Penetration Tester

Posted 2 Days Ago
Be an Early Applicant
Alexandria, VA, USA
In-Office
108K-195K Annually
Senior level
Information Technology • Software
The Role
Conduct authorized penetration testing and threat hunting across government networks, systems, applications, web applications, and code. Develop assessment plans and rules of engagement, identify exploitable weaknesses, validate cybersecurity detections, support Red and Blue Team activities, document findings, and provide remediation recommendations. Coordinate with system owners, SOC analysts, incident responders, and government stakeholders while protecting sensitive assessment data.
Summary Generated by Built In

Looking for an opportunity to make an impact?


At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers’ success. We empower our teams, contribute to our communities, and operate sustainable. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community. Our Mission, Vision, and Values guide the way we do business.


If this sounds like a mission you want to be a part of, keep reading!


Leidos is seeking experienced Penetration Testers to support the Defense Manpower Data Center (DMDC) CyberPRIMES program. Leidos is a major partner on the contract and will provide a substantial portion of the cybersecurity workforce supporting the Defense Human Resources Activity (DHRA) and DMDC. The Penetration Tester will conduct Government-directed penetration testing and threat-hunting assessments across DHRA systems, networks, applications, and supporting technologies. This position will identify exploitable weaknesses, validate the effectiveness of defensive cybersecurity capabilities, and provide actionable findings that help system owners and cybersecurity teams reduce risk.

Work Location: Mark Center, Alexandria, Virginia


Mission Environment

  • DMDC supports the Defense Human Resources Activity within the Office of the Under Secretary of Defense for Personnel and Readiness (OUSD(P&R)) and maintains the Department of Defense’s largest and most comprehensive central repository of personnel, manpower, casualty, pay, entitlement, personnel security, identity, readiness, training, and related data.
  • The DHRA Information Technology (IT) environment includes approximately 15,000 network and endpoint devices supporting more than 600 Government-Off-The-Shelf (GOTS) applications and approximately 100 Risk Management Framework (RMF) authorization boundaries managed through the Enterprise Mission Assurance Support Service (eMASS).
  • The penetration-testing team conducts Government-selected assessments of DHRA programs and also performs ad hoc testing with cybersecurity-tool administrators and Security Operations Center personnel to determine whether defensive capabilities are detecting and alerting as intended. Testing may span enterprise networks, web applications, applications, code, and other mission systems.
  • Primary Responsibilities
  • Conduct Government-selected penetration-testing assessments and threat-hunting activities in accordance with established DMDC procedures and the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-115.
  • Develop assessment plans, methodologies, test objectives, rules of engagement, and technical approaches appropriate to the target environment.
  • Execute authorized penetration-testing activities against networks, systems, applications, web applications, and code.
  • Identify vulnerabilities, exploitable configurations, attack paths, and weaknesses that could be used by a malicious actor.
  • Assess the practical exploitability and potential mission impact of identified security weaknesses.
  • Research emerging and existing threats, attack techniques, vulnerabilities, and adversary behaviors that may affect DHRA systems.
  • Develop testing methodologies designed to identify areas of risk likely to be targeted by an intruder.
  • Conduct threat-hunting activities to identify suspicious or malicious activity that may not be detected through routine monitoring.
  • Perform cooperative testing with cybersecurity-tool administrators, Security Operations Center (SOC) analysts, incident-response personnel, and Security Information and Event Management (SIEM) content developers.
  • Validate whether enterprise cybersecurity tools properly detect, generate alerts for, and support analysis of authorized offensive activity.
  • Identify detection or alerting gaps discovered during testing and provide technical findings to the appropriate cybersecurity teams.
  • Support pre-audit penetration testing to identify exploitable weaknesses before formal assessments or reviews.
  • Apply established penetration-testing methodologies and approved commercial or open-source offensive-security tools.
  • Support Red Team and Blue Team activities designed to evaluate and improve enterprise cybersecurity defenses.
  • Document testing activities, technical evidence, vulnerabilities, exploitation results, and risk findings.
  • Develop post-assessment out-briefs and final assessment reports for Government stakeholders.
  • Provide technically actionable remediation recommendations based on assessment findings.
  • Coordinate findings with system owners, application teams, network engineers, cybersecurity personnel, SOC analysts, and incident responders.
  • Maintain Government-Furnished Equipment and approved penetration-testing systems, laptops, software, and tools required to perform assessments.
  • Protect assessment data, technical artifacts, credentials, exploit information, and other sensitive testing information in accordance with Government requirements.

​

Basic Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical discipline and 8+ years of prior relevant experience. In lieu of degree, additional experience may be required.
  • Experience conducting penetration testing, vulnerability assessment, threat hunting, offensive security, or comparable cybersecurity assessment activities.
  • Experience assessing enterprise networks, systems, applications, web applications, or code for exploitable cybersecurity weaknesses.
  • Experience using commercial or open-source penetration-testing and offensive-security tools.
  • Understanding of common attack techniques, exploitation methods, network protocols, operating systems, and application-security concepts.
  • Experience developing penetration-testing methodologies, test plans, or technical assessment procedures.
  • Experience documenting vulnerabilities, technical evidence, exploitation results, and remediation recommendations.
  • Ability to distinguish theoretical vulnerabilities from weaknesses that present practical exploitation or mission risk.
  • Ability to communicate technical findings clearly to system owners, engineers, cybersecurity personnel, and Government stakeholders.
  • Ability to conduct authorized offensive-security activities within defined rules of engagement and Government-approved procedures.
  • U.S. Citizenship required.
  • Active Secret security clearance required.

Preferred Qualifications

  • Experience conducting penetration testing within Department of Defense or Federal environments.
  • Experience applying National Institute of Standards and Technology Special Publication 800-115 testing methodologies.
  • Experience conducting network, web-application, application, and source-code security assessments.
  • Experience performing threat hunting or adversary-emulation activities.
  • Experience supporting Red Team and Blue Team exercises.
  • Experience working with Security Operations Center analysts and incident responders during cooperative testing.
  • Experience validating SIEM detections, security alerts, or cybersecurity-tool effectiveness using controlled offensive activity.
  • Experience conducting pre-audit or pre-authorization security assessments.
  • Experience researching emerging vulnerabilities, attack techniques, and adversary tradecraft.
  • Experience developing executive and technical penetration-testing out-briefs and assessment reports.
  • Familiarity with Department of Defense Risk Management Framework processes.
  • Familiarity with DHRA, DMDC, or comparable Department of Defense enterprise environments.

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.

Original Posting:October 9, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:Pay Range $107,900.00 - $195,050.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Skills Required

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical discipline; additional experience may substitute for the degree
  • 8+ years of prior relevant experience
  • Experience conducting penetration testing, vulnerability assessment, threat hunting, offensive security, or comparable cybersecurity assessment activities
  • Experience assessing enterprise networks, systems, applications, web applications, or code for exploitable cybersecurity weaknesses
  • Experience using commercial or open-source penetration-testing and offensive-security tools
  • Understanding of common attack techniques, exploitation methods, network protocols, operating systems, and application-security concepts
  • Experience developing penetration-testing methodologies, test plans, or technical assessment procedures
  • Experience documenting vulnerabilities, technical evidence, exploitation results, and remediation recommendations
  • Ability to distinguish theoretical vulnerabilities from weaknesses presenting practical exploitation or mission risk
  • Ability to communicate technical findings clearly to system owners, engineers, cybersecurity personnel, and government stakeholders
  • Ability to conduct authorized offensive-security activities within defined rules of engagement and government-approved procedures
  • U.S. citizenship
  • Active Secret security clearance
  • Experience conducting penetration testing within Department of Defense or federal environments
  • Experience applying NIST Special Publication 800-115 testing methodologies
  • Experience conducting network, web-application, application, and source-code security assessments
  • Experience performing threat hunting or adversary-emulation activities
  • Experience supporting Red Team and Blue Team exercises
  • Experience working with Security Operations Center analysts and incident responders during cooperative testing
  • Experience validating SIEM detections, security alerts, or cybersecurity-tool effectiveness using controlled offensive activity
  • Experience conducting pre-audit or pre-authorization security assessments
  • Experience researching emerging vulnerabilities, attack techniques, and adversary tradecraft
  • Experience developing executive and technical penetration-testing out-briefs and assessment reports
  • Familiarity with Department of Defense Risk Management Framework processes
  • Familiarity with DHRA, DMDC, or comparable Department of Defense enterprise environments

Leidos Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Leidos and has not been reviewed or approved by Leidos.

  • Healthcare Strength — Healthcare coverage is described as comprehensive, with multiple plan options, low office-visit copays in some plans, and access to mental health and wellness support tools. The availability of HSA/FSA options and employer contributions is positioned as a meaningful part of the total package.
  • Retirement Support — Retirement benefits are framed as a strong component of total rewards, highlighted by a 401(k) match and immediate vesting in the standard package. The Employee Stock Purchase Plan is also presented as an additional long-term wealth-building feature.
  • Wellbeing & Lifestyle Benefits — Wellbeing and lifestyle supports extend beyond core insurance, including wellness programs, fitness-related stipends, and assistance resources. Work flexibility and related perks are also included as part of the broader rewards experience.

Leidos Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Reston, VA
27,104 Employees
Year Founded: 1969

What We Do

We Are Leidos For 50 years we have been tackling some of the biggest problems that face our nation and our world. OUR MISSION Through our culture of innovation and history of performance, we develop deep customer trust built on integrity and create enduring solutions that improve our world. Leidos is a science and technology solutions leader working to address some of the world’s toughest challenges in the defense, intelligence, homeland security, civil, and healthcare markets. The company’s 43,000 employees support vital missions for government and commercial customers. Headquartered in Reston, Va., Leidos reported annual revenues of approximately $11.09 billion for the fiscal year ended January 3, 2020. Leidos was cited for the meaningful work employees perform that is challenging, impactful, and aligned with our customers’ missions as reasons professionals want to work and stay at our company. Leidos has also been named to lists including Forbes’ Best Employers for Diversity, Forbes’ America’s Best Employers for Women, Military Times Best for Vets Employers, and Ethisphere Institute’s World's Most Ethical Companies®. Employees enjoy career enrichment opportunities available through mobility and development and experience rewarding relationships with supportive supervisors and talented colleagues and customers. Employees appreciate our flexible work environment, allowing for and encouraging a true work-life balance. Our professionals are also excited about our Employee Resource Groups, like the newly launched Collaborative Outreach with Remote and Embedded Employees (CORE), which strives to create an environment where every employee, regardless of location, feels fully engaged as a valued employee of Leidos. Your most important work is ahead.

Similar Jobs

NinjaOne Logo NinjaOne

Penetration Tester

Information Technology • Productivity • Software • Infrastructure as a Service (IaaS)
Remote or Hybrid
19 Locations
2000 Employees
130K-165K Annually

General Dynamics Information Technology Logo General Dynamics Information Technology

Penetration Tester Senior

Aerospace • Information Technology • Professional Services • Security • Software
In-Office
Ashburn, VA, USA
21625 Employees
143K-170K Annually

General Dynamics Information Technology Logo General Dynamics Information Technology

Penetration Tester Mid-Level

Aerospace • Information Technology • Professional Services • Security • Software
In-Office
Ashburn, VA, USA
21625 Employees
108K-129K Annually

General Dynamics Information Technology Logo General Dynamics Information Technology

Penetration Tester Junior

Aerospace • Information Technology • Professional Services • Security • Software
In-Office
Ashburn, VA, USA
21625 Employees
91K-124K Annually

Similar Companies Hiring

Ford Energy Thumbnail
Automotive • Software • Energy • Utilities • Manufacturing • Renewable Energy
US
55 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
70 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account