×
Register Here to Apply for Jobs or Post Jobs. X

Senior Penetration Testing Lead

Job in Fairfax, Fairfax County, Virginia, 22032, USA
Listing for: ECS
Full Time position
Listed on 2026-06-12
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security, Security Manager, Data Security
Salary/Wage Range or Industry Benchmark: 100000 - 125000 USD Yearly USD 100000.00 125000.00 YEAR
Job Description & How to Apply Below

Senior Penetration Testing Lead

Everforth ECS is seeking a Senior Penetration Testing Lead to work in the National Capital Region covering the Pentagon, Falls Church, and Fairfax. This position is contingent upon contract award.

The War Data Platform (WDP) is a key initiative within the U.S. Department of War’s AI‑First strategy introduced in early 2026. The WDP separates business and financial data from operational war fighting data, aiming to accelerate the deployment of artificial intelligence on the battlefield. The WDP extends to Unclassified, Secret, and Top Secret environments, supporting collaboration between Combatant Commands, Joint Staff directorates, Senior Executive Service leaders, and operational analysts.

The Senior Penetration Testing Lead is the principal offensive security authority for WDP, planning and executing controlled adversarial assessments across NIPRNet, SIPRNet, and JWICS environments to validate control effectiveness, identify exploitable attack paths, and inform Risk Management Framework authorization decisions across WDP’s multi‑enclave architecture.

Responsibilities
  • Lead offensive security operations supporting Department of War mission systems across unclassified and classified networks.
  • Plan, coordinate, and execute controlled penetration testing engagements against network infrastructure, web applications, cloud environments, and mission systems to identify exploitable attack paths beyond automated scanning capabilities.
  • Develop testing strategies, rules of engagement, and assessment methodologies aligned with DoW cybersecurity policy and authorization objectives.
  • Conduct advanced adversary emulation activities including lateral movement analysis, privilege escalation, command‑and‑control simulation, and post‑exploitation impact assessment while maintaining operational safety and system availability.
  • Coordinate testing activities with system owners, ISSOs, network defenders, and security operations teams to deconflict operations and support rapid response if anomalous behavior is detected.
  • Produce comprehensive penetration test reports detailing attack vectors, exploitation techniques, evidence artifacts, and prioritized remediation recommendations.
  • Support red team exercises validating detection, response, and recovery capabilities across defensive teams and security tooling.
  • Perform remediation verification and retesting to confirm corrective actions effectively mitigate identified risks.
  • Maintain testing documentation, evidence repositories, and executive summaries supporting Risk Management Framework activities, authorization decisions, and leadership briefings.
  • Deliver actionable insights that strengthen defensive posture, validate control effectiveness, and reinforce program values of resilience, accountability, mission assurance, and proactive cyber defense.
  • Perform other duties as assigned.
Required Skills
  • Current Secret security clearance.
  • 10‑12 years of experience in penetration testing, offensive security, red team operations, or a closely related cybersecurity discipline, with demonstrated senior-level ownership of full‑lifecycle penetration test engagements across complex federal, DoW, or enterprise network and cloud environments.
  • IAM Level I certification from an approved credential, including CompTIA Security+ CE, ISC² CAP, ISC² SSCP, or GIAC GSLC.
  • Advanced offensive security certification such as Offensive Security Certified Professional (OSCP), Offensive Security Experienced Penetration Tester (OSEP), GIAC Penetration Tester (GPEN), GIAC Exploit Researcher and Advanced Penetration Tester (GXPN), or an equivalent credential demonstrating mastery of adversary emulation, exploitation techniques, and structured penetration testing methodology.
  • Proven experience supporting DoW or federal Risk Management Framework processes, including preparation and maintenance of penetration testing plans, rules of engagement, Body‑of‑Evidence artifacts, and remediation findings packages in support of Authority to Operate decisions and continuous monitoring obligations under NIST 800‑53.
  • Strong problem‑solving and decision‑making capabilities, with a proven ability to weigh the…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary