1

Penetration Testing Government Jobs in Tennessee

Vulnerability Management Lead

Knoxville, TN · On-site

$97K - $128K/yr

... penetration testing; remediation strategies and stakeholder engagement. . Experience with ... Dependent upon role and/or federal government security clearance requirements, and in accordance ...

Penetration Testing Government information

What is penetration testing in government?

Penetration testing in government refers to authorized simulated cyberattacks on government systems, networks, or applications to identify vulnerabilities before malicious actors can exploit them. These tests help government agencies strengthen their cybersecurity defenses, comply with regulations, and protect sensitive data. Penetration testers use a variety of tools and techniques to mimic real-world cyber threats, ensuring that security measures are effective and up to date.

What are the key skills and qualifications needed to thrive as a penetration tester in a government setting?

To thrive as a Penetration Tester in government, a deep understanding of network security, vulnerability assessment, and common attack methodologies is required, typically supported by a degree in cybersecurity or a related field. Familiarity with tools like Metasploit, Nmap, Burp Suite, and certifications such as OSCP, CEH, or CISSP are highly valued. Strong analytical thinking, attention to detail, and clear written and verbal communication skills distinguish top performers in this role. These skills are vital to effectively identify security weaknesses, communicate risks, and ensure the protection of sensitive government data and infrastructure.

What are some common challenges faced by penetration testers working in government environments?

Penetration testers in government settings often encounter unique challenges, such as navigating strict security protocols, handling sensitive or classified information, and complying with complex regulatory frameworks. They may also work within rigid change management processes, which can impact the speed and flexibility of testing activities. Collaboration with various departments is essential, as testers must communicate findings clearly to both technical and non-technical stakeholders to ensure vulnerabilities are properly understood and remediated.

What is the difference between Penetration Testing Government vs Penetration Testing Private Sector?

AspectPenetration Testing GovernmentPenetration Testing Private Sector
CredentialsCertifications like OSCP, CISSP, CEH often requiredSimilar certifications widely recognized, such as OSCP, CEH, CISSP
Work EnvironmentGovernment agencies, secure facilities, strict protocolsCorporate offices, consulting firms, diverse environments
Employer & Industry UsageFederal, state, or local government agenciesPrivate companies, cybersecurity firms, consulting agencies
Search & Comparison IntentUnderstanding roles within government cybersecurityComparing government vs private sector penetration testing roles

Penetration Testing Government professionals focus on securing government systems within strict protocols, often requiring specific certifications and working in secure environments. Private sector penetration testers work with commercial clients, offering more diverse projects and flexible settings. Both roles demand similar skills and certifications but differ mainly in work environment and employer type.

How much do penetration testing government professionals make?

Penetration testing professionals working for government agencies typically earn between $70,000 and $130,000 annually, depending on experience, security clearance level, and location. Advanced skills in cybersecurity tools, certifications like CISSP or CEH, and knowledge of government security protocols can influence salary levels.

Is there a demand for penetration testing government?

There is strong demand for penetration testers in government sectors due to increasing cybersecurity threats and the need to protect sensitive information. These roles often require knowledge of security tools, compliance standards, and certifications such as CEH or CISSP, and may involve working in secure environments with regular updates to security protocols.

What is the average pay for penetration testing government?

Penetration testers working for government agencies typically earn between $70,000 and $120,000 annually, depending on experience, security clearance, and location. Higher salaries are common for those with specialized skills, certifications like OSCP or CISSP, and roles requiring clearance or advanced technical expertise.

What are popular job titles related to Penetration Testing Government jobs in Tennessee?

For Penetration Testing Government jobs in Tennessee, the most frequently searched job titles are:

What job categories do people searching Penetration Testing Government jobs in Tennessee look for?

The top searched job categories for Penetration Testing Government jobs in Tennessee are:

What cities in Tennessee are hiring for Penetration Testing Government jobs?

Cities in Tennessee with the most Penetration Testing Government job openings:

Infographic showing various Penetration Testing Government job openings in Tennessee as of August 2026, with employment types broken down into 92% Full Time, 2% Part Time, and 6% Contract. Highlights an 98% In-person, and 2% Remote job distribution.

Application Security-Penetration Tester

Boston Government Services, LLC

Oak Ridge, TN • On-site

$170K - $200K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 6 hours ago


Job description

Boston Government Services, LLC. (BGS) has created this Evergreen Talent Pool post for gathering qualified candidates for a position relating to Application Security-Penetration Tester to support our clients in various locations across the US.


BGS is an engineering, technology, and security firm helping to advance missions of national importance for government programs, national laboratories, national security facilities, nuclear operations, and complex projects. We support clients at every stage, from strategic planning and program management to the execution of engineering and technical activities. We work to attract and retain the best talent because the best talent delivers the best results for our clients. Our capabilities are based on our experience in complex, secure, and highly regulated environments. We leverage our experience and capabilities to provide mission-driven solutions tuned to our client's mission needs and strategic direction.


Work that Matters. People that Matter More. At BGS, we believe meaningful work starts with great people. We foster a culture built on respect, collaboration, and accountability—where employees are empowered to contribute ideas, grow professionally, and make an impact. We care about our employees’ well-being through competitive benefits, clear expectations, and an environment that values both excellence and connection.


If you align with BGS’ company values and culture, we would love for you to explore opportunities to join our growing team by checking out the job description below!


Responsibilities:

The Application Security-Penetration Tester conducts application, infrastructure, and network security testing to identify exploitable vulnerabilities, validate security controls, support risk reduction, and provide actionable recommendations for client systems.

  • Support development and maintenance of penetration testing rules of engagement, test plans, and testing documentation.
  • Conduct application, network, infrastructure, vulnerability, lateral movement, and related security testing activities.
  • Perform reconnaissance, enumeration, target assessment, vulnerability validation, exploitability analysis, and evidence collection.
  • Use approved commercial and open-source tools to identify and validate vulnerabilities.
  • Prepare draft and final penetration test reports with findings, evidence, access paths, risks, and recommendations.
  • Coordinate kickoff meetings, stakeholder approvals, debriefs, validation testing, and reporting timelines.
  • Identify systemic trends across findings and support security posture improvement recommendations.


Requirements:

  • Bachelor’s Degree or equivalent.
  • Experience conducting penetration tests, vulnerability assessments, application security testing, or technical security assessments.
  • Familiarity with ROE development, test planning, exploitability validation, vulnerability scanning, web application security, network testing, and report writing.
  • Knowledge of OWASP, NIST, CVSS, secure configuration, and common attack techniques.
  • Ability to communicate findings clearly to technical and non-technical stakeholders.
  • Must be a U.S. citizen.
  • Successful drug screening.
  • Must be eligible to obtain and maintain a security or clearance badge.


Preferred Qualifications:

  • OSCP, GPEN, GWAPT, PenTest+, CEH, CISSP, or equivalent.


Location/Work Arrangement:

  • Schedule is full-time, Monday – Friday 40-hour week, 4/10’s, or 9/80’s and may require on call or overnight shifts depending on contract needs.
  • This position may be fully onsite or hybrid/remote depending on the needs of the specific contract.


Benefits:

BGS offers a competitive total compensation package to eligible employees. Benefits include Health, Dental, Vision, Life Insurance, Paid Vacation, 401K, Long and Short-Term Disability.


Starting compensation for this role typical salary ranges between $170,167 – $200,196 annually is commensurate with experience relative to the position and may vary based on candidate geographical location.


EEO:

BGS is an Equal Opportunity/Affirmative Action employer. All qualified applicants are encouraged to apply and will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, or protected veteran status.


Exclusive Agreement Disclaimer:

BGS has standing contracts with federal agencies throughout the United States. We require an affirmative exclusive agreement to represent all candidates to our clients. By submitting this application, you are consenting to allow BGS to represent you as a candidate for the role in which you are applying.


Schedule is full-time, Monday – Friday 40-hour week, 4/10’s, or 9/80’s and may require on call or overnight shifts depending on contract needs.