Pen Test SME
Washington, AR - USA
Job Summary
Job Title: Pen Test SME (Optional Task 10)
Washington DC(Hybrid)
Long Term
Job Summary
The Pen Test SME leads execution of Optional Task 10 (Penetration Testing) when the Government exercises it up to once annually. The SME applies a methodology combining NIST SP 800-115 with the Penetration Testing Execution Standard (PTES). Responsibilities include scoping Rules of Engagement (ROE) development within 10 days of activation full-spectrum testing across on-premises and cloud assets findings analysis and report development within 15 days of test completion plus the Penetration Test Briefing within 15 days of report delivery. The SME applies non-intrusive techniques and white-box collaboration when fragile or sensitive assets are in scope.
Mandatory Qualifications
- Minimum five (5) years dedicated penetration testing experience with documented engagement track record
- Demonstrated NIST SP 800-115 methodology application
- Demonstrated PTES (Penetration Testing Execution Standard) methodology application
- Experience with full attack lifecycle: footprinting scanning enumeration gaining access privilege escalation maintaining access network exploitation covering tracks
- Experience with Metasploit-class frameworks; Burp Suite Nmap Wireshark and other industry-standard tools
- Experience with cloud asset penetration testing (AWS Azure or GCP)
- Experience producing executive-summary findings and prioritized remediation recommendations for non-technical Government leadership
- U.S. citizenship required
Preferred Qualifications
- MITRE ATT&CK framework expertise
- Federal pen test engagement history (DoD civilian agency intelligence community)
- Web application pen testing under OWASP WSTG
- ICS / IoT / OT pen test experience
- Red / blue / purple team coordination experience
Required Certifications (mandatory unless noted)
- MANDATORY ONE OF: OSCP (Offensive Security Certified Professional) GPEN (GIAC Penetration Tester) OR CEH Master
- Active or recent Public Trust suitability
Recruiting Submission Checklist
- Resume in TGI federal proposal format (chronological work history certifications education security clearances federal experience flag)
- Signed Letter of Commitment (using template in Section 4 of this document)
- Verified copies of required certifications (e.g. CISSP CAP CISM)
- Public trust suitability status if currently held; HSPD-12 readiness statement if not
- Contact information for two professional references (federal supervisors preferred)
- Confirmation of availability within 30-day Transition-In window