Penetration Tester - IT Security Audit (Short Term/Remote) Job at TestPros, Sterling, VA

Mlk4NkYyZVBlT2Z4Y3ZhS2paWE5ETnEwSEE9PQ==
  • TestPros
  • Sterling, VA

Job Description

Company Overview:

TestPros is a successful and growing business, established in 1988 to provide Information Technology (IT) technical support services to a wide range of Commercial and U.S. Federal, State, and Local Government customers. Our capabilities include Program Management, Program Oversight, Process Audit, Intelligence Analysis, Cyber Security, NIST 800-53, NIST SP 800-171 / CMMC Consulting/Assessment/Compliance, PCI Compliance, SOC 2, GLBA, Zero Trust, Resiliency, Computer Forensics, Software Supply Chain Assurance, Software Testing, Test Automation, Section 508 and WCAG Accessibility Assessment and Remediation, Localization Testing, Independent Verification and Validation (IV&V), Quality Assurance (QA), Compliance, and Research and Development (R&D) services. TestPros is an Equal Opportunity Employer.

Position: Part time (as needed, 1099 or Corp. to Corp)

Job Summary:

The ideal candidate will have strong hands-on experience conducting external and internal vulnerability assessments, penetration testing, and compliance-based security evaluations for government or municipal environments. This role requires the ability to perform non-disruptive testing, work within outage windows, and deliver clear, executive-level reporting.

Key Responsibilities

  • Perform external penetration testing and vulnerability scanning across a /24 public IP space .

  • Conduct internal penetration testing across a /21 internal network , including multiple VLANs and network segments.

  • Execute an assumed-breach scenario , such as testing from a compromised workstation via VPN.

  • Conduct a public Wi-Fi security assessment , identifying wireless vulnerabilities and attack vectors.

  • Evaluate the City's current security posture against CJIS, CORA, and NIST standards .

  • Coordinate testing that may involve systems or IP ranges belonging to sister government agencies .

  • Work within designated planned outage windows to perform active testing without disrupting operations.

  • Document all findings, including:

    • What was tested

    • What was not tested

    • Identified vulnerabilities and exploitability

    • Severity and risk prioritization

    • Recommended remediation steps

  • Prepare a comprehensive final report and participate in review meetings if requested.

Required Qualifications

  • OSCP or OSCE certification (either meets the requirement).

  • 5+ years of hands-on penetration testing and vulnerability assessment experience.

  • Proven experience performing both external and internal penetration tests in complex environments.

  • Strong understanding of:

    • Network segmentation

    • VPN-based testing

    • Active Directory

    • Cloud/SaaS environments

    • Firewall and IDS/IPS technologies

  • Experience with government, public sector, or municipal IT environments is highly preferred.

  • Ability to write clear, professional, and actionable technical reports.

Preferred Skills

  • Experience with SCADA-adjacent environments (testing is not performed on SCADA, but awareness is valuable).

  • Familiarity with CJIS security policy requirements.

  • Experience coordinating with multi-agency or cross-organizational IT teams.

  • Expertise with common tools such as Kali Linux, Burp Suite, Nmap, Metasploit, Nessus/Tenable, and Wireshark.

Engagement Details

  • Estimated Start: February 2026

  • Estimated Duration: 6–8 weeks

  • Work Location: Fully Remote (VPN access provided)

  • Clearances: Not required, but government experience is a plus

Benefits

TestPros offers a competitive salary, medical/dental/vision insurance, life insurance, paid time off, paid holidays, 401(k) retirement plan with company match, opportunities for professional growth, cell phone discounts, and much more!  All benefits are per TestPros current policies and are subject to change without notice.  Benefits are available to full-time employees.​

TestPros, Inc. is an Equal Opportunity Employer.

EEO Statement

All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, sexual orientation, gender identity, marital status, age, national origin, or protected veteran status.

Job Tags

Remote job, Full time, Temporary work, Part time, Local area,

Similar Jobs

DK Security

Armed Security Specialist Job at DK Security

 ...Overview DK Security is Michigans fastest growing security company. Established in 1995, we began as an investigations firm and quickly expanded to provide uniform security, event staff security, loss prevention services, and much more based on the needs of our clients... 

Marriott International

Housekeeping Attendant Job at Marriott International

 ...POSITION SUMMARY Our jobs aren't just about giving guests a clean room and a freshly made bed. Instead, we want to build an experience that is memorable and unique. Our Guest Environment Experts are skilled in a wide range of housekeeping functions with responsibility... 

Global

Structures Mechanic Job at Global

 ...heavy aircraft maintenance or modifications experience*Repairs and overhaul airframe experience*Repair structures components and composites repairs*Ability to read and interpret SB,EO SRM*Ability to layout work using bend radius, set back/bend allowance charts and... 

Pacific Aviation

Airline Customer Service Agent SFO - Chinese/English Speakers Job at Pacific Aviation

 ...Pacific Aviation is hiring bilingual Airline Customer Service Agents at San Francisco International Airport (SFO) to support international...  ...attend 5 days of required computer training Authorized to work in the United States Must pass a background check and drug... 

Worldwide Flight Services

Air Logistics Controller Job at Worldwide Flight Services

 ...locations, 18 countries, and on 5 continents. Are you ready to take off on your next career with us? Job SummaryThe work of an Air Logistics Controller may include any of the following: monitoring inbound/outbound flight activity, computer data input and manual revisions;...