More jobs:
Penetration Testing Lead
Job in
Washington, District of Columbia, 20022, USA
Listed on 2026-08-02
Listing for:
Jobtailor
Full Time
position Listed on 2026-08-02
Job specializations:
-
Engineering
Cybersecurity
Job Description & How to Apply Below
Responsibilities
- Serve as primary technical point of contact for all penetration testing activities, including network, system, application, aircraft cyber, and specialized assessments.
- Develop Rules of Engagement (ROE) with system owners and ACG for each penetration test.
- Ensure all parties understand scope, constraints, and reporting requirements before testing begins.
- Personally lead high‑complexity penetration tests in NAS and Mission Support environments.
- Direct testing teams during execution.
- Plan and execute red team and blue team exercises in simulated environments as directed by the FAA.
- Design realistic attack scenarios that test the effectiveness of NAS cybersecurity defenses.
- Document all penetration test results in Penetration Test Reports (PTRs) including attack vectors tested, vulnerabilities discovered, exploitation paths, and recommended remediation actions.
- Assess and document impact when access is gained during testing, including potential cascading effects on associated systems and network infrastructure.
- Report high‑risk findings immediately to the FAA.
- Lead regression penetration testing to validate that previously identified vulnerabilities have been effectively remediated.
- Manage and maintain penetration testing tools and environments; all tools must be FAA‑approved.
- Attend all Program Management Reviews and report on penetration testing status, findings trends, and upcoming test schedules.
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Mathematics, Physics, or a related technical discipline from an accredited institution.
- Minimum of fifteen (15) years of cybersecurity experience, including at least five (5) years leading or supervising penetration testing teams.
- At least two (2) years of relevant experience performed within the last three (3) years.
- Demonstrated experience planning, executing, and documenting penetration testing engagements in complex, multi‑system environments.
- Expert‑level proficiency with penetration testing tools such as Metasploit, Burp Suite, Nmap, and related frameworks.
- Ability to conduct manual testing beyond automated tool output.
- Deep understanding of NIST SP 800‑115, PTES, OWASP, and industry‑standard penetration testing methodologies.
- Experience developing and operating within formal Rules of Engagement (ROE) for penetration testing.
- Experience with red team / blue team exercises, including scenario development, execution, and after‑action reporting.
- Understanding of network exploitation across multi‑vendor environments, including wireless, routing (Layer
3), switching (Layer
2), firewalls, IDS/IPS, and cloud services. - Candidate must have the ability to obtain and maintain a Public Trust; an active Secret clearance is preferred.
Demonstrates expert‑level proficiency in penetration testing, including planning, executing, and documenting complex engagements. Capable of leading teams in high‑complexity environments while ensuring compliance with established methodologies and reporting standards.
#J-18808-LjbffrTo View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×