Penetration Tester
Listed on 2026-03-01
-
IT/Tech
Cybersecurity, IT Consultant
Overview
Description
Department of Homeland Security (DHS), Customs and Border Protection (CBP) Security Operations Center (SOC) is a US Government program responsible to prevent, identify, contain and eradicate cyber threats to CBP networks through monitoring, intrusion detection and protective security services to CBP information systems including local area networks/wide area networks (LAN/WAN), commercial Internet connection, public facing websites, wireless, mobile/cellular, cloud, security devices, servers and workstations.
The CBP SOC is responsible for the overall security of CBP Enterprise-wide information systems, and collects, investigates, and reports any suspected and confirmed security violations.
We are seeking a highly skilled and experienced Penetration Tester to join our team supporting the CBP SOC. This candidate will be responsible for conducting comprehensive security assessments of CBP FISMA systems with the purpose of identifying vulnerabilities and providing actionable recommendations to enhance the security posture of CBP s critical systems and networks. This role requires a deep understanding of offensive cybersecurity techniques, strong analytical capabilities, detailed report writing skills and the ability to work as part of a team.
PrimaryResponsibilities
Conduct penetration testing activities aligned with CBP and industry best practices.
Perform internal and external web application, network, and infrastructure pentest assessments using commercial and open-source tools.
Execute testing operations safely and in accordance with defined operational guidelines.
Produce detailed reports outlining findings and actionable remediation recommendations.
Partner with SOC, engineering, and security teams to validate and remediate vulnerabilities.
Support tool development, methodology improvements, and team-wide knowledge sharing.
Assist in verifying Bug Bounty findings and remediations.
Bachelors degree from an accredited college in a related discipline, or equivalent experience/combined education, with 3 to 5 (T3) / 5 to 8 (T4) years of professional experience; or 3 to 5 years of professional experience with a Masters degree.
3 to 5 (T3) / 5 to 8 (T4) years in Pen Testing and Vulnerability Assessment, with specific emphasis on web application and enterprise network environments.
3-5 (T3) / 5-8 (T4) years of professional experience in incident detection and response, malware analysis, or cyber forensics.
Specific experience (1-3 years for T3) or (3-5 years for T4) in at least 1 of the following specialties:
Network pentesting
Web application pentesting
Active directory pentesting
Mobile application pentesting
Cloud infrastructure pentesting
RF pentesting
Experience with 1-3 (T3) / 3-5 (T4) of the tools listed below:
Kali Linux
Metasploit
Burp Suite Pro
Cobalt Strike / Sliver
Tenable Nessus
Tenable Security Center
Bloodhound
Blade
RF/HackRFHak5 equipment
Wireshark / tcpdump
Prowler
Scout Suite
At least one penetration testing certification:
OSCP
GPEN
CRTO
OSWP
GWAPT
AWS Solutions Architect Associate
In addition to specific security clearance requirements all CBP SOC employees are required to successfully complete a CBP Background Investigation to support this program.
Preferred QualificationsCISSP
GISF
GXPN
OSCE
OSEE
AWS Certified Security - Specialty
Certified Kubernetes Administrator (CKA)
Ability to brief senior government leadership on pentesting requirements and results
Red Team operator experience
Experience creating and updating SOPs
Analytical and problem-solving skills
Communication skills
Note:
Pay and benefits information and additional company details are provided in the posting.
About Leidos
Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit
Pay and Benefits
Pay and benefits are fundamental to any career decision. That is why we craft compensation packages that reflect the…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).