Cti-md logo

Penetration Tester - CLEARANCE and POLYGRAPH REQUIRED

Cti-md Fort Meade, Maryland, United States

onsite

Salary: 80% employer pa

Posted Nov 6, 2025

Role & seniority: Senior Cybersecurity/Penetration Tester (contract); must hold TS/SCI with active polygraph

Stack/tools: Burp Suite, Web Inspect, AppDetective, Kali; web app pentest and security tools; programming/scripting: Python, PowerShell, C, JavaScript, Java, XML, Perl, HTML; familiarity with IPS/IDS; Cyber Kill Chain; Risk Management Framework

Top 3 responsibilities

  • Conduct web application, API, and physical penetration testing; perform IT security risk assessments

  • Develop and implement mitigation strategies; collaborate with technical staff and customers for modernization and legacy integration

  • Manage multiple projects simultaneously and adapt to shifting priorities; apply RMF and secure configurations

Must-have skills

  • US citizenship; TS/SCI clearance with active polygraph (poly within last 5 years)

  • 12+ years of relevant experience; penetration testing tool expertise

  • Web development/programming experience (Java, XML, Perl, HTML) and scripting (Python, PowerShell, C, JavaScript)

  • Strong familiarity with Burp Suite, WebInspect, AppDetective; Kali; IPS/IDS; Cyber Kill Chain; RMF; secure OS configurations

  • Ability to collaborate with stakeholders and manage multiple projects

Nice-to-haves

  • Technical degree; certifications such as GWAPT, GPEN, CEH, CISM, GWEB, CISSP

  • Experience in integrated security services management, IA for application development, and firewall-related evaluations

  • Location & work type: Multiple contra

Full Description

Cyber Kill Chain methodology, Risk Management Framework, Burp Suite, Web Inspect, Appdetective, Python, Powershell, C, JavaScript, Java, XML, Perl and HTM

Due to federal contract requirements, United States citizenship and an active TS/SCI security clearance and polygraph are required for the position.

\n

Required

  • Must be a US Citizen.
  • Must have TS/SCI clearance w/ active polygraph (Polygraph must be within the last five (05) years).
  • Must have at least twelve (12) years of relevant experience.
  • Must have experience with penetration testing tools.
  • Must have experience in web development and programming languages such as Java, XML, Perl and HTML.
  • Must have experience with programming/scripting in Python, Powershell, C, JavaScript, etc.
  • Must have extensive experience performing IT security risk assessments.
  • Must have experience performing web app and physical pentests.
  • Must have experience with or strong familiarity of the following Web Application tools; Burp Suite, Web Inspect, Appdetective.
  • Must have experience with or strong familiarity of Kali.
  • Must have experience with or strong familiarity of IPS/IDS solutions.
  • Must have a strong understanding of the Cyber Kill Chain methodology.
  • Must have experience applying Risk Management Framework.
  • Must have experience with secure configurations of commonly used desktop and server operating systems.
  • Must have the ability to effectively collaborate with technical staff and customers to form mitigation strategies and plan for continuous modernization and legacy integration.
  • Must have experience managing multiple projects simultaneously and quickly and effectively adjusting to shifting priorities in resolving issues.

These Qualifications Would Be Nice to Have

  • Bachelor's degree in a technical/information assurance field.

Certifications in one or more of the following areas strongly preferred

  • GIAC Web Applications Penetration Tester (GWAPT)
  • GIAC Penetration Tester (GPEN)
  • Certified Ethical Hacker (CEH)
  • Certified Information Security Manager (CISM)
  • Certified Web Application Defender (GWEB)
  • Certified Information System Security Professional (CISSP)
  • Extensive experience developing/implementing integrated security services management processes, such as assessing and auditing network penetration testing, anti-virus planning assistance, risk analysis, and incident response.
  • Extensive experience providing information assurance support for application development that includes system security certifications and project evaluations for firewalls that encompass development, design, and implementation.​

\n $170,000 - $180,000 a year The pay range for this job, with multi-levels, is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law. \n

The benefits package

  • Affordable healthcare options with 80% employer paid premium PLUS a company-funded HSA

  • Dental insurance with 100% employer paid premium

  • Vision with 80% employer paid premium

  • Employer paid Life insurance 100%

  • Employer paid Short-term and Long-term disability 100%

  • Annual training, continued education, and professional memberships reimbursement

  • Unlimited access to Red Hat Enterprise Linux and AWS training and accreditation

  • Annual reimbursement for technology i.e. phones, computers, printers, etc.

  • 401(k) with company match up to 5% with 100% immediate vesting (after 90 days of employment)

The environment and perks

  • Professional development investment and paid time off for training

  • Contract and work locations in Maryland, Virginia, Colorado, Texas, Utah, Florida and Hawaii.

  • Team building events throughout the year such as Destination Family Events, Holiday Party, Monthly Get-Togethers

  • Leadership Team engagement and mentorship

  • Performance Recognition Program

  • Complimentary branded apparel

Don't see a job opening that's the perfect fit? Apply to our General Position to join our talent pool for consideration for future opportunities. Know someone else who may be a good fit? Refer them through the CTI External Referral Program and you could receive a one-time referral bonus of up to $10,000! Email cti-staffing@cti-md.com for more information. Constellation Technologies is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, religion, creed, color, national origin, ancestry, sex (including pregnancy, childbirth, breastfeeding, or medical conditions related to pregnancy, childbirth, or breastfeeding), age, medical condition, marital or domestic partner status, sexual orientation, gender, gender identity, gender expression and transgender status, mental disability or physical disability, genetic information, military or veteran status, citizenship, low-income status or any other status or characteristic protected by applicable law. Job applicants can submit questions about CTI’s equal employment opportunity policy to cti-hr@cti-md.com.

Penetration TestingCyber Kill ChainRisk Management FrameworkBurp SuiteWeb InspectAppdetectivePythonPowershellCJavaScriptJavaXMLPerlHTMLIT Security Risk AssessmentsWeb Application Securitymulti-location

Cookies & analytics consent

We serve candidates globally, so we only activate Google Tag Manager and other analytics after you opt in. This keeps us aligned with GDPR/UK DPA, ePrivacy, LGPD, and similar rules. Essential features still run without analytics cookies.

Read how we use data in our Privacy Policy and Terms of Service.