Hiring.Camp

Penetration Tester

Gunnison Consulting Group, Inc.

·

Today

Salary
$150k – $170k/yr
Location
Alexandria, VA
Workplace
Hybrid, Onsite
Experience
5+ years
Education
Bachelor
Visa
Not sponsored
Source
Paylocity

Description

Description

* This position is contingent upon a future opening with Gunnison.


Salary: $150,000 - $170,000/year


Work location: Hybrid, 2-3 days per week on-site in Alexandria, VA. The first 30 days of work will be full-time on-site.

  • Coordinate and conduct all Agency penetration testing on systems operated by and on behalf of NCUA, ensuring access to NCUA applications and infrastructure occurs only through NCUA-specified authentication methods and is limited to vetted personnel
  • Develop, maintain, and update the Penetration Testing Concept of Operations (CONOPS) and Standard Operating Procedures (SOPs) in accordance with NIST guidance, applicable Federal regulations, and industry best practices
  • Coordinate with NCUA prior to each assessment to determine the appropriate assessment model and identify the underlying technology to be tested
  • Draft Rules of Engagement and test-specific penetration testing documentation for each engagement
  • Perform a range of testing and detection activities — including red teaming, blue teaming, penetration testing, adversary emulation, purple teaming, and breach and attack simulation — to improve SOC operations and strengthen the Agency's overall defensive posture
  • Meticulously document all findings and vulnerabilities identified during testing, including categorizing risk, evaluating potential impact, and prioritizing remediation based on severity; provide regular status updates to stakeholders to ensure transparency and timely action
  • Simulate advanced persistent threat (APT) scenarios by emulating sophisticated adversary tactics, techniques, and procedures (TTPs) to evaluate system resilience, identify gaps in security posture, and inform enhanced protective measures
  • Conduct red and blue team exercises in which the red team simulates attacks and the blue team detects and responds in real time; produce post-exercise reviews highlighting successful detections and areas for improvement
  • Execute the full assessment lifecycle, including onboarding, active assessment of the target, findings development, triage, detailed reporting, and patch validation
  • Draft and publish a report for each penetration test, including results, findings, and proposed remediation efforts where applicable
  • Maintain overall tracking of penetration testing activities across engagements
  • Integrate penetration testing with related security efforts, including vulnerability assessments, threat modeling, event detection evaluation, continuous monitoring tool verification, incident response, and incident reporting compliance


Requirements

  • US Citizenship required
  • Strong understanding of operating systems (Windows, Linux/Unix) and core networking protocols (TCP/IP, DNS, HTTP/S, SMB, etc.) 
  • Demonstrated ability to identify, validate, and exploit vulnerabilities across networks, systems, and applications 
  • Working knowledge of web application technologies and common vulnerability classes (OWASP Top 10: injection flaws, authentication/session weaknesses, access control issues, etc.) 
  • Proficiency with industry-standard penetration testing tools (e.g., Burp Suite, Metasploit, Nmap, Nessus, Cobalt Strike, or equivalent) 
  • Scripting/automation ability in one or more languages (Python, Bash, PowerShell) to develop custom tools or modify existing exploits 
  • Must hold one or more of the following certifications: OSCP, CEH, GPEN, GWAPT, PenTest+, eCPPT. 
  • Bachelor of Science in Computer Science, Information Technology, Information Security, Cybersecurity or related field 

Minimum of 5 years of experience conducting, supporting the conduct of, or leading penetration tests, including:

  • Planning and executing network, application, and infrastructure penetration tests against enterprise environments
  • Performing reconnaissance, vulnerability identification, exploitation, and post-exploitation activities in accordance with an approved rules of engagement
  • Developing and delivering findings reports that translate technical vulnerabilities into business risk and prioritized remediation guidance
  • Strong written communication skills, with demonstrated ability to produce clear, well-organized findings reports for both technical and non-technical stakeholders
  • Strong verbal communication skills to brief findings, risk ratings, and remediation recommendations to leads, system owners, or client stakeholders
  • Strong problem-solving skills and ability to work independently or as part of a team under defined timelines
  • Ability to exercise sound judgment and professionalism when operating within sensitive or production environments 

Desirable Qualifications:

  • Experience supporting or leading engagements in a regulated or federal environment is a plus, particularly experience aligned with NIST SP 800-53, SP 800-115, and Risk Management Framework (RMF) processes
  • Familiarity with wireless and social engineering testing methodologies is a plus 

Clearance Requirement: Ability to obtain and maintain a Public Trust.



The salary range for this position depends upon multiple factors including location, the individual's knowledge, skills, competencies, and experience, and contract-specific budget constraints and organizational requirements.
Gunnison Consulting Group's total compensation package also includes bonus and profit-sharing opportunities, depending on company and employee performance. Available employee benefits include:

  • 3 weeks of Personal Leave your first year
  • 11 paid Holidays each year
  • 5 days of Flexible Time Off each year for approved training or certifications (self-study is ineligible)
  • 401(k) company match at 50% up to 10% of your salary
  • Medical, Dental and Vision Insurance
  • Life and Disability Insurance
  • Public Transportation Subsidies
  • Certifications and Training Allowance - Up to $5,000/year!

Why Join Gunnison?

  • Gunnison takes on ambitious projects. We target fun, challenging work that requires creative thinking and innovation.
  • Quality is our top priority.
  • Gunnison employee benefits meet or exceed what other companies in the Washington, D.C. metropolitan area offer.
  • There is a great sense of camaraderie at Gunnison. This is an atmosphere we will maintain as we continue to grow.
  • We are growing rapidly and the opportunity for individual professional growth with Gunnison is outstanding.
  • We hire for careers at Gunnison, not to fill a position.

Equal Opportunity/Affirmative Action Employer. Must be eligible for employment in the United States. We are unable to sponsor candidates at this time.
In 1994 Gunnison began serving the greater Washington, D.C. metro area, focused on tackling our customers' most ambitious technology projects. By creating a culture dedicated to enabling our customers and employees to achieve more than they ever thought they could, the company has thrived for over 25 years.

Skills

PythonLinuxCybersecurityPenetration TestingSOCTCP/IPRisk ManagementCompliance

Similar Jobs

30

Penetration Tester

RSM · SLV-San Salvador-Calle Cortez Blanco #8 Urb. Madreselva, El Salvador

4 days ago

Penetration Tester

Bytes Software Services · Randalls Way, Leatherhead KT22 7TW, UK

5 days ago

Penetration Tester

Guidepointsecurity · Alexandria, VA · Onsite

5 days ago

Penetration Tester

Workstreet · Philippines

1 week ago

Penetration Tester

In Jaggaer · Hyderabad, IN

1 week ago

Penetration Tester

Northrop Grumman · TXSA03, United States of America · Remote, Hybrid

1 week ago

Penetration Tester

Northrop Grumman · San Antonio, TX,US, US · Remote, Hybrid

1 week ago

Penetration Tester

Spectris · Frascati, IT, Italy

2 weeks ago

Penetration Tester

Fortreum · Remote · Remote

2 weeks ago

Penetration Tester

ASRC Federal · Quantico, VA 22134, USA

3 weeks ago

Penetration Tester

Gresearch · London, United Kingdom

3 weeks ago

Penetration Tester

Kyndryl · Budapest (HUBUONE) BUDAONE, Hungary · Remote

1 month ago

Penetration Tester

Professional Kyndryl · Budapest (HUBUONE) BUDAONE, Hungary · Remote

1 month ago

Penetration Tester

ISA Cybersecurity · Toronto, Ontario, Canada

1 month ago

Penetration Tester

BDO · Brisbane, Australia

1 month ago

Penetration Tester

Booz Allen Hamilton · USA, MD, Fort Meade (6910 Cooper Ave), United States of America

1 month ago

Penetration Tester

Align · United States - Remote · Remote

1 month ago

Penetration Tester

Nngroup · Digital Hub Prague, Czechia · Hybrid

1 month ago

Penetration Tester

Nttlimited · hyderabad, India · Hybrid

2 months ago

Penetration Tester

Darkwolfsolutions · Washington DC Metro Area +1 · Hybrid

2 months ago

Penetration Tester

Align · London, United Kingdom – In-Office Hybrid · Hybrid, Onsite

3 months ago

Penetration Tester

Manulife and John Hancock Careers · Manila, Manulife Business Processing Services, Philippines · Hybrid

3 months ago

Penetration Tester

EMNTSolutions · Remote

3 months ago

Penetration Tester

Djamo · Abidjan, CI · Remote, Onsite

3 months ago

Penetration Tester

Packetlabs · Melbourne, Australia

3 months ago

Penetration Tester

Akamai · Poland, PL · Remote

3 months ago

Penetration Tester

Accenture Federal Services · Washington, DC +1 · Hybrid

4 months ago

Penetration Tester

Peraton · Arlington, VA, US · Hybrid, Onsite

5 months ago

Penetration Tester

Caci · BYS CHANTILLY VA, United States of America · Onsite

5 months ago

Penetration Tester

OSec · New York, NY · Remote

6 months ago