See how much of this job your resume covers, and what’s missing.
Want a recruiter to go through it line by line?
Get professional reviewQuestions interviewers often ask for this role, with sample answers.
Upload your resume and we draft a letter for this exact role, tailored to what it asks for.
The Penetration Tester will conduct web, network, and mobile application security assessments while managing engagements from scoping through reporting. They will also provide strategic cybersecurity guidance and present findings to both technical teams and executive stakeholders.
Science Applications International Corporation (SAIC) is seeking a Penetration Tester to join our offensive security practice supporting a major state & local government customer. This role sits at the intersection of hands-on technical execution and cybersecurity leadership and it's built around delivering real impact for clients who depend on us to find what others miss.
Web application & Network penetration testing is the core of what you'll do every day, and we're looking for someone who brings both technical depth and genuine curiosity to every engagement. Beyond web and network pentesting you'll contribute to our mobile application testing practice (iOS and Android), support ethical hacking operations, and provide strategic guidance on enterprise cyber architecture and cloud security. This position reports to the Security Assessments Manager.
This is a role where your contributions are visible, your growth is intentional, and your voice matters to the team and to the clients we serve.
Deliver high-quality penetration tests across a range of client environments, applying black box, white box, web app or mobile methodologies as needed and aligned to NIST standards
Independently manage engagement workloads from scoping through reporting, with a consistent focus on quality
Produce clear, well-structured technical reports that communicate findings, risk context, and actionable remediation guidance to both technical teams and executive stakeholders and translate complex technical documentation into terms any stakeholder can act on
Support and contribute to mobile application security assessments (iOS and Android) using the OWASP MASVS/MSTG framework, with the expectation of growing mobile capabilities over time
Perform strategic planning and management in cybersecurity and digital forensics in alignment with the National Initiative for Cybersecurity Education (NICE) Framework
Address a wide range of security issues including architectures, firewalls, electronic data traffic, and network access
Research, evaluate, and recommend new security tools, techniques, and technologies; utilize COTS/GOTS and custom tools to scan, identify, contain, mitigate, and remediate vulnerabilities and intrusions
Apply expert engineering knowledge to design, develop, and implement security solutions across enterprise engagements
Confidently present findings to clients whether it is walking a developer through a vulnerability chain or explaining business risk to a CISO in the same afternoon
Act as a spokesperson and advisor on advanced technical projects and research; participate with senior management to establish strategic plans and objectives
Actively share knowledge with teammates, contribute to internal tooling and methodology improvements, and help close skill gaps across the practice
Stay current on emerging vulnerabilities, attack techniques, and industry developments and bring that knowledge back to the team
TYPICAL EDUCATION AND EXPERIENCE:
Candidates must be a US Citizen and able to pass a CJIS Criminal Justice background investigation and maintain CJIS clearance throughout employment term.
Advanced technical knowledge in cybersecurity and digital forensics
Strong working knowledge of the OWASP WSTG and OWASP Top 10 — not just the list, but how to find and exploit the vulnerabilities
Proficiency with standard web application testing tools (e.g., Burp Suite Pro, FFUF, SQLMap, Nuclei)
Working familiarity with mobile application testing concepts and tooling (e.g., Frida, Objection, MobSF, ADB)
Proven experience in red-teaming, ethical hacking, and cloud security architecture
Proficiency in malware reverse engineering and enterprise cyber architecture
Strong background in addressing security issues related to architectures, firewalls, electronic data traffic, and network access
Experience researching, evaluating, and recommending new security tools and technologies
Proficiency utilizing COTS/GOTS and custom tools for vulnerability management
Demonstrated ability to write professional, client-ready penetration test reports with minimal revision
GWAPT certification required or strongly preferred; candidates holding OSCP, OSWE, or GWEB will also be considered
Hands-on experience conducting iOS and/or Android application assessments
Familiarity with API security testing (REST, GraphQL, SOAP)
Exposure to source code review as part of white box engagements
Experience presenting findings directly to client stakeholders, including senior leadership
Participation with senior management to establish strategic plans and objectives
Experience working on unusually complex technical problems and providing innovative solutions
Proven ability to work under consultative direction toward long-range goals and objectives
Experience serving as an organizational spokesperson and advisor on advanced technical projects
Knowledge of applying advanced technical principles, theories, and concepts to develop new principles and concepts
Experience making decisions on administrative or project work matters to achieve program or organizational objectives
Strong background in developing advanced technological ideas and guiding them to final product development
Experience influencing organizational image and technological capability through decision-making and recommendations
Stop the endless job search. Our AI finds and applies to the best jobs for you.
Featuring 216,987+ Jobs in Penetration Tester
Answer easy questions
216,987+ jobs across 15+ categories
Get your best job matches
Only hand-screened, legit jobs
Find a remote job faster
No ads, scams, or junk
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”