waypointjobs

Dragonfli Group

Penetration Tester Analyst

Remote — United States (see country and timezone requirements)

Check who can apply and the requirements below before continuing.

Job description

Description

Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.

Dragonfli Group is seeking a Pen Testing Analyst to join a growing Penetration Testing workstream supporting a large federal agency. In this fully remote role, you will provide analytical and hands-on support for authorized penetration testing activities, including test preparation, reconnaissance, evidence collection, documentation, and reporting for rapid validation efforts. You will help maintain test schedules and scope records, support controlled discovery and enumeration within approved authorization boundaries, and document findings and remediation recommendations for inclusion in final assessment reports. You will also assist with triage of external-facing asset findings, CISA WAS and FAST results, KEV exposure items, and Vulnerability Disclosure Program (VDP) submissions, and will use approved automation and AI-enabled tools to improve data collection, correlation, and reporting workflows. This role is well suited to a candidate with approximately 2 to 4 years of relevant experience in penetration testing, vulnerability assessment, or a closely related cybersecurity discipline.

This is a multi-year contract position involving a large US federal agency. Candidates with previous federal contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.

This is a fully remote position.

Key Responsibilities:

Support assessment planning by maintaining test schedules, scope records, stakeholder coordination notes, and required pre-assessment documentation.

Assist with controlled discovery, enumeration, testing support, and evidence capture within approved authorization boundaries.

Document findings, affected assets, ownership, reproducibility details, remediation recommendations, and retest requirements for inclusion in final reports.

Support validation and triage of external-facing asset findings, CISA WAS and FAST results, KEV exposure items, and VDP submissions.

Coordinate daily status inputs, meeting notes, action tracking, and after-action support for assigned testing activities.

Use approved automation and AI-enabled tools to improve data collection, initial correlation, draft reporting, and testing workflow efficiency.

Requirements

Must-Have

U.S. Citizenship or Permanent Residency (required for this federal engagement)

Approximately 2 to 4 years of experience in penetration testing, vulnerability assessment, or a related offensive/defensive cybersecurity role

Working knowledge of common penetration testing methodologies and tools (e.g., Burp Suite, Nmap, Metasploit, or equivalents)

Familiarity with reconnaissance, enumeration, and evidence collection within authorized testing boundaries

Strong written documentation skills for findings, reproducibility steps, and remediation recommendations

Ability to work fully remote with reliable, secure connectivity

Preferred / Nice-to-Have

Previous federal contracting experience

Exposure to CISA Web Application Scanning (WAS) and Fast Attack Surface Testing (FAST) programs

Familiarity with Known Exploited Vulnerabilities (KEV) catalog and Vulnerability Disclosure Program (VDP) triage

Relevant certifications such as Security+, CEH, GPEN, or OSCP (or actively pursuing)

Experience using AI-enabled or automation tools to support testing and reporting workflows

Skill(s)

Technical Skills

Penetration testing fundamentals and common toolsets

Vulnerability scanning, enumeration, and evidence capture

Report writing and findings documentation

Familiarity with CISA WAS/FAST, KEV, and VDP processes

Comfort with automation and AI-enabled testing support tools

Soft Skills

Strong written and verbal communication

Attention to detail and thorough documentation habits

Ability to work independently in a remote, distributed team

Collaborative coordination with stakeholders and testing leads

Time management across concurrent assessment activities

Benefits

Dragonfli Group offers a comprehensive benefits package that includes:

Medical, Multiple POS health plan options including an HSA-compatible plan

Dental, PPO coverage for preventive, basic, and major services

Vision, Annual exam, frames, lenses, and contact lens allowance

401(k), Employer match up to 5% of eligible compensation

Long-Term Disability, 100% employer-paid coverage at 50% of pre-disability earnings

Life Insurance and AD&D, 100% employer-paid coverage valued at $10,000 each

PTO, 15 to 25 days annually based on tenure

Paid Federal Holidays, All 11 federal holidays observed

Originally posted on Himalayas

Who can apply

Eligible countries: United States. Accepted UTC offsets: UTC-10, UTC-9, UTC-8, UTC-7, UTC-6, UTC-5, UTC+14. Review the full description for employer-specific work authorization, residency and schedule requirements.

Ready for your next step?Apply on the official website
Apply on Himalayas ↗

Explore related searches

Current related jobs

infisical

Jobicy

Senior Full Stack Engineer

Remote — Brazil, Canada, Europe, USA

Salary not specifiedRemote

Infisical is the open source security infrastructure platform that engineers use for secrets management, certificates, and privileged access mana…

Listing review due 2026-10-07View job

Spotify

Jobicy

Data Scientist - Music Mission

Remote — USA

Salary not specifiedRemote

The Music Mission enables music creators to grow, engage, and monetize their fan bases on Spotify. Central to the Music Mission's vision is the d…

Listing review due 2026-10-07View job

Spotify

Jobicy

Data Scientist - Music Promotion

Remote — USA

Salary not specifiedRemote

The Music Mission enables Music creators to grow, engage & monetize their fan bases on Spotify. Central to the Music Mission's vision is the deve…

Listing review due 2026-10-07View job

infisical

Jobicy

Strategic Finance

Remote — Canada, USA

Salary not specifiedRemote

Infisical is the open source security infrastructure platform that engineers use for secrets management, certificates, and privileged access mana…

Listing review due 2026-10-07View job