCP, or equivalent offensive security certifications
About GovCIO
Similar Jobs





More Jobs at GovCIO




More Information Technology Jobs
