Summary
Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. The Penetration Tester Analyst will support authorized penetration testing activities through assessment planning, reconnaissance, evidence collection, findings documentation, reporting, and triage of vulnerability-related results using approved automation and AI-enabled tools.
Responsibilities
- Support assessment planning by maintaining test schedules, scope records, stakeholder coordination notes, and required pre-assessment documentation
- Assist with controlled discovery, enumeration, testing support, and evidence capture within approved authorization boundaries
- Document findings, affected assets, ownership, reproducibility details, remediation recommendations, and retest requirements for inclusion in final reports
- Support validation and triage of external-facing asset findings, CISA WAS and FAST results, KEV exposure items, and VDP submissions
- Coordinate daily status inputs, meeting notes, action tracking, and after-action support for assigned testing activities
- Use approved automation and AI-enabled tools to improve data collection, initial correlation, draft reporting, and testing workflow efficiency
Skills
- U.S. Citizenship or Permanent Residency (required for this federal engagement)
- Approximately 2 to 4 years of experience in penetration testing, vulnerability assessment, or a related offensive/defensive cybersecurity role
- Working knowledge of common penetration testing methodologies and tools (e.g., Burp Suite, Nmap, Metasploit, or equivalents)
- Familiarity with reconnaissance, enumeration, and evidence collection within authorized testing boundaries
- Strong written documentation skills for findings, reproducibility steps, and remediation recommendations
- Ability to work fully remote with reliable, secure connectivity
- Previous federal contracting experience
- Exposure to CISA Web Application Scanning (WAS) and Fast Attack Surface Testing (FAST) programs
- Familiarity with Known Exploited Vulnerabilities (KEV) catalog and Vulnerability Disclosure Program (VDP) triage
- Relevant certifications such as Security+, CEH, GPEN, or OSCP (or actively pursuing)
- Experience using AI-enabled or automation tools to support testing and reporting workflows
Qualifications
Must Haves
- U.S. Citizenship or Permanent Residency (required for this federal engagement)
- Approximately 2 to 4 years of experience in penetration testing, vulnerability assessment, or a related offensive/defensive cybersecurity role
- Working knowledge of common penetration testing methodologies and tools (e.g., Burp Suite, Nmap, Metasploit, or equivalents)
- Familiarity with reconnaissance, enumeration, and evidence collection within authorized testing boundaries
- Strong written documentation skills for findings, reproducibility steps, and remediation recommendations
- Ability to work fully remote with reliable, secure connectivity
Nice to Haves
- Previous federal contracting experience
- Exposure to CISA Web Application Scanning (WAS) and Fast Attack Surface Testing (FAST) programs
- Familiarity with Known Exploited Vulnerabilities (KEV) catalog and Vulnerability Disclosure Program (VDP) triage
- Relevant certifications such as Security+, CEH, GPEN, or OSCP (or actively pursuing)
- Experience using AI-enabled or automation tools to support testing and reporting workflows
Benefits
- Medical, multiple POS health plan options including an HSA-compatible plan
- Dental, PPO coverage for preventive, basic, and major services
- Vision, annual exam, frames, lenses, and contact lens allowance
- 401(k), employer match up to 5% of eligible compensation
- Long-Term Disability, 100% employer-paid coverage at 50% of pre-disability earnings
- Life Insurance and AD&D, 100% employer-paid coverage valued at $10,000 each
- PTO, 15 to 25 days annually based on tenure
- Paid Federal Holidays, all 11 federal holidays observed