This one is closed
Live roles like this one
-
C
6h ago
Werkstudent (m/w/d) Schwachstellenmanagement: Von der SBOM zur Entscheidung
Langlauf Security Automation GmbH Lippstadt
-
C
22h ago
Senior Security Engineer, Identity and Access Management
HackerOne Netherlands, UK, USA
- D 19h ago
- C 1d ago
See every "Mid Level Penetration" role →
Get new “Mid Level Penetration” roles by email
One email a day with what is new in "Mid Level Penetration". Nothing new, no email.
We confirm the address first, and every mail carries an unsubscribe link. Alerts are ours, not a third party's.
Why this grade This listing scored 63/100, which is a C. It lost the most ground on pay transparency. See the breakdown
- Description depth 20 / 20 How much the posting actually says about the work, measured in characters of real text.
- Freshness 12 / 15 How recently it was posted. Older postings are likelier to be filled or abandoned.
- Pay transparency 12 / 25 A published salary range, worth more than any other single factor because it is what a candidate cannot find out without applying.
- Remote clarity 8 / 15 Whether "remote" means anywhere, or is quietly restricted to one country.
- Role specificity 6 / 10 Whether the listing is tagged well enough to tell what the role actually is.
- Corroboration 5 / 10 Whether more than one source carries this listing.
Every figure above is arithmetic over the posting itself — its salary field, its text, its age, its tags and how many sources carry it. How the grades work →
This listing does not state a salary
$112k – $155k
That is the middle half of what comparable roles paid on this board over the last 90 days — 50 listings that did publish a figure, median $136k. It is not this employer's offer, and we have no idea what they pay. It is only what the rest of the market advertised.
Developer Mid level Full Time
Description
Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.
Dragonfli Group is seeking a Mid-Level Penetration Tester to join a consolidated enterprise Penetration Testing program supporting a large federal agency. In this fully remote role, you will plan and execute authorized penetration tests across network, endpoint, wireless, database, application, and infrastructure environments, following structured Planning, Discovery, Testing, and Reporting phases. You will develop Rules of Engagement, Execution Plans, and decision-ready reporting, coordinate directly with system owners and SOC personnel to confirm scope and safety thresholds, and validate exploitable conditions arising from misconfigurations, outdated software, and weak access controls. You will also support validation of CISA WAS and FAST findings, KEV exposure items, and coordinate retesting to confirm closure, using approved AI-enabled tools to improve reconnaissance and ATT&CK/ATLAS mapping while maintaining human oversight. This role calls for approximately 5 to 8 years of relevant experience leading or independently executing penetration testing engagements.
This is a multi-year contract position involving a large US federal agency. Candidates with previous federal contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.
This is a fully remote position.
Key Responsibilities:
- Plan and execute authorized penetration tests across network, endpoint, wireless, database, application, and infrastructure environments using structured Planning, Discovery, Testing, and Reporting phases.
- Develop and tailor Rules of Engagement, Execution Plans, daily status updates, and final reporting inputs for assigned assessments.
- Coordinate with system owners, SOC personnel, and other stakeholders to confirm scope, test windows, prerequisites, safety thresholds, and stop/pause procedures.
- Validate vulnerabilities arising from misconfigurations, outdated software, weak access controls, incomplete control implementation, and exploitable attack paths.
- Support validation of CISA WAS, CISA FAST, KEV exposure, and external-facing asset findings, and coordinate retesting to confirm closure.
- Use approved automated and AI-enabled tools to improve reconnaissance, testing efficiency, ATT&CK/ATLAS mapping, evidence development, and reporting while maintaining human oversight.
Requirements
Must-Have
- U.S. Citizenship or Permanent Residency (required for this federal engagement)
- Approximately 5 to 8 years of experience conducting or leading penetration testing engagements
- Demonstrated ability to plan and execute assessments across network, endpoint, wireless, database, application, and infrastructure environments
- Experience developing Rules of Engagement, Execution Plans, and formal, decision-ready reporting for stakeholders
- Experience coordinating directly with system owners and SOC personnel on scope, safety thresholds, and stop/pause procedures
- Ability to work fully remote with reliable, secure connectivity
Preferred / Nice-to-Have
- Previous federal contracting experience
- Experience with CISA WAS, CISA FAST, and KEV validation and retest workflows
- Familiarity with MITRE ATT&CK and ATLAS mapping
- Advanced certifications such as OSCP, OSCE, GPEN, or GXPN
- Experience integrating AI-enabled tools into testing workflows while maintaining human oversight of results
Skill(s)
Technical Skills
- End-to-end penetration testing across network, endpoint, wireless, database, application, and infrastructure environments
- Rules of Engagement and Execution Plan development
- Vulnerability validation and exploit chain analysis
- CISA WAS/FAST and KEV validation and retesting
- MITRE ATT&CK/ATLAS mapping and AI-enabled testing tools
Soft Skills
- Stakeholder coordination with system owners and SOC teams
- Clear, decision-ready written and verbal reporting
- Sound judgment around safety thresholds and stop/pause procedures
- Ability to lead an assessment independently with minimal oversight
- Mentorship of junior testing staff
Benefits
- Dragonfli Group offers a comprehensive benefits package that includes:
- Medical, Multiple POS health plan options including an HSA-compatible plan
- Dental, PPO coverage for preventive, basic, and major services
- Vision, Annual exam, frames, lenses, and contact lens allowance
- 401(k), Employer match up to 5% of eligible compensation
- Long-Term Disability, 100% employer-paid coverage at 50% of pre-disability earnings
- Life Insurance and AD&D, 100% employer-paid coverage valued at $10,000 each
- PTO, 15 to 25 days annually based on tenure
- Paid Federal Holidays, All 11 federal holidays observed
Originally posted on Himalayas
Apply for this role Opens himalayas.app — the link as listed; we have not yet verified it is the employer's own page
Quick question · anonymous · one tap
Would you apply to this job?
Answer to see what other job seekers said.
Your turn · no account needed
Help the next applicant
You may know something about this listing that we cannot see from here. One tap. No account needed. Signed-in reports earn points once the evidence agrees with you.
I know what it pays
Sign in with Google to earn points for reports — 100 confirmed points buy a week of Early Access.
Where this listing came from
- 19 Sep 2026 Himalayas first sighting
Seen on 1 board over 0 days.