Penetration Tester

Dragonfli GroupWashington, DC
8h

About The Position

As a Penetration Tester, you will be responsible for evaluating the security of a large federal agency’s applications, networks, cloud environments, and supporting infrastructure. This role focuses on hands-on manual testing and controlled exploitation to identify and help remediate vulnerabilities. The ideal candidate will possess at least 3–5 years of experience in offensive security, with a deep proficiency in manual application testing and vulnerability validation across on-prem and cloud assets. This is a multi-year contract position involving a large US federal agency. Candidates with previous federal contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.

Requirements

  • Strong understanding of web application security and modern attack techniques.
  • Demonstrated ability to distinguish false positives from exploitable issues.
  • Proven experience documenting evidence and providing pragmatic remediation guidance.
  • Ability to operate within strict rules of engagement and ethical safety constraints.
  • U.S. Citizenship or Permanent Residency (Green Card).

Nice To Haves

  • Previous experience supporting federal contracting environments.
  • Experience with mobile (Android/iOS) or cloud penetration testing (AWS/Azure/GCP).
  • Experience with CI/CD and supply chain security testing.
  • Familiarity with modern app architectures like microservices and containers.

Responsibilities

  • Engagement Scoping & Planning: Partner with stakeholders to define objectives, rules of engagement, and success criteria to ensure safe execution.
  • Reconnaissance & Enumeration: Perform passive and active discovery of attack surfaces, services, and APIs to map trust boundaries.
  • Manual Application Testing: Conduct deep testing of web and mobile apps aligned with OWASP Top 10 and common design flaws.
  • Vulnerability Validation: Safely verify findings such as XSS, SQLi, CSRF, SSRF, and broken access control to demonstrate real-world impact.
  • Network & Infrastructure Testing: Identify weaknesses in exposed services, insecure protocols, and misconfigurations across hybrid environments.
  • Post-Exploitation Analysis: Assess blast radius, lateral movement paths, and persistence risks while minimizing operational impact.
  • Reporting & Remediation: Deliver clear technical reports with reproduction steps and prioritized fixes for both engineers and leadership.

Benefits

  • Insurance - health, dental, and vision
  • Paid Time Off (PTO) and 11 Federal Holidays
  • 401(k) employer match
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service