Penetration Testing Lead
Job description
Job Summary: The Penetration Testing Lead / Information Security Analyst SME is responsible for leading all penetration testing assessment activities, developing testing strategies, and overseeing execution. This role serves as the primary technical interface with oversight bodies, ensuring comprehensive security evaluations across cloud, network, application, and data environments. The position involves validating detection capabilities, conducting executive briefings, and delivering detailed findings to stakeholders.
Responsibilities: - Lead security architecture assessments and develop Rules of Engagement (ROE).
- Design custom attack-path testing methodologies tailored to organizational needs.
- Oversee and execute penetration testing across cloud, network, application, and data exfiltration domains.
- Validate detection and monitoring capabilities to ensure effective security controls.
- Conduct executive briefings and present exit brief and findings reports.
- Review and approve all deliverables related to penetration testing activities.
Required Skills & Certifications: - Bachelor's Degree in Cybersecurity, Computer Science, Information Systems, or related field.
- Minimum 10 years of cybersecurity experience.
- At least 7 years of penetration testing experience.
- Experience supporting Federal agencies.
- Knowledge of NIST Risk Management Framework (RMF) and FISMA environments.
- Experience conducting cloud security assessments.
Preferred Skills & Certifications: - OSCP certification (highly preferred).
- CISSP certification.
- GPEN, GXPN, or CEH certifications.
- Experience with hybrid cloud penetration testing.
- Expertise in data exfiltration testing and vulnerability exploitation.
- Security architecture review experience.
- Familiarity with Privacy Act and Controlled Unclassified Information (CUI) environments.
Special Considerations: - Must comply with federal security standards and regulations.
- May require handling sensitive and classified information.
- Role involves interaction with oversight and regulatory bodies.
Scheduling: - Standard work schedule with potential for additional hours during critical assessment phases.
- Availability for executive briefings and presentations as required.
first seen 2026-08-12 08:40:01 · last verified 2026-08-19 06:48:01
pentestcareers.com // breach the job market