Senior Penetration Tester – Assessments Lead

Job not on LinkedIn

🔥 20 hours ago

🇺🇸 United States – Remote

💵 $90.3k - $189.6k / year

⏰ Full Time

🟠 Senior

🔧 QA Engineer (Quality Assurance)

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of CACI International Inc

CACI International Inc

10,000+ employees

Founded 1962

🎖️ Defense

🏛️ Government

🔒 Cybersecurity

🔥 Funding within the last year

💰 $500M Post-IPO Debt on 2026-02

Defense • Government • Cybersecurity

CACI International Inc is a U. S. -based government contractor that provides technologies and professional services to national security, defense, and federal civilian customers. CACI delivers solutions across cyber and digital operations, enterprise IT modernization, electronic warfare, counter-unmanned systems (C-UxS), space and optical communications, agile DevSecOps software development, and mission engineering and logistics support. The company positions itself as a large prime contractor that uses advanced software, analytics, sensing, and hardware to detect and counter evolving threats and modernize government technology architectures.

📋 Description

• Lead assigned penetration-testing engagements from scoping and rules-of-engagement development through test planning, execution, reporting, out-briefing, and remediation clarification • Translate customer objectives, architecture, constraints, and safety requirements into sequenced assessment plans with authorization boundaries and deconfliction procedures • Direct and mentor junior testers while conducting complex network, web/API, Active Directory/AD CS, Linux, Windows, AWS, Azure, and identity-focused attack paths • Validate vulnerabilities through safe manual testing and controlled exploitation without disrupting operations or altering live data • Review scanner output and operator evidence, eliminate false positives, reproduce findings, assign severity, and prioritize remediation • Ensure assessment reports document scope, methods, evidence, attack paths, root causes, risk, and actionable remediation recommendations • Perform technical quality review before report delivery • Lead technical discussions and customer out-briefs, answer remediation questions, and support validation of corrected weaknesses • Escalate scope conflicts, safety issues, unanticipated access, and material findings to the Technical Lead and customer points of contact • Provide continuous technical assessment support for proactive testing of externally and internally visible federal cyber assets supporting the CDM Program

🎯 Requirements

• U.S. citizenship is required • Must meet eligibility requirements for access to sensitive information • Must be able to obtain a Public Trust fitness determination (High Risk) • Ability to work in customer-provided remote environments and comply with rules of engagement, data-handling requirements, evidence controls, deconfliction procedures, and stop-work criteria • Five or more years of hands-on penetration-testing or offensive-security experience, including at least two years leading technical assessments or small assessment teams • Ability to scope, plan, execute, and report enterprise penetration tests across internal/external networks, web applications/APIs, Windows/Active Directory, Linux, and cloud environments • Advanced experience with Nmap, Tenable/Nessus, Burp Suite Pro, OWASP ZAP, Metasploit, BloodHound, PowerView, Impacket, NetExec, Certipy/Certify, Wireshark/tcpdump, and comparable customer-approved tools • Strong manual-testing skills, including exploit validation, attack-path development, evidence preservation, and safe proof-of-concept creation • Ability to produce technically accurate assessment reports and brief technical and senior customer audiences • One or more recognized hands-on certifications such as OSCP, OSEP/OSCE, OSWE, GPEN, GXPN, GWAPT, PNPT, CPTS, or equivalent • Desired: Eight or more years of offensive-security experience across multiple enterprise assessment domains • Desired: CISA AES/HVA Assessment Lead or Technical Lead experience, or comparable federal high-value-asset assessment leadership • Desired: Advanced AWS/Azure, Kubernetes/container, mobile, IoT, wireless, database, or source-code security-testing experience • Desired: ICS/OT, critical-infrastructure, restricted-network, or air-gapped assessment experience • Desired: Experience developing reusable assessment playbooks, report templates, test harnesses, automation, or internal training

🏖️ Benefits

• Flexible time off benefit • Robust learning resources • Healthcare benefits • Wellness benefits • Financial benefits • Retirement benefits • Family support benefits • Continuing education benefits • Time off benefits • Competitive compensation • Learning and development opportunities

Apply Now

Similar Jobs

🕒 Yesterday

Warner Bros. Discovery

10,000+ employees

📱 Media

🎮 Gaming

Quality Assurance Lead shaping scalable testing for Warner Bros. Games’ online multiplayer RPG. Improving coverage through tooling, telemetry, simulation, and data-informed quality practices.

🕒 Yesterday

Elevar Therapeutics

11 - 50

🧬 Biotechnology

💊 Pharmaceuticals

🏥 Healthcare

Senior Director overseeing QA systems, GMP compliance, audits, and quality improvement for Elevar Therapeutics’ drug manufacturing operations.

🇺🇸 United States – Remote

💵 $225k - $275k / year

💰 $20M Venture Round - Elevar Therapeutics on 2018-07

⏰ Full Time

🟠 Senior

🔧 QA Engineer (Quality Assurance)

🕒 Yesterday

Dexcom

10,000+ employees

🏥 Healthcare

💼 Consulting

🏭 Manufacturing

Software QA Engineer investigating postmarket issues for Dexcom’s continuous glucose monitoring technology. Driving risk assessments, root-cause analysis, and quality improvements.

🕒 Yesterday

PALCO

2 - 10

🤝 B2B

📣 Marketing

QA Tester II leading automated and manual testing for Palco’s self-directed caregiver management programs. Ensuring compliant, defect-free software releases across multiple projects.

JMeter

SQL

🕒 Yesterday

Softthink Solutions

51 - 200

💼 Consulting

📦 Logistics

🏥 Healthcare

SQA Engineer ensuring software quality, testing, traceability, and compliance for Softthink Solutions, a US-based IT services consultancy. Supporting audits, lifecycle reviews, and corrective actions.