Mid-Level Penetration Tester

🏢 Dragonfli Group · all 8 jobs
📍 United States
📅 Posted Sep 19, 2026 · via Himalayas
🏷 Cybersecurity, Penetration Testing, Ethical Hacking, Infosec, Security Testing, Mid Level Cybersecurity Engineer +2 more
Apply on original site ↗

Description

Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.

Dragonfli Group is seeking a Mid-Level Penetration Tester to join a consolidated enterprise Penetration Testing program supporting a large federal agency. In this fully remote role, you will plan and execute authorized penetration tests across network, endpoint, wireless, database, application, and infrastructure environments, following structured Planning, Discovery, Testing, and Reporting phases. You will develop Rules of Engagement, Execution Plans, and decision-ready reporting, coordinate directly with system owners and SOC personnel to confirm scope and safety thresholds, and validate exploitable conditions arising from misconfigurations, outdated software, and weak access controls. You will also support validation of CISA WAS and FAST findings, KEV exposure items, and coordinate retesting to confirm closure, using approved AI-enabled tools to improve reconnaissance and ATT&CK/ATLAS mapping while maintaining human oversight. This role calls for approximately 5 to 8 years of relevant experience leading or independently executing penetration testing engagements.

This is a multi-year contract position involving a large US federal agency. Candidates with previous federal contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.
This is a fully remote position.
Key Responsibilities:

- Plan and execute authorized penetration tests across network, endpoint, wireless, database, application, and infrastructure environments using structured Planning, Discovery, Testing, and Reporting phases.

- Develop and tailor Rules of Engagement, Execution Plans, daily status updates, and final reporting inputs for assigned assessments.

- Coordinate with system owners, SOC personnel, and other stakeholders to confirm scope, test windows, prerequisites, safety thresholds, and stop/pause procedures.

- Validate vulnerabilities arising from misconfigurations, outdated software, weak access controls, incomplete control implementation, and exploitable attack paths.

- Support validation of CISA WAS, CISA FAST, KEV exposure, and external-facing asset findings, and coordinate retesting to confirm closure.

- Use approved automated and AI-enabled tools to improve reconnaissance, testing efficiency, ATT&CK/ATLAS mapping, evidence development, and reporting while maintaining human oversight.

Requirements
Must-Have

- U.S. Citizenship or Permanent Residency (required for this federal engagement)

- Approximately 5 to 8 years of experience conducting or leading penetration testing engagements

- Demonstrated ability to plan and execute assessments across network, endpoint, wireless, database, application, and infrastructure environments

- Experience developing Rules of Engagement, Execution Plans, and formal, decision-ready reporting for stakeholders

- Experience coordinating directly with system owners and SOC personnel on scope, safety thresholds, and stop/pause procedures

- Ability to work fully remote with reliable, secure connectivity

Preferred / Nice-to-Have

- Previous federal contracting experience

- Experience with CISA WAS, CISA FAST, and KEV validation and retest workflows

- Familiarity with MITRE ATT&CK and ATLAS mapping

- Advanced certifications such as OSCP, OSCE, GPEN, or GXPN

- Experience integrating AI-enabled tools into testing workflows while maintaining human oversight of results

Skill(s)
Technical Skills

- End-to-end penetration testing across network, endpoint, wireless, database, application, and infrastructure environments

- Rules of Engagement and Execution Plan development

- Vulnerability validation and

Flights + hotels

This role requires you to be in the United States. If that means relocating or flying in, it is worth checking fares before you commit to a start date.

Compare flights and hotels →

← All remote jobs

Want more like this? Browse every live remote developer role.All remote developer jobs →
Get new developer jobs by email
Daily email, only when there's something new. One click to stop.

Get remote developer jobs like this by email

10 hand-picked jobs, one email a day. No spam, unsubscribe anytime.

Similar for you