waypointjobs

Dragonfli Group

Penetration Tester

Remote — United States (see country and timezone requirements)

Check who can apply and the requirements below before continuing.

Job description

Description

Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.

Dragonfli Group is seeking a Mid-Level Penetration Tester to join a consolidated enterprise Penetration Testing program supporting a large federal agency. In this fully remote role, you will plan and execute authorized penetration tests across network, endpoint, wireless, database, application, and infrastructure environments, following structured Planning, Discovery, Testing, and Reporting phases. You will develop Rules of Engagement, Execution Plans, and decision-ready reporting, coordinate directly with system owners and SOC personnel to confirm scope and safety thresholds, and validate exploitable conditions arising from misconfigurations, outdated software, and weak access controls. You will also support validation of CISA WAS and FAST findings, KEV exposure items, and coordinate retesting to confirm closure, using approved AI-enabled tools to improve reconnaissance and ATT&CK/ATLAS mapping while maintaining human oversight. This role calls for approximately 5 to 8 years of relevant experience leading or independently executing penetration testing engagements.

This is a multi-year contract position involving a large US federal agency. Candidates with previous federal contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.

This is a fully remote position.

Key Responsibilities:

Plan and execute authorized penetration tests across network, endpoint, wireless, database, application, and infrastructure environments using structured Planning, Discovery, Testing, and Reporting phases.

Develop and tailor Rules of Engagement, Execution Plans, daily status updates, and final reporting inputs for assigned assessments.

Coordinate with system owners, SOC personnel, and other stakeholders to confirm scope, test windows, prerequisites, safety thresholds, and stop/pause procedures.

Validate vulnerabilities arising from misconfigurations, outdated software, weak access controls, incomplete control implementation, and exploitable attack paths.

Support validation of CISA WAS, CISA FAST, KEV exposure, and external-facing asset findings, and coordinate retesting to confirm closure.

Use approved automated and AI-enabled tools to improve reconnaissance, testing efficiency, ATT&CK/ATLAS mapping, evidence development, and reporting while maintaining human oversight.

Requirements

Must-Have

U.S. Citizenship or Permanent Residency (required for this federal engagement)

Approximately 5 to 8 years of experience conducting or leading penetration testing engagements

Demonstrated ability to plan and execute assessments across network, endpoint, wireless, database, application, and infrastructure environments

Experience developing Rules of Engagement, Execution Plans, and formal, decision-ready reporting for stakeholders

Experience coordinating directly with system owners and SOC personnel on scope, safety thresholds, and stop/pause procedures

Ability to work fully remote with reliable, secure connectivity

Preferred / Nice-to-Have

Previous federal contracting experience

Experience with CISA WAS, CISA FAST, and KEV validation and retest workflows

Familiarity with MITRE ATT&CK and ATLAS mapping

Advanced certifications such as OSCP, OSCE, GPEN, or GXPN

Experience integrating AI-enabled tools into testing workflows while maintaining human oversight of results

Skill(s)

Technical Skills

End-to-end penetration testing across network, endpoint, wireless, database, application, and infrastructure environments

Rules of Engagement and Execution Plan development

Vulnerability validation and exploit chain analysis

CISA WAS/FAST and KEV validation and retesting

MITRE ATT&CK/ATLAS mapping and AI-enabled testing tools

Soft Skills

Stakeholder coordination with system owners and SOC teams

Clear, decision-ready written and verbal reporting

Sound judgment around safety thresholds and stop/pause procedures

Ability to lead an assessment independently with minimal oversight

Mentorship of junior testing staff

Benefits

Dragonfli Group offers a comprehensive benefits package that includes:

Medical, Multiple POS health plan options including an HSA-compatible plan

Dental, PPO coverage for preventive, basic, and major services

Vision, Annual exam, frames, lenses, and contact lens allowance

401(k), Employer match up to 5% of eligible compensation

Long-Term Disability, 100% employer-paid coverage at 50% of pre-disability earnings

Life Insurance and AD&D, 100% employer-paid coverage valued at $10,000 each

PTO, 15 to 25 days annually based on tenure

Paid Federal Holidays, All 11 federal holidays observed

Originally posted on Himalayas

Who can apply

Eligible countries: United States. Accepted UTC offsets: UTC-10, UTC-9, UTC-8, UTC-7, UTC-6, UTC-5, UTC+14. Review the full description for employer-specific work authorization, residency and schedule requirements.

Ready for your next step?Apply on the official website
Apply on Himalayas ↗

Explore related searches

Current related jobs

Red Wine and Blue

Himalayas

General Interest Application

Remote — United States (see country and timezone requirements)

Salary not specifiedfull timeRemote

WHO THE HECK ARE WE? Red Wine & Blue is a national community of over 600,000 diverse suburban women working together to defeat extremism, one fr…

Listing expires 2026-12-04View job

Carle Health

Himalayas

Finance Systems Analyst

Remote — United States (see country and timezone requirements)

$26.41 – $44.10 per hourfull timeRemote

OverviewThe Finance Systems Analyst assists with supporting assigned finance/accounting applications for the enterprise such as costing, producti…

Listing expires 2026-12-04View job

Kyowa Kirin

Himalayas

Scientific Relations Manager

Remote — Worldwide (see timezone requirements)

Salary not specifiedfull timeRemote

OverviewWE PUSH THE BOUNDARIES OF MEDICINE. LEAPING FORWARD TO MAKE PEOPLE SMILE At Kyowa Kirin International (KKI), our purpose is to make peop…

Listing expires 2026-12-04View job

Belden, Inc

Himalayas

Solution Consultant - Cybersecurity Practice (US)

Remote — United States (see country and timezone requirements)

$125,000.00 – $160,000.00 per yearfull timeRemote

Innovation Starts With YouPropel your career at Belden, where innovation creates possibilities—for our people, our customers, and the communities…

Listing expires 2026-12-04View job