Penetration Tester
LeidosAshburn, VAPosted 9 March 2026
Job Description
Department of Homeland Security (DHS), Customs and Border Protection (CBP) Security Operations Center (SOC) is a US Government program responsible to prevent, identify, contain and eradicate cyber threats to CBP networks through monitoring, intrusion detection and protective security services to CBP information systems including local area networks/wide area networks (LAN/WAN), commercial Internet connection, public facing websites, wireless, mobile/cellular, cloud, security devices, servers and workstations. The CBP SOC
is responsible for
the
overall security of CBP Enterprise-wide information systems, and collects, investigates, and reports any suspected and confirmed security
violations.
We
are
seeking
a highly skilled and experienced Penetration Tester to join our team supporting
the
CBP SOC . Th is
candidate will
be responsible for
conducting comprehensive security assessments
of
CBP
FISMA
systems with the purpose of
identifying
vulnerabilities and providing actionable recommendations to enhance the security posture of CBP's critical systems and networks. This role requires a deep understanding of offensive cybersecurity techniques, strong analytical capabilities,
detailed report writing skills
and the ability to work
as part of a team.
Primary Responsibilities:
Conduct penetration testing activities aligned with
CBP
and industry best practices.
Perform
internal and external
web application, network, and infrastructure
pentest
assessments using commercial and open-source tools.
Execute testing operations safely and
in accordance with
defined operational guidelines.
Produce detailed reports outlining findings and actionable remediation recommendations.
Partner with SOC, engineering, and security teams to
validate
and remediate vulnerabilities.
Support tool development,
methodology
improvements, and team-wide knowledge sharing.
Assist
in verifying Bug Bounty findings and remediations
Basic Qualifications:
Bachelors’ degree from an accredited college in a related discipline, or equivalent experience/combined education, with
3 to 5(T3)/
5 to 8
(T4)
years of professional experience; or 3 to 5 years of professional experience with a Masters’ degree.
3(T3) / 5 (T4) years in Pen Testing and Vulnerability Assessment, with specific emphasis on web application and enterprise network environments.
3-5 (T3) 5-8(T4) years of p rofessional experience in incident detection and response, malware analysis, or cyber forensics.
Specific experience
(1-3 years for T3) or (3-5 years for T4)
in at least 1
o f the following specialties:
Network
pentesting
Web application
pentesting
Active directory
pentesting
Mobile application
pen testing
Cloud infrastructure
pen testing
RF
pent esting
Experience with
1-3 (T3)
3-5(T4)
of the tools listed below:
Kali Linux
Metaspoilt
Burp suite pro
Cobalt Strike /
Sliver
Tenable Nessus
Tenable Security Center
Bloodhound
BladeRF
/
HakRF
Hak5 equipment
Wireshark /
tcpdump
Prowler
Scoutsuite
Core Certifications:
At least one
pentesting
certification:
OSCP
GPEN
CRTO
OSWP
GWAPT
AWS Solutions Architect Associate
Clearance:
In addition to specific security clearance requirements all CBP SOC employees
are required to
successfully complete a CBP Background Investigation to support this program
Pre ferred Qualifications :
CISSP
GISF
GXPN
OSCE
OSEE
AWS Certified Security - Specialty
Certified Kubernetes Administrator (CKA)
Ability to brief senior government leadership on pentesting requirements and results
Red Team operator experience
Experience creating and updating SOPs
Analytical and Problem-Solving Skills
Communication Skills
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at s ... (truncated, view full listing at source)
Apply Now
Direct link to company career page
AI Resume Fit Check
See exactly which skills you match and which are missing before you apply. Free, instant, no spam.
Check my resume fitFree · No credit card