GovCIO LLC seeks a Senior Penetration Tester to lead advanced offensive security assessments for federal customers. You will plan and execute web, network, API, cloud, and mobile penetration tests; perform red teaming, social engineering, and adversary emulation; and deliver clear reports and remediation guidance to stakeholders. You'll collaborate with developers, architects, and security teams to validate fixes, improve secure design, and enhance zero-trust architectures. This role includes mentoring junior testers, refining methodologies, and supporting accreditation and compliance for high-impact government systems.
Responsibilities
- Plan and execute penetration tests on web, network, cloud, and mobile systems for federal clients.
- Conduct red team exercises, social engineering, and adversary emulation to assess resilience.
- Identify, exploit, and document vulnerabilities, providing clear risk and impact analysis.
- Develop and present detailed technical reports and executive summaries with remediation guidance.
- Collaborate with engineering and security teams to validate fixes and improve secure design.
- Support federal compliance initiatives (e.g., NIST, Fed
- RAMP) with security testing evidence.
- Mentor and guide junior penetration testers, sharing best practices and methodologies.
- Continuously refine tools, scripts, and testing methodologies to improve assessment quality.
Required Skills
- Penetration testing
- Web application security
- Network security assessment
- Cloud security (AWS/Azure/GCP)
- Red teaming/adversary emulation
- Social engineering
- Secure coding and remediation guidance
- Vulnerability assessment and prioritization
- Scripting (Python/Bash/Power
- Shell)
- Security reporting and documentation