Penetration Tester

Alexandria, VA


Apply Save

Type: Contract-to-Hire

Category: Security

Industry: Government

Reference ID: JN -082026-108252

Date Posted: 08/11/2026

Shortcut: http://careers.eliassen.com/nj7HXN


Description:

Hybrid 2-3 days per week on-site in Alexandria, VA. The first 30 days of work will be full-time on-site. in Alexandria, VA

 

Our client seeks an experienced penetration testing professional to plan and execute comprehensive security assessments across applications, systems, and infrastructure in alignment with federal standards and industry best practices. The role will coordinate assessment scoping, develop and maintain testing procedures, conduct multi-team exercises, and produce clear reporting with prioritized remediation guidance to strengthen defensive posture and SOC effectiveness.

 

Due to federal security clearance requirements, applicant must be a United States Citizen. This is a contract to hire opportunity. Applicants must be willing and able to work on a w2 basis and convert to FTE following contract duration. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance.

 

Rate: $75.00 to $85.00/hr. w2


Responsibilities:
  • Coordinate and conduct Agency penetration testing on systems operated by and on behalf of NCUA, ensuring access occurs only through specified authentication methods and is limited to vetted personnel.
  • Develop, maintain, and update the Penetration Testing CONOPS and SOPs aligned to NIST guidance, applicable Federal regulations, and industry best practices.
  • Coordinate prior to each assessment to determine the appropriate assessment model and identify the technology to be tested.
  • Draft Rules of Engagement and test-specific penetration testing documentation for each engagement.
  • Perform testing and detection activities including red teaming, blue teaming, penetration testing, adversary emulation, purple teaming, and breach and attack simulation to improve SOC operations and defensive posture.
  • Document findings and vulnerabilities with risk categorization, impact evaluation, and prioritized remediation, and provide regular status updates to stakeholders.
  • Simulate APT scenarios by emulating adversary TTPs to evaluate system resilience and inform enhanced protective measures.
  • Conduct red and blue team exercises with post-exercise reviews highlighting detections and areas for improvement.
  • Execute the full assessment lifecycle including onboarding, active assessment, findings development, triage, detailed reporting, and patch validation.
  • Draft and publish reports for each penetration test including results, findings, and proposed remediation.
  • Maintain tracking of penetration testing activities across engagements.
  • Integrate penetration testing with vulnerability assessments, threat modeling, event detection evaluation, continuous monitoring tool verification, incident response, and incident reporting compliance.

Experience Requirements:
  • US Citizenship required.
  • Minimum of 5 years of experience conducting, supporting, or leading penetration tests across enterprise environments.
  • Strong understanding of Windows and Linux/Unix operating systems and core networking protocols such as TCP/IP, DNS, HTTP/S, and SMB.
  • Ability to identify, validate, and exploit vulnerabilities across networks, systems, and applications.
  • Working knowledge of web technologies and common vulnerability classes including the OWASP Top 10.
  • Proficiency with tools such as Burp Suite, Metasploit, Nmap, Nessus, and Cobalt Strike or equivalents.
  • Scripting or automation ability in Python, Bash, or PowerShell.
  • Experience performing reconnaissance, vulnerability identification, exploitation, and post-exploitation per approved rules of engagement.
  • Capability to develop and deliver findings reports that translate technical issues into business risk with prioritized remediation.
  • Strong written communication skills for clear, organized findings reports for technical and non-technical stakeholders.
  • Strong verbal communication skills to brief findings, risk ratings, and recommendations to leads, system owners, or client stakeholders.
  • Problem-solving skills and ability to work independently or as part of a team under defined timelines.
  • Sound judgment and professionalism when operating within sensitive or production environments.
  • Desirable: Experience in regulated or federal environments aligned with NIST SP 800-53, SP 800-115, and RMF processes.
  • Desirable: Familiarity with wireless and social engineering testing methodologies.
  • Clearance: Ability to obtain and maintain a Public Trust.

Education Requirements:
  • Bachelor of Science in Computer Science, Information Technology, Information Security, Cybersecurity, or related field.
  • Must hold one or more certifications: OSCP, CEH, GPEN, GWAPT, PenTest+, or eCPPT.

Recruitment Transparency Notice
 
Eliassen Group values transparency in our recruitment practices. Please be advised that Eliassen Group utilizes artificial intelligence (AI) tools as part of its initial application screening and hiring process. You may receive email and SMS notifications from the Eliassen Virtual Recruiting Team (noreply@eliassen.com, 781-808-2924) inviting you to complete a brief voice screening as part of your application process. These tools assist our hiring teams in different ways, including but not limited to, assistance in reviewing application materials to help identify candidates whose qualifications most closely match the requirements of the position. All AI-assisted evaluations and responses are reviewed by human recruiters before any hiring decisions are made. The use of AI in our process is intended to support fairness, efficiency, and consistency, and Eliassen Group takes measures to prevent bias or discrimination in connection with its hiring practices. By proceeding, you acknowledge, agree, and consent to Eliassen Group’s use of these tools, including AI tools, as part of the application and hiring process.
 

Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range.

W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality.
If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following:

· When you work with Eliassen Group, all email communication will come from an Eliassen.com address, never Gmail, Yahoo, etc.

· Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group.

If you have any indication of fraudulent activity, please contact fraud@eliassen.com.

 
About Eliassen Group:
 
Eliassen Group is a strategic consulting firm that helps organizations reach further and achieve more through our technology, business advisory, and life sciences solutions. For nearly 40 years, we have combined exceptional people, deep domain expertise, and intelligent capabilities to expand our clients’ capacity and accelerate meaningful outcomes. We are driven by a purpose to positively impact the lives of our employees, clients, consultants, and the communities we serve.
 
Eliassen is committed to building a diverse and inclusive team from a variety of backgrounds, perspectives, and skills. We are an Equal Opportunity and Affirmative Action Employer and all employment decisions are based on merit, performance, and business needs. Eliassen does not discriminate on the basis of race, color, gender identity or expression, sexual preference or orientation, sex (including pregnancy, childbirth, and related medical conditions), marital status, creed, religion, physical or mental disability, genetic information, military or veteran status, age, ancestry, national origin, citizenship status, prohibited criminal record inquiries of applicants and employees, or any other category protected by federal, state, or local laws.
 
Don’t miss out on our referral program! If we hire a candidate that you refer us to then you can be eligible for a $1,000 referral check!
 

  • Cybersecurity Incident Response Lead

    Alexandria, VA

    Description: Hybrid, 2-3 days per week on-site in Alexandria, VA. The first 30 days of work will be full-time on-site. in Alexandria, VA Our client seeks a seasoned leader to direct enterprise cybersecurity incident response and offensive security init...

    Date Posted: 08/10/2026 Recommended

  • Cybersecurity Audit Manager

    Alexandria, VA

    Description: Hybrid 2-3 days per week on-site in Alexandria, VA. The first 30 days of work will be full-time on-site. in Alexandria, VA Our client seeks a cybersecurity audit management professional to drive compliance with federal regulations and info...

    Date Posted: 08/10/2026 Recommended

  • Project Manager

    Cleveland, OH

    Description: On-site 5 days/week in Cleveland, OH Our client seeks an experienced Project Manager to lead a high-priority Oracle security remediation initiative addressing audit findings and control exceptions. The PM will coordinate SMEs across Oracle...

    Date Posted: 07/30/2026 Recommended

  • Information Technology Risk & Controls Audit Manager

    San Francisco, CA

    Description: Hybrid in San Francisco, CA Our client is seeking an experienced IT Risk & Controls Audit Manager to lead audit, risk, and compliance initiatives within a dynamic environment. The role will evaluate technology and business controls, manage...

    Date Posted: 07/29/2026 Recommended

  • Quality Manual Test Lead

    Englewood, CO

    Description: Hybrid 4 days on site in Englewood, CO Our client is seeking a Quality Manual Test Lead to oversee a manual testing team focused on front-end web and mobile applications in production. The role includes test planning, case design, executio...

    Date Posted: 07/20/2026 Recommended

  • Design Thinking Strategist IV

    Charlotte, NC

    Description: Hybrid standard in Charlotte, NC Our client seeks a Design Thinking Strategist IV to lead discovery, research, and strategy that inform innovative products and services. The role will frame opportunities, structure and run research, plan a...

    Date Posted: 07/30/2026 Recommended

  • eTMF Specialist, Pharma, BiAnnual Review Project

    Anywhere

    Description: Remote Our client is seeking an eTMF Specialist to support a biannual review of Phase III Trial Master Files. The specialist will ensure TMFs are complete, accurate, compliant, and inspection-ready through comprehensive quality review and ...

    Date Posted: 08/06/2026 Recommended

  • SailPoint Senior Systems Engineer

    Washington, DC

    Description: On-site in Washington, DC Our client seeks a SailPoint Senior Systems Engineer to enhance cybersecurity and identity management capabilities. The role will coordinate with external stakeholders, including DHS CISA integrators, to implement...

    Date Posted: 08/04/2026 Recommended

  • Lead Agilist

    Cincinnati, OH

    Description: Hybrid 3-4 days on site in Cincinnati, OH Our client seeks a Lead Agilist to coach and enable Agile Squads to deliver business value using Scrum and complementary Agile practices. The Lead Agilist will facilitate Scrum events, foster a tru...

    Date Posted: 08/12/2026 Recommended

  • Compliance Project Manager

    Anywhere

    Description: Remote Our client seeks a Compliance Project Manager to provide end-to-end project management supporting Regulatory Compliance. The role facilitates, supports, tracks, and reports on initiatives to ensure execution of laws and regulations,...

    Date Posted: 07/29/2026 Recommended

  • Full Stack Engineer

    Westlake, TX

    Description: Hybrid Every Other Week onsite / 5 days in Westlake, TX Our client is seeking a Full Stack Engineer to build and support real-time APIs using Oracle SOA 12c, open-source technologies, or OCS. The role includes shell scripting with cron and...

    Date Posted: 08/12/2026 Recommended

  • Senior Exchange Administrator

    Quantico, VA

    Description: On-site in Quantico, VA Our client seeks a Senior Exchange Administrator to support a large-scale hybrid Microsoft Exchange 2019 and Microsoft 365 environment serving over 260,000 users across classified and unclassified networks. The role...

    Date Posted: 08/04/2026 Recommended

  • Senior Full Stack React.js / Node.js Developer

    Greenwood Village, CO

    Description: On-site in Greenwood Village, CO Our client seeks a Senior Full Stack React.js / Node.js Developer for a long-term contract on the internal build and tools team. You will contribute core features across multiple web applications that serve...

    Date Posted: 07/16/2026 Recommended

  • Software Test Engineer

    San Diego, CA

    Description: Hybrid in San Diego, CA Our client seeks a Software Test Engineer to lead and execute advanced software testing for web applications and instrument systems with a focus on C# and TypeScript solutions. The role includes designing and implem...

    Date Posted: 08/10/2026 Recommended

  • P2 Application Support Engineer

    Austin, TX

    Description: Hybrid Monday - Thursday. Friday is remote in Austin, TX Our client seeks a P2 Application Support Engineer to join a second-level support team responsible for stability, reliability, and performance of a financial technology platform supp...

    Date Posted: 08/02/2026 Recommended

  • SAP IS-U FICA Functional Consultant

    Anywhere

    Description: Remote Our client seeks an SAP IS-U FICA Functional Consultant to provide production support, testing, and minor enhancements across Contract Accounts Receivable and Payable. The consultant will triage incidents, perform root cause analysi...

    Date Posted: 08/13/2026 Recommended

  • Kyriba Consultant

    Anywhere

    Description:Remote Our client seeks a Kyriba consultant to complete implementation, optimize configuration, and integrate Kyriba with NetSuite. The consultant will assess current-state deployment, stabilize core treasury workflows, and design a scalabl...

    Date Posted: 07/30/2026 Recommended

  • Data Scientist-AI – GTM/Propensity to Buy Modeling.

    Anywhere

    Description: Remote Our client seeks a Data Scientist to operationalize lead scoring and propensity-to-buy models that inform go-to-market strategy. You will partner with GTM, Marketing, and Customer Success to translate product usage and behavioral si...

    Date Posted: 08/13/2026 Recommended

  • Lead Software Engineer

    Chicago, IL

    Description: Hybrid At least 2 days per week in office in Chicago, IL Our client seeks a Lead Software Engineer to drive the design, delivery, and technical strategy for cloud-native data platforms within a Customer Data Platform team. The role will de...

    Date Posted: 08/10/2026 Recommended

  • Lead Software Engineer

    Boston, MA

    Description: Hybrid at least 2 days per week in office in Wakefield, MA Our client seeks a Lead Software Engineer for the CDP team to drive design, delivery, technical strategy, and execution for critical data systems. You will define engineering stand...

    Date Posted: 08/10/2026 Recommended

  • Senior Software Developer

    St. Louis, MO

    Description: Hybrid 2-3 days on-site in St. Louis, MO Our client seeks a Senior Software Developer to support modernization and maintenance of a mission-critical enterprise application in AWS for the U.S. Treasury. The role requires full-stack developm...

    Date Posted: 07/31/2026 Recommended

  • Lead Software Engineer

    Irving, TX

    Description: Hybrid At least 2 days per week in office in Irving, TX Our client seeks a Lead Software Engineer to drive design, delivery, and technical strategy for cloud-native data platforms that power data-driven, omnichannel experiences. You will l...

    Date Posted: 08/10/2026 Recommended

  • Business Analyst

    Anywhere

    Description: Remote Our client seeks a Business Analyst to support a NexGen / Guidewire program. The role focuses on two parallel tracks. First, it supports Release 1 SIT/UAT by creating and executing test cases, triaging defects, and tracing issues to...

    Date Posted: 08/09/2026 Recommended

  • Mid Systems Engineer, CyberArk

    Washington, DC

    Description: Onsite in Washington, DC Our client seeks a Mid Systems Engineer, CyberArk, to support a Privileged Access Management program for a federal environment. The role will assist senior engineers with CyberArk deployment, operations, reporting,...

    Date Posted: 08/10/2026 Recommended

  • Sr Software Engineer

    Greenwood Village, CO

    Description: Hybrid 4 onsite / 1 work from home in Greenwood Village, CO Data driven decision-making is a core tenant of our client, a Fortune 500 telecommunications provider. This agentic AI development team enables this process and oversees an intern...

    Date Posted: 07/29/2026 Recommended

  • Technical Coach

    Fort Worth, TX

    Description: Hybrid 3 to 4 days a week in Fort Worth, TX Our client seeks a Technical Coach to raise engineering discipline and improve delivery flow. You will coach in the work by pairing in code, shaping team routines, and making improvements measura...

    Date Posted: 08/06/2026 Recommended

  • Quality Engineer

    Merrimack, NH

    Description: On-site Every Other Week onsite / 5 days in Merrimack, NH Our client seeks a Quality Engineer to support a SaaS and cloud-first Workday Integration Team within Corporate Technology. The role focuses on testing web applications and REST API...

    Date Posted: 07/21/2026 Recommended

  • Senior Oracle Fusion GL Security & Technical Consultant

    Dallas, TX

    Description: On-site in Dallas, TX Our client seeks a hands-on senior Oracle Fusion GL Security and Technical Consultant to stabilize the Oracle security model, correct role and user-assignment issues, resolve production and hypercare tickets, and help...

    Date Posted: 08/06/2026 Recommended

  • Senior Software Engineer

    Chicago, IL

    Description: Hybrid At least 2 days per week in office in Chicago, IL Our client seeks a Senior Software Engineer for the CDP team to drive design, delivery, technical strategy, and execution for cloud-native data platforms. You will define engineering...

    Date Posted: 08/14/2026 Recommended

  • Lead Agilist

    Farmington Hills, MI

    Description: On-site in Farmington Hills, MI Our client seeks a Lead Agilist to support an Agentic AI engineering team. The role will coach and facilitate Agile Squad practices, foster servant leadership, and partner with Product Owners and developers ...

    Date Posted: 07/31/2026 Recommended

Eliassen Group is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status. Eliassen Group’s Affirmative Action Plan (AAP) is available for inspection by any employee or applicant for employment upon request, during normal business hours of Monday through Friday, 8:30am to 5:30pm EST. Interested persons should contact Phaedra Wells at pwells@eliassen.com for assistance. It is unlawful in Massachusetts and Maryland to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Applicants with disabilities that believe they require an accommodation or assistance with a position, please email our HR team at hradmin@eliassen.com. This email inbox is designed exclusively to assist job seekers whose disability prevents them from being able to apply online. Emails sent for other purposes will not receive a response.


Please be advised that a number of fraudulent job postings have been released under the Eliassen Group brand.

Unfortunately, fraudulent job postings can happen. If anyone reaches out to you about an open position connected with Eliassen Group, never provide personal or financial information to anyone who is not clearly associated with Eliassen Group

If anyone seemingly from Eliassen Group has ever requested this personal information in the past or does so in the future, please contact fraud@eliassen.com.

Please ensure that you are working directly with us by confirming the following:

  • When you work with Eliassen Group, all email communication will come from an Eliassen.com address, never Gmail, Yahoo, etc.
  • Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group, as indicated above