2

Remote Pentest Jobs in Washington (NOW HIRING)

Direct Hire / Perm Work Model: 99% remote with occasional onsite for meetings Security Clearance ... CompTIA PenTest+ * CAP/CGRC * CISSP * CISM * Knowledge, Skills, and Abilities Strong analytical ...

Direct Hire / Perm Work Model: 99% remote with occasional onsite for meetings Security Clearance ... CompTIA PenTest+ * CAP/CGRC * CISSP * CISM * Knowledge, Skills, and Abilities Strong analytical ...

Direct Hire / Perm Work Model: 99% remote with occasional onsite for meetings Security Clearance ... CompTIA PenTest+ * CAP/CGRC * CISSP * CISM * Knowledge, Skills, and Abilities Strong analytical ...

Direct Hire / Perm Work Model: 99% remote with occasional onsite for meetings Security Clearance ... CompTIA PenTest+ * CAP/CGRC * CISSP * CISM * Knowledge, Skills, and Abilities Strong analytical ...

Bethesda, MD (mostly remote, occasional onsite required) Work schedule: 40 hrs/week Compensation ... CompTIA Security+, CySA+, PenTest+, CASP+ * CEH * Microsoft SC-900 * System One, and its ...

Bethesda, MD (mostly remote, occasional onsite required) Work schedule: 40 hrs/week Compensation ... CompTIA Security+, CySA+, PenTest+, CASP+ * CEH * Microsoft SC-900 * System One, and its ...

Bethesda, MD (mostly remote, occasional onsite required) Work schedule: 40 hrs/week Compensation ... CompTIA Security+, CySA+, PenTest+, CASP+ * CEH * Microsoft SC-900 * System One, and its ...

Bethesda, MD (mostly remote, occasional onsite required) Work schedule: 40 hrs/week Compensation ... CompTIA Security+, CySA+, PenTest+, CASP+ * CEH * Microsoft SC-900 * System One, and its ...

Remote Pentest information

What is a remote pentest?

A Remote Pentest, or remote penetration test, is a security assessment where ethical hackers evaluate the vulnerabilities of an organization's IT systems from a location outside of the physical premises. This process simulates cyberattacks to identify and exploit weaknesses in networks, applications, or other digital assets, all conducted over the internet. Remote pentesting helps organizations discover security gaps that could be exploited by real attackers, enabling them to strengthen their defenses without the need for on-site visits. It is an efficient and cost-effective way to assess security, especially for companies with remote or distributed infrastructures.

What are the key skills and qualifications needed to thrive as a remote pentester, and why are they important?

To thrive as a Remote Pentester, you need a strong background in network security, vulnerability assessment, and ethical hacking, often supported by a degree in computer science or cybersecurity and relevant certifications like OSCP or CEH. Familiarity with penetration testing tools such as Metasploit, Burp Suite, and Nmap, as well as secure remote collaboration platforms, is essential. Strong problem-solving skills, attention to detail, and effective written communication are crucial soft skills for documenting findings and advising clients remotely. These competencies are vital for identifying security risks, delivering actionable insights, and maintaining client trust in a distributed work environment.

What are some common challenges faced by remote pentesters, and how can they overcome them?

Remote pentesters often encounter challenges such as limited direct access to client environments, communication barriers with client teams, and ensuring secure handling of sensitive data. To overcome these, they typically use VPNs and secure remote desktop tools, maintain clear and regular communication through scheduled meetings and detailed reporting, and follow strict data protection protocols. Building strong relationships with client IT teams and staying updated on remote testing best practices also help ensure effective and compliant assessments.

What is the difference between Remote Pentest vs Vulnerability Analyst?

AspectRemote PentestVulnerability Analyst
CertificationsOSCP, CEH, GPENOSCP, CEH, CISSP
Work EnvironmentProject-based, client sites or remoteOffice or remote, mainly analysis-focused
Industry UsageCybersecurity, consulting firmsIT departments, security teams
Job FocusSimulating attacks to find vulnerabilitiesIdentifying and prioritizing security weaknesses

Remote Pentests involve actively testing systems for vulnerabilities through simulated attacks, often requiring offensive skills. Vulnerability Analysts focus on identifying and assessing security flaws, typically through scanning and analysis. While both roles require cybersecurity knowledge and certifications like OSCP or CEH, Remote Pentesters are more offensive and hands-on, whereas Vulnerability Analysts are more analytical and reporting-oriented.

What job categories do people searching Remote Pentest jobs in Washington look for?

The top searched job categories for Remote Pentest jobs in Washington are:

What cities in Washington are hiring for Remote Pentest jobs?

Cities in Washington with the most Remote Pentest job openings:

Infographic showing various Remote Pentest job openings in Washington as of August 2026, with employment types broken down into 89% Full Time, 2% Part Time, and 9% Contract. Highlights an 63% Physical, 8% Hybrid, and 29% Remote job distribution.

RMF IT Security Analyst

System One

Bethesda, MD • Remote

Full-time

Medical, Dental, Vision, Life, Retirement

Posted 26 days ago


Job description

Job Title: RMF IT Security Analyst Location: Bethesda, Maryland Type: Direct Hire / Perm Work Model: 99% remote with occasional onsite for meetings Security Clearance: Public Trust Position Summary The RMF IT Security Analyst serves as a mid-level cybersecurity professional. Working under Lead and Senior RMF personnel, the analyst independently supports RMF lifecycle activities, security assessments, continuous monitoring, and compliance initiatives while mentoring junior staff. Work is primarily remote with occasional on-site meetings. Key Responsibilities

  • Support the implementation and maintenance of the NIST RMF program.
  • Develop, review, and maintain RMF documentation including SSPs, SARs, POA&Ms, and authorization packages.
  • Support system categorization, security control selection, assessments, authorization, and continuous monitoring.
  • Maintain the Risk Management Register and track remediation activities.
  • Support cybersecurity audits and assessments conducted by NIH, HHS, OIG, GAO, and other oversight organizations.
  • Support Cybersecurity Supply Chain Risk Management (C-SCRM) activities, including vendor documentation and SBOM reviews.
  • Manage or assist with Risk Mitigation Waivers, documentation, approvals, annual reviews, and tracking.
  • Coordinate contingency plan testing and document results and corrective actions.
  • Communicate risk posture and compliance status while collaborating with system owners, ISSOs, and technical teams.
  • Provide technical guidance and mentoring to junior analysts.
Required Qualifications Bachelor's degree in a related technical field (or equivalent experience) and 3–5 years supporting RMF, cybersecurity compliance, or information security programs. Preferred Qualifications
  • Experience supporting federal civilian agencies, including NIH, HHS, or other Federal agencies.
  • Familiarity with NIST RMF, NIST SP 800-37, NIST SP 800-53 Rev. 5, and the Joint Cybersecurity Assessment Methodology (JCAM).
  • Experience using eMASS or similar Governance, Risk, and Compliance (GRC) platforms.
  • Experience supporting cybersecurity audits, POA&M management, continuous monitoring, and contingency planning.
  • Knowledge of Cybersecurity Supply Chain Risk Management (C-SCRM).
  • Experience developing or reviewing SSPs, SARs, SAPs, POA&Ms, and Authorization Packages.
Desired Certifications
  • ISC2 Certified in Cybersecurity (CC)
  • CompTIA Security+
  • CompTIA CySA+
  • CompTIA SecurityX (formerly CASP+)
  • CompTIA PenTest+
  • CAP/CGRC
  • CISSP
  • CISM
  • Knowledge, Skills, and Abilities Strong analytical, organizational, and communication skills with knowledge of RMF processes, documentation, and federal cybersecurity compliance. Ability to collaborate with system owners, ISSOs, and technical teams. Work Environment This position is primarily remote with occasional on-site meetings or support activities as required.

System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.

System One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law.

#M-2 #LI-CB5 Ref: #856-Baltimore-S1


System One logo

About System One

Sourced by ZipRecruiter

System One helps employers get work done more efficiently and economically without compromising quality. Over our 35+ year history, we've helped connect thousands of talented people with innovative companies. The excitement of a perfect fit motivates us every single day.

Industry

Business consulting services and recruiting and staffing services

Company size

5,001 - 10,000 Employees

Headquarters location

Pittsburgh, PA, US