1

Contractual Pentest Jobs (NOW HIRING)

CO · On-site

$82K - $137K/yr

... contractual and regulatory quality requirements, and support readiness for external audits and ... PenTest+ - Security+ (Security+ CE acceptable) - SSCP Notice of Anticipated Employment ...

CO

$82K - $137K/yr

... contractual and regulatory quality requirements, and support readiness for external audits and ... PenTest+ - Security+ (Security+ CE acceptable) - SSCP Notice of Anticipated Employment ...

Contractual Pentest information

See salary details

$39K

$110.3K

$118K

How much do contractual pentest jobs pay per year?

As of Jul 26, 2026, the average yearly pay for contractual pentest in the United States is $110,301.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,000.00 and $116,500.00 per year, depending on experience, location, and employer.
What cities are hiring for Contractual Pentest jobs? Cities with the most Contractual Pentest job openings:
What are the most commonly searched types of Pentest jobs? The most popular types of Pentest jobs are:
What states have the most Contractual Pentest jobs? States with the most job openings for Contractual Pentest jobs include:
Information Systems Security Officer (ISSO) with **DoD Clearance**

Information Systems Security Officer (ISSO) with **DoD Clearance**

Vets, Inc

Scott Air Force Base, IL • Hybrid

Full-time

Posted 13 days ago


Job description

VETS, Inc., is looking to add a mid-level (3-5 years experience) Information Systems Security Officer (ISSO) to our growing team. This is a full-time, permanent position with full benefits located at Scott AFB. Due to contractual requirements, this position required US Citizenship and a current/active DoD Clearance.
The successful candidate will:
  • Own the day-to-day security authorization posture of assigned DoD information systems
  • Work within a well-resourced team with dedicated engineering, operations, and architecture support
  • Develop expertise in modern RMF tooling including eMASS and eMASSer automation
  • Directly support mission continuity by managing ATO packages and continuous monitoring programs
  • Grow into a senior GRC role with clear advancement pathways
Responsibilities
  • Develop, maintain, and update System Security Plans (SSPs) for assigned systems
  • Manage POA&Ms from identification through remediation and closure
  • Compile and submit Authorization to Operate (ATO) packages
  • Conduct continuous monitoring activities per established strategy
  • Utilize eMASS for GRC management and RMF workflow tracking
  • Coordinate with ISSEs and SecOps to validate control implementations
  • Develop Security Assessment Plans (SAPs) and support SAR coordination
  • Draft supply chain risk management plans
  • Support the Cybersecurity Architect with RMF strategic planning

Required:

  • Active Secret or TS clearance
  • 3–5 years of RMF/ATO experience within DoD or federal environments
  • Hands-on experience with eMASS
  • Working knowledge of NIST SP 800-53r5 and DoD RMF processes
  • Demonstrated ability to independently author SSPs and manage POA&Ms
  • DoD 8140.03M DCWF Basic tier certification — CEH
  • DoD 8140 Interim Education Options

Desired

  • DoD 8140.03M DCWF Intermediate tier certification — one of: CEH(P), RCCE Level 1, Cloud+, CPTE, FITSP-A, GCED, GCIH, GCSA, GICSP, GSEC, PenTest+, or Security+
  • Degree in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering
  • Experience with eMASSer or similar RMF automation tooling
  • Exposure to cloud-hosted or hybrid system authorization boundaries
  • Familiarity with the DoD RMF Knowledge Service