Point your AI agent at freehire and let it find you a job.

Get the CLI →

ASRC Federal

NewBe an early applicant

Expert Penetration Tester

Posted Updated
Discussion

ASRC Federal Technology Solutions is seeking an experienced Expert Penetration Tester to lead advanced security assessments and contribute to the development and execution of penetration testing strategies. This role combines hands-on testing with leadership, mentoring, and collaboration across cybersecurity disciplines.
Work Location: Hybrid, DC (3 days per week onsite)
Responsibilities

Lead and perform advanced security assessments, including hands-on penetration testing of systems and applications.

Identify vulnerabilities, assess risks, and deliver clear, actionable remediation recommendations.

Develop and maintain assessment plans aligned with NIST SP 800-53 and FedRAMP Cloud Security Controls.

Execute security assessments per defined plans and document findings accurately and promptly.

Design, develop, and maintain tools/scripts to automate and enhance penetration testing activities.

Manage and mentor a small team of junior penetration testers; provide technical guidance and training.

Build and lead a Purple Team to perform joint red/blue team exercises with customer sites.

Support secure systems operations and maintenance, including security validation and accreditation activities.

Analyze and mitigate system security threats throughout the lifecycle, including risk assessments and implementation of security engineering controls.

Ensure compliance with business continuity, operations security, insider threat detection, physical security analysis, and regulatory requirements.

Communicate technical findings effectively to technical teams and executive stakeholders.

Requirements

Education: Bachelor's degree in a related field.

Experience: 8+ years of relevant experience in cybersecurity and penetration testing (or equivalent combination of education and experience).

Clearance: Active DOE Q-Clearance or Top Secret (TS) equivalent or eligible to obtain.

Certifications (Preferred):

OSCP (Offensive Security Certified Professional)

OSCE (Offensive Security Certified Expert)

CEH (Certified Ethical Hacker)

CISSP (Certified Information Systems Security Professional)

Technical Skills & Tools

Strong proficiency in vulnerability analysis, risk remediation, and reporting.

Ability to clearly replicate vulnerabilities and provide actionable mitigation steps.

Familiarity with tools including:

Linux, Tenable Nessus, Forescout, Carbon Black, Invicti,

Scythe, Rubrik, Fidelis

Excellent written and verbal communication skills; ability to present technical findings to executive audiences.

Skills

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available