{"id":1948062,"url":"https://alion.io/job/saic-penetration-tester","title":"Penetration Tester","company":{"id":58788,"name":"SAIC","domain":"saic.com","url":"https://alion.io/company/saic","size_band":"5000+","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Oracle","truth_index":{"grade":"B","score":80,"open_postings":54,"ghost_share":0,"stale_share":0.981,"repost_share":0,"time_to_fill_p50_days":12,"computed_at":"2026-10-10T05:45:15Z"}},"role":"Security","role_family":"Security","seniority":"staff","employment_type":null,"work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"posting_text","remote_working_hours":null,"hiring_geo_confidence":"inferred","locations":[],"countries":[],"hiring_countries":["US"],"hiring_countries_total":1,"salary":null,"salary_estimate":{"min_usd":131000,"max_usd":279000,"period":"year","method":"global_role_seniority_cell","sample_n":561},"experience_years_min":9,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Burp Suite","optional":false},{"name":"FFUF","optional":false},{"name":"Frida","optional":false},{"name":"MobSF","optional":false},{"name":"Nuclei","optional":false},{"name":"Objection","optional":false},{"name":"OWASP","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"SQLmap","optional":false},{"name":"GraphQL","optional":true},{"name":"Rest API","optional":true},{"name":"SOAP","optional":true}],"status":"live","first_seen_at":"2026-10-05T16:27:49Z","employer_posted_date":"2026-10-05","last_verified_at":"2026-10-11T17:32:19Z","board_verified":true,"closed_at":null,"days_open":6,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":6},"description":"Science Applications International Corporation (SAIC) is seeking a Penetration Tester to join our offensive security practice supporting a major state & local government customer. This role sits at the intersection of hands-on technical execution and cybersecurity leadership and it's built around delivering real impact for clients who depend on us to find what others miss.\nWeb application & Network penetration testing is the core of what you'll do every day, and we're looking for someone who brings both technical depth and genuine curiosity to every engagement. Beyond web and network pentesting you'll contribute to our mobile application testing practice (iOS and Android), support ethical hacking operations, and provide strategic guidance on enterprise cyber architecture and cloud security. This position reports to the Security Assessments Manager.\nThis is a role where your contributions are visible, your growth is intentional, and your voice matters to the team and to the clients we serve. \nEssential duties of this position include:\nDeliver high-quality penetration tests across a range of client environments, applying black box, white box, web app or mobile methodologies as needed and aligned to NIST standards\n\nIndependently manage engagement workloads from scoping through reporting, with a consistent focus on quality\n\nProduce clear, well-structured technical reports that communicate findings, risk context, and actionable remediation guidance to both technical teams and executive stakeholders and translate complex technical documentation into terms any stakeholder can act on\n\nSupport and contribute to mobile application security assessments (iOS and Android) using the OWASP MASVS/MSTG framework, with the expectation of growing mobile capabilities over time\n\nPerform strategic planning and management in cybersecurity and digital forensics in alignment with the National Initiative for Cybersecurity Education (NICE) Framework\n\nAddress a wide range of security issues including architectures, firewalls, electronic data traffic, and network access\n\nResearch, evaluate, and recommend new security tools, techniques, and technologies; utilize COTS/GOTS and custom tools to scan, identify, contain, mitigate, and remediate vulnerabilities and intrusions\n\nApply expert engineering knowledge to design, develop, and implement security solutions across enterprise engagements\n\nConfidently present findings to clients whether it is walking a developer through a vulnerability chain or explaining business risk to a CISO in the same afternoon\n\nAct as a spokesperson and advisor on advanced technical projects and research; participate with senior management to establish strategic plans and objectives\n\nActively share knowledge with teammates, contribute to internal tooling and methodology improvements, and help close skill gaps across the practice\n\nStay current on emerging vulnerabilities, attack techniques, and industry developments and bring that knowledge back to the team\n\n TYPICAL EDUCATION AND EXPERIENCE:\nBachelors and nine (9) years or more experience; Masters and seven (7) years or more experience; PhD or JD and four (4) years or more related experience. Additional experience considered in lieu of degree. \nCandidates must be a US Citizen and able to pass a CJIS Criminal Justice background investigation and maintain CJIS clearance throughout employment term.\n\nRequired Experience:\nAdvanced technical knowledge in cybersecurity and digital forensics\n\nStrong working knowledge of the OWASP WSTG and OWASP Top 10 - not just the list, but how to find and exploit the vulnerabilities\n\nProficiency with standard web application testing tools (e.g., Burp Suite Pro, FFUF, SQLMap, Nuclei)\n\nWorking familiarity with mobile application testing concepts and tooling (e.g., Frida, Objection, MobSF, ADB)\n\nProven experience in red-teaming, ethical hacking, and cloud security architecture\n\nProficiency in malware reverse engineering and enterprise cyber architecture\n\nStrong background in addressing security issues related to architectures, firewalls, electronic data traffic, and network access\n\nExperience researching, evaluating, and recommending new security tools and technologies\n\nProficiency utilizing COTS/GOTS and custom tools for vulnerability management\n\nDemonstrated ability to write professional, client-ready penetration test reports with minimal revision\n\nGWAPT certification required or strongly preferred; candidates holding OSCP, OSWE, or GWEB will also be considered\n\nPreferred Experience:\n\nHands-on experience conducting iOS and/or Android application assessments\n\nFamiliarity with API security testing (REST, GraphQL, SOAP)\n\nExposure to source code review as part of white box engagements\n\nExperience presenting findings directly to client stakeholders, including senior leadership\n\nParticipation with senior management to establish strategic plans and objectives\n\nExperience working on unusually complex technical problems and providing innovative solutions\n\nProven ability to work under consultative direction toward long-range goals and objectives\n\nExperience serving as an organizational spokesperson and advisor on advanced technical projects\n\nKnowledge of applying advanced technical principles, theories, and concepts to develop new principles and concepts\n\nExperience making decisions on administrative or project work matters to achieve program or organizational objectives\n\nStrong background in developing advanced technological ideas and guiding them to final product development\n\nExperience influencing organizational image and technological capability through decision-making and recommendations","description_format":"text","description_chars":5658,"description_truncated":false,"requirements":{"experience_years_min":9,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Penetration Testing","Digital Government","Systems Integrators","Engineering Services"],"lifecycle":[{"event":"open","at":"2026-10-06T08:16:08Z"}],"visa":[],"liveness":{"score":57,"band":"ok","label":"Likely open","p_open":1,"p_active":0.632,"p_room":0.9,"age_days":4,"expected_fill_days":12,"reasons":["conf:2","stale_co","velocity","win:mid","comp:brand"],"computed_at":"2026-10-10T05:45:15Z"},"pay":null,"html_url":"https://alion.io/job/saic-penetration-tester","json_url":"https://alion.io/job/saic-penetration-tester.json","meta":{"generated_at":"2026-10-11T21:23:02Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler_verified","counted_by":"address","units_charged":1,"used_today":10231,"day_limit":null,"remaining_today":null,"minute_limit":300,"resets_at":"2026-10-12T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":58788},"rest":"https://alion.io/mcp/rest/get_company?id=58788"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fsaic-penetration-tester"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fsaic-penetration-tester"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fsaic-penetration-tester"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/saic-penetration-tester\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fsaic-penetration-tester"}]}