Dragonfly AI Logo

Dragonfly AI

Penetration Tester

Posted 18 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in GBR
Senior level
Remote
Hiring Remotely in GBR
Senior level
Plan and independently execute authorized penetration tests across network, endpoint, wireless, database, application, and infrastructure environments. Develop Rules of Engagement, execution plans, status updates, and formal reports; coordinate scope and safety procedures with system owners and SOC teams; validate vulnerabilities and exploit chains; support CISA WAS, FAST, and KEV retesting; apply ATT&CK/ATLAS mapping and AI-enabled tools with human oversight; and mentor junior testers.
The summary above was generated by AI
Description

Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.

Dragonfli Group is seeking a Mid-Level Penetration Tester to join a consolidated enterprise Penetration Testing program supporting a large federal agency. In this fully remote role, you will plan and execute authorized penetration tests across network, endpoint, wireless, database, application, and infrastructure environments, following structured Planning, Discovery, Testing, and Reporting phases. You will develop Rules of Engagement, Execution Plans, and decision-ready reporting, coordinate directly with system owners and SOC personnel to confirm scope and safety thresholds, and validate exploitable conditions arising from misconfigurations, outdated software, and weak access controls. You will also support validation of CISA WAS and FAST findings, KEV exposure items, and coordinate retesting to confirm closure, using approved AI-enabled tools to improve reconnaissance and ATT&CK/ATLAS mapping while maintaining human oversight. This role calls for approximately 5 to 8 years of relevant experience leading or independently executing penetration testing engagements.

This is a multi-year contract position involving a large US federal agency. Candidates with previous federal contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.

This is a fully remote position.

Key Responsibilities:

  • Plan and execute authorized penetration tests across network, endpoint, wireless, database, application, and infrastructure environments using structured Planning, Discovery, Testing, and Reporting phases.
  • Develop and tailor Rules of Engagement, Execution Plans, daily status updates, and final reporting inputs for assigned assessments.
  • Coordinate with system owners, SOC personnel, and other stakeholders to confirm scope, test windows, prerequisites, safety thresholds, and stop/pause procedures.
  • Validate vulnerabilities arising from misconfigurations, outdated software, weak access controls, incomplete control implementation, and exploitable attack paths.
  • Support validation of CISA WAS, CISA FAST, KEV exposure, and external-facing asset findings, and coordinate retesting to confirm closure.
  • Use approved automated and AI-enabled tools to improve reconnaissance, testing efficiency, ATT&CK/ATLAS mapping, evidence development, and reporting while maintaining human oversight.
Requirements

Must-Have

  • U.S. Citizenship or Permanent Residency (required for this federal engagement)
  • Approximately 5 to 8 years of experience conducting or leading penetration testing engagements
  • Demonstrated ability to plan and execute assessments across network, endpoint, wireless, database, application, and infrastructure environments
  • Experience developing Rules of Engagement, Execution Plans, and formal, decision-ready reporting for stakeholders
  • Experience coordinating directly with system owners and SOC personnel on scope, safety thresholds, and stop/pause procedures
  • Ability to work fully remote with reliable, secure connectivity

Preferred / Nice-to-Have

  • Previous federal contracting experience
  • Experience with CISA WAS, CISA FAST, and KEV validation and retest workflows
  • Familiarity with MITRE ATT&CK and ATLAS mapping
  • Advanced certifications such as OSCP, OSCE, GPEN, or GXPN
  • Experience integrating AI-enabled tools into testing workflows while maintaining human oversight of results
Skill(s)

Technical Skills

  • End-to-end penetration testing across network, endpoint, wireless, database, application, and infrastructure environments
  • Rules of Engagement and Execution Plan development
  • Vulnerability validation and exploit chain analysis
  • CISA WAS/FAST and KEV validation and retesting
  • MITRE ATT&CK/ATLAS mapping and AI-enabled testing tools

Soft Skills

  • Stakeholder coordination with system owners and SOC teams
  • Clear, decision-ready written and verbal reporting
  • Sound judgment around safety thresholds and stop/pause procedures
  • Ability to lead an assessment independently with minimal oversight
  • Mentorship of junior testing staff
Benefits
  • Dragonfli Group offers a comprehensive benefits package that includes:
  • Medical, Multiple POS health plan options including an HSA-compatible plan
  • Dental, PPO coverage for preventive, basic, and major services
  • Vision, Annual exam, frames, lenses, and contact lens allowance
  • 401(k), Employer match up to 5% of eligible compensation
  • Long-Term Disability, 100% employer-paid coverage at 50% of pre-disability earnings
  • Life Insurance and AD&D, 100% employer-paid coverage valued at $10,000 each
  • PTO, 15 to 25 days annually based on tenure
  • Paid Federal Holidays, All 11 federal holidays observed
HQ

Dragonfly AI London, England Office

8-14 Vine Hill, London, United Kingdom, EC1R 5DX

Similar Jobs

18 Days Ago
Remote
GBR
Mid level
Mid level
Artificial Intelligence • Machine Learning • Analytics
Supports authorized penetration testing for a federal agency through assessment planning, reconnaissance, enumeration, evidence collection, findings documentation, remediation recommendations, retesting, and reporting. The role also assists with triaging external-facing asset findings, CISA WAS/FAST results, KEV exposures, and VDP submissions. Responsibilities include maintaining schedules and scope records, coordinating stakeholders, tracking actions, and using automation and AI-enabled tools to improve testing and reporting workflows.
Top Skills: Burp SuiteCisa FastCisa WasKnown Exploited Vulnerabilities (Kev)MetasploitNmap
One Month Ago
In-Office or Remote
London, Greater London, England, GBR
Senior level
Senior level
Artificial Intelligence • Cloud • Software • Cybersecurity • Design • Generative AI
The Senior Penetration Tester will conduct penetration testing across various environments, mentor junior testers, and contribute to the development of methodologies.
Top Skills: Active DirectoryBurpsuite ProCheckKali LinuxLinuxNessusNmapPythonShellWindows
4 Hours Ago
In-Office or Remote
Walker-on-Tyne, Newcastle upon Tyne, England, GBR
Entry level
Entry level
Software • Hospitality
Supports hotel food and beverage operations across bars, restaurants, room service, and events. Greets guests, takes and serves orders, prepares tables, maintains clean and organized work areas, and follows health, safety, sanitation, and alcohol-awareness regulations. The casual role offers flexible shifts and opportunities for additional hours.

What you need to know about the London Tech Scene

London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account