We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Senior Penetration Tester / Vulnerability Assessment Engineer

ANALYGENCE
United States, D.C., Washington
Oct 01, 2026

Tharros supports the Department of Homeland Security (DHS) with cybersecurity services across its Intelligence Enterprise.

In support of this mission, we have an immediate opportunity for a Senior Penetration Tester / Vulnerability Assessment Engineer. In this role you will identify, assess, and validate vulnerabilities across DHS Intelligence Enterprise cloud and on-premise systems through penetration testing, software assurance, and vulnerability assessment. You will emphasize manual, expert-driven techniques to find what automated tools miss and validate SOC detection and response. This position is on-site in a Government SCIF in Washington, DC.

Duties include but not limited to:


  • Perform penetration tests across the DHS IE portfolio using standard methodologies (e.g., MITRE ATT&CK, OWASP), from rules of engagement through exploitation, post-exploitation, and reporting.
  • Use manual techniques to find vulnerabilities commonly missed by automated tools.
  • Validate SOC incident response procedures through controlled testing.
  • Perform software assurance through vulnerability and compliance testing of software requests; provide approval recommendations.
  • Conduct source code reviews using automated tools and manual processes.
  • Perform vulnerability assessments and supply chain risk management reviews.
  • Maintain the security posture of the penetration testing kit.
  • Update penetration testing, SCRM, and vulnerability assessment SOPs.
  • BS degree in Information Technology, Cybersecurity, Information Systems, or Computer Science OR minimum of 10 years' experience in IT or cybersecurity.
  • Minimum of 7 years' experience in penetration testing or vulnerability assessment.
  • Active TS/SCI clearance and U.S. citizenship; willingness to undergo a DHS counterintelligence-scope polygraph.
  • Knowledge of penetration testing methodologies and frameworks (e.g., MITRE ATT&CK, OWASP, PTES).
  • Knowledge of software assurance and secure code review practices.
  • Knowledge of common attack vectors across network, application, and cloud layers.
  • Skill in manual exploitation using tools such as Burp Suite, Metasploit, or Core Impact.
  • Skill in static code analysis using tools such as SonarQube or Fortify.
  • Ability to write clear penetration test reports with recommended corrective actions.
  • Proficient in Microsoft Office Suite to include Teams or similar workplace chat and videoconferencing tools.
  • Excellent written and oral communications skills.

Desired


  • OSCP, GPEN, GWAPT, CEH, or CISSP certification.
  • Cloud (AWS, Azure) or Cross Domain Solution testing experience.

Applied = 0

(web-9db6c7984-p2wxp)