Penetration Tester

Leidos•Alexandria, VA
•$87,100 - $157,450•Onsite

About The Position

Leidos is seeking experienced Penetration Testers to support the Defense Manpower Data Center (DMDC) CyberPRIMES program. This role involves conducting Government-directed penetration testing and threat-hunting assessments across DHRA systems, networks, applications, and supporting technologies. The objective is to identify exploitable weaknesses, validate defensive cybersecurity capabilities, and provide actionable findings to reduce risk. The work environment is the Mark Center in Alexandria, Virginia. DMDC supports the Defense Human Resources Activity (DHRA) and manages a large repository of personnel and related data. The DHRA IT environment is extensive, with numerous devices, applications, and authorization boundaries. The penetration-testing team conducts assessments of DHRA programs and performs ad hoc testing to ensure defensive capabilities are functioning as intended, covering enterprise networks, web applications, applications, code, and other mission systems.

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical discipline and 4 – 8 years of prior relevant experience (Specific experience, education and training may be considered in lieu of degree).
  • Experience conducting penetration testing, vulnerability assessment, threat hunting, offensive security, or comparable cybersecurity assessment activities.
  • Experience assessing enterprise networks, systems, applications, web applications, or code for exploitable cybersecurity weaknesses.
  • Experience using commercial or open-source penetration-testing and offensive-security tools.
  • Understanding of common attack techniques, exploitation methods, network protocols, operating systems, and application-security concepts.
  • Experience developing penetration-testing methodologies, test plans, or technical assessment procedures.
  • Experience documenting vulnerabilities, technical evidence, exploitation results, and remediation recommendations.
  • Ability to distinguish theoretical vulnerabilities from weaknesses that present practical exploitation or mission risk.
  • Ability to communicate technical findings clearly to system owners, engineers, cybersecurity personnel, and Government stakeholders.
  • Ability to conduct authorized offensive-security activities within defined rules of engagement and Government-approved procedures.
  • U.S. Citizenship required.
  • Active Secret security clearance required.

Nice To Haves

  • Experience conducting penetration testing within Department of Defense or Federal environments.
  • Experience applying National Institute of Standards and Technology Special Publication 800-115 testing methodologies.
  • Experience conducting network, web-application, application, and source-code security assessments.
  • Experience performing threat hunting or adversary-emulation activities.
  • Experience supporting Red Team and Blue Team exercises.
  • Experience working with Security Operations Center analysts and incident responders during cooperative testing.
  • Experience validating SIEM detections, security alerts, or cybersecurity-tool effectiveness using controlled offensive activity.
  • Experience conducting pre-audit or pre-authorization security assessments.
  • Experience researching emerging vulnerabilities, attack techniques, and adversary tradecraft.
  • Experience developing executive and technical penetration-testing out-briefs and assessment reports.
  • Familiarity with Department of Defense Risk Management Framework processes.
  • Familiarity with DHRA, DMDC, or comparable Department of Defense enterprise environments.

Responsibilities

  • Conduct Government-selected penetration-testing assessments and threat-hunting activities in accordance with established DMDC procedures and NIST SP 800-115.
  • Develop assessment plans, methodologies, test objectives, rules of engagement, and technical approaches.
  • Execute authorized penetration-testing activities against networks, systems, applications, web applications, and code.
  • Identify vulnerabilities, exploitable configurations, attack paths, and weaknesses.
  • Assess the practical exploitability and potential mission impact of identified security weaknesses.
  • Research emerging and existing threats, attack techniques, vulnerabilities, and adversary behaviors.
  • Develop testing methodologies designed to identify areas of risk likely to be targeted by an intruder.
  • Conduct threat-hunting activities to identify suspicious or malicious activity.
  • Perform cooperative testing with cybersecurity-tool administrators, SOC analysts, incident-response personnel, and SIEM content developers.
  • Validate whether enterprise cybersecurity tools properly detect, generate alerts for, and support analysis of authorized offensive activity.
  • Identify detection or alerting gaps and provide technical findings to cybersecurity teams.
  • Support pre-audit penetration testing to identify exploitable weaknesses before formal assessments.
  • Apply established penetration-testing methodologies and approved commercial or open-source offensive-security tools.
  • Support Red Team and Blue Team activities.
  • Document testing activities, technical evidence, vulnerabilities, exploitation results, and risk findings.
  • Develop post-assessment out-briefs and final assessment reports for Government stakeholders.
  • Provide technically actionable remediation recommendations.
  • Coordinate findings with system owners, application teams, network engineers, cybersecurity personnel, SOC analysts, and incident responders.
  • Maintain Government-Furnished Equipment and approved penetration-testing systems, laptops, software, and tools.
  • Protect assessment data, technical artifacts, credentials, exploit information, and other sensitive testing information.

Benefits

  • Pay Range $87,100.00 - $157,450.00
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service