Summary
Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. The company is seeking a Mid-Level Penetration Tester to independently plan and execute authorized penetration tests across diverse environments, coordinate with system owners and SOC personnel, validate vulnerabilities and federal findings, and produce decision-ready reports.
Responsibilities
- Plan and execute authorized penetration tests across network, endpoint, wireless, database, application, and infrastructure environments using structured Planning, Discovery, Testing, and Reporting phases
- Develop and tailor Rules of Engagement, Execution Plans, daily status updates, and final reporting inputs for assigned assessments
- Coordinate with system owners, SOC personnel, and other stakeholders to confirm scope, test windows, prerequisites, safety thresholds, and stop/pause procedures
- Validate vulnerabilities arising from misconfigurations, outdated software, weak access controls, incomplete control implementation, and exploitable attack paths
- Support validation of CISA WAS, CISA FAST, KEV exposure, and external-facing asset findings, and coordinate retesting to confirm closure
- Use approved automated and AI-enabled tools to improve reconnaissance, testing efficiency, ATT&CK/ATLAS mapping, evidence development, and reporting while maintaining human oversight
Skills
- U.S. Citizenship or Permanent Residency (required for this federal engagement)
- Approximately 5 to 8 years of experience conducting or leading penetration testing engagements
- Demonstrated ability to plan and execute assessments across network, endpoint, wireless, database, application, and infrastructure environments
- Experience developing Rules of Engagement, Execution Plans, and formal, decision-ready reporting for stakeholders
- Experience coordinating directly with system owners and SOC personnel on scope, safety thresholds, and stop/pause procedures
- Ability to work fully remote with reliable, secure connectivity
- End-to-end penetration testing across network, endpoint, wireless, database, application, and infrastructure environments
- Rules of Engagement and Execution Plan development
- Vulnerability validation and exploit chain analysis
- CISA WAS/FAST and KEV validation and retesting
- MITRE ATT&CK/ATLAS mapping and AI-enabled testing tools
- Stakeholder coordination with system owners and SOC teams
- Clear, decision-ready written and verbal reporting
- Sound judgment around safety thresholds and stop/pause procedures
- Ability to lead an assessment independently with minimal oversight
- Mentorship of junior testing staff
- Candidates with previous federal contracting experience are preferred
- Previous federal contracting experience
- Experience with CISA WAS, CISA FAST, and KEV validation and retest workflows
- Familiarity with MITRE ATT&CK and ATLAS mapping
- Advanced certifications such as OSCP, OSCE, GPEN, or GXPN
- Experience integrating AI-enabled tools into testing workflows while maintaining human oversight of results
Qualifications
Must Haves
- U.S. Citizenship or Permanent Residency (required for this federal engagement)
- Approximately 5 to 8 years of experience conducting or leading penetration testing engagements
- Demonstrated ability to plan and execute assessments across network, endpoint, wireless, database, application, and infrastructure environments
- Experience developing Rules of Engagement, Execution Plans, and formal, decision-ready reporting for stakeholders
- Experience coordinating directly with system owners and SOC personnel on scope, safety thresholds, and stop/pause procedures
- Ability to work fully remote with reliable, secure connectivity
- End-to-end penetration testing across network, endpoint, wireless, database, application, and infrastructure environments
- Rules of Engagement and Execution Plan development
- Vulnerability validation and exploit chain analysis
- CISA WAS/FAST and KEV validation and retesting
- MITRE ATT&CK/ATLAS mapping and AI-enabled testing tools
- Stakeholder coordination with system owners and SOC teams
- Clear, decision-ready written and verbal reporting
- Sound judgment around safety thresholds and stop/pause procedures
- Ability to lead an assessment independently with minimal oversight
- Mentorship of junior testing staff
Nice to Haves
- Candidates with previous federal contracting experience are preferred
- Previous federal contracting experience
- Experience with CISA WAS, CISA FAST, and KEV validation and retest workflows
- Familiarity with MITRE ATT&CK and ATLAS mapping
- Advanced certifications such as OSCP, OSCE, GPEN, or GXPN
- Experience integrating AI-enabled tools into testing workflows while maintaining human oversight of results
Benefits
- Medical coverage, including multiple POS health plan options and an HSA-compatible plan
- Dental PPO coverage for preventive, basic, and major services
- Vision coverage, including an annual exam and frames, lenses, and contact lens allowance
- 401(k) with employer match up to 5% of eligible compensation
- Long-Term Disability coverage that is 100% employer-paid at 50% of pre-disability earnings
- Life Insurance and AD&D coverage, 100% employer-paid and valued at $10,000 each
- 15 to 25 days of PTO annually based on tenure
- Paid Federal Holidays, with all 11 federal holidays observed
- Fully remote position