Penetration Tester III Security Clearance
Job in
Springfield, Fairfax County, Virginia, 22156, USA
Listed on 2026-07-28
Listing for:
Agile Defense, Inc.
Full Time
position Listed on 2026-07-28
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
About Agile Defense At Agile Defense we know that action defines the outcome and new challenges require new solutions. That’s why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next. Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility—leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation’s vital interests.
Requisition #: 1749
Job Title:
Penetration Tester III
Location:
Hybrid, Springfield, VA Clearance Level: Top Secret / SCI, Must Have Clearance to Start Required Certification(s): OSCP, GPEN or other related cybersecurity cert
Job Description Agile Defense is currently seeking a Senior Cyber Threat Emulation (TE) SME to support a federal Agency. The threat emulation program is part of a purple team that provides comprehensive computer network defense, incident response, and other cybersecurity support through monitoring and analysis of potential threat activity targeting the enterprise. This SME will run the offensive portion of the purple team.
The TE SME, as part of a small team, will have full latitude to execute penetration activity from initial infection vector to final report – the full spectrum of offensive operations, the entire killchain. The advanced TE SME advances organizational understanding over risks and potential exposures related to software, system, and network weakness using advanced security testing and auditing methods.
This senior level cyber TE analysts engage with senior leadership to identify, report, and perform real-world threat activity simulation attacks, such as those used by our nation’s adversaries, in order to train and measure the effectiveness of the people, processes, and technology used to defend Agency networks and systems. This full spectrum SME will develop and write targeted exploits and benign malware, pivoting through enterprise systems, and emulating malicious actors.
This SME uses malicious means to get into a position where he/she could disrupt the operations of Agency systems or maintain persistence for the purposes of further exploitation. Additionally, the ideal candidate is familiar with intrusion detection systems, intrusion analysis, security information event management platforms, endpoint threat detection tools, and federal agency SOC procedures. Corporate duties such as solution proposals. In support of this task and the activities listed above, the Contractor shall:
* Research and remain up to date with emerging threats and Threat Emulation methodologies.
* Map Cyber Key Terrain and generate priority target lists.
* Engage in project meetings to gain knowledge of changes to the infrastructure and information sources that will aid the Threat Emulation Team.
* Conduct research on commercial and open-source tools that may address capability gaps in detecting and/or blocking malicious activity.
* Be familiar with development of attack vectors, system and infrastructure reconnaissance, collection of open‐source intelligence, enumeration, and foot-printing of target networks and services.
* Conduct in-depth analysis of computer network and host data to determine threat patterns and unusual behaviors to identify potential TTPs employed by adversarial APTs and identify related APT activities and malware within operational networks and systems.
* Use TTPs to emulate real-world threats in order to train and measure the effectiveness of the people, processes, and technology used to defend environments.
* Engage with other Agency offices to gain access to various information sources in support of Threat Emulation activities.
* Review collected monitoring and defense information that will be used as inputs or indicators of abnormalities or malicious activity for threat simulation development.
* Generate threat intelligence indicators during emulation operations as part of research and apply and fine tune them across the enterprise network.
* Develop and write (Python, Rust, Power Shell or your language of…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×