View all jobs

Senior Penetration Tester

  • Hybrid Washington DC, Maryland

ClearFocus Technologies, a HUBZone certified company, is located in Leesburg, VA. We specialize in cybersecurity and support multiple government and commercial clients for a variety of missions. We value our clients, integrity and employees and believe a single person can make a difference!  
We are seeking a Senior Penetration Tester for a Part-time opportunity. This opportunity requires travel to throughout the DMV area.

The Senior Penetration Tester serves as a technical lead supporting the Department of Health and Human Services (HHS) Office of Inspector General (OIG) Cyber Assessment Team. This position performs advanced penetration testing, vulnerability assessments, security research, exploitation activities, and technical consulting across federal systems, applications, cloud environments, and networks. The individual will lead testing engagements, provide expert recommendations to auditors and stakeholders, develop detailed technical reports, and assist with cybersecurity training initiatives.
Key Responsibilities:
  • Lead penetration testing engagements for web applications, external and internal networks, cloud environments, mobile applications, wireless networks, containers, and emerging technologies.
  • Conduct reconnaissance, enumeration, vulnerability analysis, exploitation, privilege escalation, persistence, and post-exploitation activities.
  • Develop and review Rules of Engagement (RoE) documentation and participate in planning meetings, entrance conferences, and results briefings.
  • Analyze vulnerability scan results and correlate findings from multiple tools to validate security weaknesses and eliminate false positives.
  • Provide expert technical consulting and security guidance to federal auditors and assessment teams.
  • Develop attack confirmation documentation, evidence collection packages, and technical recommendations for remediation.
  • Author formal penetration testing reports, conclusions memoranda, executive summaries, and technical findings.
  • Present complex technical findings to senior executives, IT management, and technical staff.
  • Participate in the design and delivery of hands-on cybersecurity training and live demonstrations.
  • Mentor junior penetration testers and review technical deliverables for quality and accuracy.
Required Qualifications
  • 7+ years of hands-on penetration testing, red team, or offensive security experience.
  • Experience conducting federal, healthcare, or regulated-industry security assessments.
  • Ability to obtain and maintain a Tier 4 High Risk Public Trust clearance
Strong knowledge of:
  • Web application security
  • Active Directory security
  • Cloud security (AWS, Azure, GCP)
  • Network and wireless security
  • Mobile application testing
  • Social engineering methodologies
  • NIST SP 800-115 and cybersecurity assessment frameworks
  • Ability to communicate highly technical information to non-technical audiences.
  • Ability to obtain and maintain a Public Trust