Penetration Tester Analyst

Posted 8 Days Ago
Be an Early Applicant
Hiring Remotely in GBR
Remote
Mid level
Artificial Intelligence • Machine Learning • Analytics
The Role
Supports authorized penetration testing for a federal agency through assessment planning, reconnaissance, enumeration, evidence collection, findings documentation, remediation recommendations, retesting, and reporting. The role also assists with triaging external-facing asset findings, CISA WAS/FAST results, KEV exposures, and VDP submissions. Responsibilities include maintaining schedules and scope records, coordinating stakeholders, tracking actions, and using automation and AI-enabled tools to improve testing and reporting workflows.
Summary Generated by Built In
Description

Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.

Dragonfli Group is seeking a Pen Testing Analyst to join a growing Penetration Testing workstream supporting a large federal agency. In this fully remote role, you will provide analytical and hands-on support for authorized penetration testing activities, including test preparation, reconnaissance, evidence collection, documentation, and reporting for rapid validation efforts. You will help maintain test schedules and scope records, support controlled discovery and enumeration within approved authorization boundaries, and document findings and remediation recommendations for inclusion in final assessment reports. You will also assist with triage of external-facing asset findings, CISA WAS and FAST results, KEV exposure items, and Vulnerability Disclosure Program (VDP) submissions, and will use approved automation and AI-enabled tools to improve data collection, correlation, and reporting workflows. This role is well suited to a candidate with approximately 2 to 4 years of relevant experience in penetration testing, vulnerability assessment, or a closely related cybersecurity discipline.

This is a multi-year contract position involving a large US federal agency. Candidates with previous federal contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.

This is a fully remote position.

Key Responsibilities:

  • Support assessment planning by maintaining test schedules, scope records, stakeholder coordination notes, and required pre-assessment documentation.
  • Assist with controlled discovery, enumeration, testing support, and evidence capture within approved authorization boundaries.
  • Document findings, affected assets, ownership, reproducibility details, remediation recommendations, and retest requirements for inclusion in final reports.
  • Support validation and triage of external-facing asset findings, CISA WAS and FAST results, KEV exposure items, and VDP submissions.
  • Coordinate daily status inputs, meeting notes, action tracking, and after-action support for assigned testing activities.
  • Use approved automation and AI-enabled tools to improve data collection, initial correlation, draft reporting, and testing workflow efficiency.
Requirements

Must-Have

  • U.S. Citizenship or Permanent Residency (required for this federal engagement)
  • Approximately 2 to 4 years of experience in penetration testing, vulnerability assessment, or a related offensive/defensive cybersecurity role
  • Working knowledge of common penetration testing methodologies and tools (e.g., Burp Suite, Nmap, Metasploit, or equivalents)
  • Familiarity with reconnaissance, enumeration, and evidence collection within authorized testing boundaries
  • Strong written documentation skills for findings, reproducibility steps, and remediation recommendations
  • Ability to work fully remote with reliable, secure connectivity

Preferred / Nice-to-Have

  • Previous federal contracting experience
  • Exposure to CISA Web Application Scanning (WAS) and Fast Attack Surface Testing (FAST) programs
  • Familiarity with Known Exploited Vulnerabilities (KEV) catalog and Vulnerability Disclosure Program (VDP) triage
  • Relevant certifications such as Security+, CEH, GPEN, or OSCP (or actively pursuing)
  • Experience using AI-enabled or automation tools to support testing and reporting workflows
Skill(s)

Technical Skills

  • Penetration testing fundamentals and common toolsets
  • Vulnerability scanning, enumeration, and evidence capture
  • Report writing and findings documentation
  • Familiarity with CISA WAS/FAST, KEV, and VDP processes
  • Comfort with automation and AI-enabled testing support tools

Soft Skills

  • Strong written and verbal communication
  • Attention to detail and thorough documentation habits
  • Ability to work independently in a remote, distributed team
  • Collaborative coordination with stakeholders and testing leads
  • Time management across concurrent assessment activities
Benefits
  • Dragonfli Group offers a comprehensive benefits package that includes:
  • Medical, Multiple POS health plan options including an HSA-compatible plan
  • Dental, PPO coverage for preventive, basic, and major services
  • Vision, Annual exam, frames, lenses, and contact lens allowance
  • 401(k), Employer match up to 5% of eligible compensation
  • Long-Term Disability, 100% employer-paid coverage at 50% of pre-disability earnings
  • Life Insurance and AD&D, 100% employer-paid coverage valued at $10,000 each
  • PTO, 15 to 25 days annually based on tenure
  • Paid Federal Holidays, All 11 federal holidays observed

Skills Required

  • U.S. Citizenship or Permanent Residency
  • Approximately 2 to 4 years of experience in penetration testing, vulnerability assessment, or a related cybersecurity role
  • Working knowledge of penetration testing methodologies and tools such as Burp Suite, Nmap, Metasploit, or equivalents
  • Familiarity with reconnaissance, enumeration, and evidence collection within authorized testing boundaries
  • Strong written documentation skills for findings, reproducibility steps, and remediation recommendations
  • Ability to work fully remotely with reliable, secure connectivity
  • Previous federal contracting experience
  • Exposure to CISA Web Application Scanning and Fast Attack Surface Testing programs
  • Familiarity with the Known Exploited Vulnerabilities catalog and Vulnerability Disclosure Program triage
  • Security+, CEH, GPEN, or OSCP certification, or active pursuit of one
  • Experience using AI-enabled or automation tools for testing and reporting workflows
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: London
35 Employees
Year Founded: 2018

What We Do

Dragonfly AI uses a biologically driven AI to predict attention on visual assets. Across all channels and environments, the platform can be integrated with workflows to validate decision-making with data for creative that has a higher impact and performs better. Particularly relevant for CPG and FMCG brands but can be integrated with any creative process for a new layer of data insights to support teams in optimizing creative specifically for attention

Similar Jobs

SailPoint Logo SailPoint

Forward Deployed Engineer

Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Remote or Hybrid
United Kingdom
2461 Employees
106K-179K Annually

Tapestry - Coach and Kate Spade Logo Tapestry - Coach and Kate Spade

Sales Associate

eCommerce • Fashion • Retail • Sales • Wearables • Design
Remote or Hybrid
Wirral, England, GBR
16000 Employees
26K-28K Annually

Skillsoft Logo Skillsoft

EMEA Market Solutions Director

Artificial Intelligence • Consumer Web • Edtech • HR Tech • Information Technology • Software • Conversational AI
Remote
United Kingdom
2900 Employees

LogicMonitor Logo LogicMonitor

Customer Success Manager

Artificial Intelligence • Cloud • Information Technology • Machine Learning • Software
Easy Apply
Remote or Hybrid
London, Greater London, England, GBR
1100 Employees

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account