Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

Penetration Tester

SkyePoint Decisions
CompanySkyePoint Decisions
CategorySecurity
Location1801 North Lynn St
RemoteOn-site (inferred)
EmploymentNot stated
LevelNot stated
SalaryNot stated by the employer
Posted23 Apr 2026
Last verified4 Aug 2026
SourceEmployer ATS (greenhouse)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure and Operations, and Applications Development and Maintenance IT service provider headquartered in Dulles, Virginia with operations across the U.S. We provide innovative enterprise-wide solutions as well as targeted services addressing the complex challenges faced by our federal government clients. Our focus is on enabling our clients to deliver their mission most efficiently and effectively – anytime, anywhere, securely. We combine technical expertise, mission awareness, and an empowered workforce to produce meaningful results. This is a contingent position based upon customer approval. SkyePoint Decisions is seeking a Penetration Tester to support the Diplomatic Security Cyber Mission (DSCM) program providing leading cyber and technology security experience to enable innovative, effective, and secure business processes.  This position is located in Arlington, VA and will be onsite 5 days a week. No hybrid/telework allowed.  Responsibilities: Support the Red Cell Team by performing and leading penetration tests to assess the security of customer systems. Identify vulnerabilities and develop recommended remediations to satisfy mandated NIST 800-53 security controls. Report and demonstrate findings to system owners and engineers. Maintain Red Cell infrastructure. Develop or modify tools to automate discovery or exploitation.   Required Qualifications: Bachelor of Science and 5 years of relevant experience in Cyber/IT, or a Master's of Science and 3 years of relevant experience in Cyber/IT. In lieu of a degree, 4 years of additional IT security or penetration testing experience may be considered. Minimum of 2 years with penetration testing experience.  Possess one of the following certifications, OR be able to obtain before start date: CCNA Cyber Ops, CCNA-Security, CEH, CFR, Cloud+, CySA+, GCIA, GCIH, GICSP, SCYBER, Security+ CE, SSCP Demonstrated experience with Kali Linux. Demonstrated penetration testing tools experience with Nmap, Burp Suite, Metasploit, etc. Demonstrated ability in evaluating vulnerabilities, performing root cause analysis, and reporting findings utilizing assessment methodologies such as NIST SP 800-115, Penetration Testing Execution Standard (PTES), Information Systems Security Assessment Framework (ISSAF), OWASP Web Security Testing Guide (WTG), etc. Demonstrated ability to lead a penetration test and guide Senior/Junior Penetration Testers. U.S. citizenship required.  An active Secret security clearance.  Must have the ability to obtain a final Top Secret security clearance.   Preferred Qualifications: Active Top Secret or TS/SCI clearance. One of the following certifications or an alternate, verifiable certification demonstrating IT security competence: CompTIA CASP+ ISC2 Certified Information Security Professional (CISSP) ISC2 Certified Cloud Security Professional (CCSP) ISC2 Information Systems Security Engineering Professional (ISSEP) One of the following certifications or an alternate, verifiable certification demonstrating practical penetration testing competence: Offensive Security Certified Professional (OSCP) Offensive Security Certified Professional (OSCP) Hack the Box Certified Penetration Testing Specialist (CPTS) TCM Security Practical Network Penetration Tester (PNPT) GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) Zero Point Security Red Team Ops II Advanced understanding of the following: NIST Risk Management Framework (RMF) and the Assessment and Authorization (A&A) process. Security principles such as CIA, IAAAA, access control models, risk management, etc. Networking principles and technologies such as IP routing, TCP/UDP, VPNs, firewalls, NAT, etc. Common network protocols such as SSH, FTP, SMTP, SMB, HTTP,