Dragonfli Group logo
Dragonfli Group
Posted 19 days agoVerified live 1d ago

Mid-Level Penetration Tester

Brief overview

Remote
5+ yrsMinimum
Penetration TestingVulnerability Validation and Exploit Chain AnalysisMITRE ATT&CK and ATLAS MappingOSCPOSCEGPENGXPNIndependent Leadership

About the company

Dragonfli Group logo
Dragonfli Groupdragonfligroup.com

The Dragonfli Group is a Washington, DC based LLC specializing in management and technology consulting.

Job description

Summary

Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. The company is seeking a Mid-Level Penetration Tester to independently plan and execute authorized penetration tests across diverse environments, coordinate with system owners and SOC personnel, validate vulnerabilities and federal findings, and produce decision-ready reports.

Responsibilities

  • Plan and execute authorized penetration tests across network, endpoint, wireless, database, application, and infrastructure environments using structured Planning, Discovery, Testing, and Reporting phases
  • Develop and tailor Rules of Engagement, Execution Plans, daily status updates, and final reporting inputs for assigned assessments
  • Coordinate with system owners, SOC personnel, and other stakeholders to confirm scope, test windows, prerequisites, safety thresholds, and stop/pause procedures
  • Validate vulnerabilities arising from misconfigurations, outdated software, weak access controls, incomplete control implementation, and exploitable attack paths
  • Support validation of CISA WAS, CISA FAST, KEV exposure, and external-facing asset findings, and coordinate retesting to confirm closure
  • Use approved automated and AI-enabled tools to improve reconnaissance, testing efficiency, ATT&CK/ATLAS mapping, evidence development, and reporting while maintaining human oversight

Skills

  • U.S. Citizenship or Permanent Residency (required for this federal engagement)
  • Approximately 5 to 8 years of experience conducting or leading penetration testing engagements
  • Demonstrated ability to plan and execute assessments across network, endpoint, wireless, database, application, and infrastructure environments
  • Experience developing Rules of Engagement, Execution Plans, and formal, decision-ready reporting for stakeholders
  • Experience coordinating directly with system owners and SOC personnel on scope, safety thresholds, and stop/pause procedures
  • Ability to work fully remote with reliable, secure connectivity
  • End-to-end penetration testing across network, endpoint, wireless, database, application, and infrastructure environments
  • Rules of Engagement and Execution Plan development
  • Vulnerability validation and exploit chain analysis
  • CISA WAS/FAST and KEV validation and retesting
  • MITRE ATT&CK/ATLAS mapping and AI-enabled testing tools
  • Stakeholder coordination with system owners and SOC teams
  • Clear, decision-ready written and verbal reporting
  • Sound judgment around safety thresholds and stop/pause procedures
  • Ability to lead an assessment independently with minimal oversight
  • Mentorship of junior testing staff
  • Candidates with previous federal contracting experience are preferred
  • Previous federal contracting experience
  • Experience with CISA WAS, CISA FAST, and KEV validation and retest workflows
  • Familiarity with MITRE ATT&CK and ATLAS mapping
  • Advanced certifications such as OSCP, OSCE, GPEN, or GXPN
  • Experience integrating AI-enabled tools into testing workflows while maintaining human oversight of results

Qualifications

Must Haves

  • U.S. Citizenship or Permanent Residency (required for this federal engagement)
  • Approximately 5 to 8 years of experience conducting or leading penetration testing engagements
  • Demonstrated ability to plan and execute assessments across network, endpoint, wireless, database, application, and infrastructure environments
  • Experience developing Rules of Engagement, Execution Plans, and formal, decision-ready reporting for stakeholders
  • Experience coordinating directly with system owners and SOC personnel on scope, safety thresholds, and stop/pause procedures
  • Ability to work fully remote with reliable, secure connectivity
  • End-to-end penetration testing across network, endpoint, wireless, database, application, and infrastructure environments
  • Rules of Engagement and Execution Plan development
  • Vulnerability validation and exploit chain analysis
  • CISA WAS/FAST and KEV validation and retesting
  • MITRE ATT&CK/ATLAS mapping and AI-enabled testing tools
  • Stakeholder coordination with system owners and SOC teams
  • Clear, decision-ready written and verbal reporting
  • Sound judgment around safety thresholds and stop/pause procedures
  • Ability to lead an assessment independently with minimal oversight
  • Mentorship of junior testing staff

Nice to Haves

  • Candidates with previous federal contracting experience are preferred
  • Previous federal contracting experience
  • Experience with CISA WAS, CISA FAST, and KEV validation and retest workflows
  • Familiarity with MITRE ATT&CK and ATLAS mapping
  • Advanced certifications such as OSCP, OSCE, GPEN, or GXPN
  • Experience integrating AI-enabled tools into testing workflows while maintaining human oversight of results

Benefits

  • Medical coverage, including multiple POS health plan options and an HSA-compatible plan
  • Dental PPO coverage for preventive, basic, and major services
  • Vision coverage, including an annual exam and frames, lenses, and contact lens allowance
  • 401(k) with employer match up to 5% of eligible compensation
  • Long-Term Disability coverage that is 100% employer-paid at 50% of pre-disability earnings
  • Life Insurance and AD&D coverage, 100% employer-paid and valued at $10,000 each
  • 15 to 25 days of PTO annually based on tenure
  • Paid Federal Holidays, with all 11 federal holidays observed
  • Fully remote position

More jobs like this