Jobs and Careers
CA

Offensive Security Technical Lead

CACI International Inc
999 REMOTE, United States, United StatesRemotefull_timeVerifiedPosted 20 Aug 2026
💰 $231,100/yr($105,100/yr$231,100/yr)

About the role

Job Title: Offensive Security Technical Lead

Job Category: Information Technology

Time Type: Full time

Minimum Clearance Required to Start: None

Employee Type: Regular

Percentage of Travel Required: Up to 25%

Type of Travel: Continental US

* * *


The Opportunity:

CACI is seeking an Offensive Security Technical Lead to own technical delivery across the penetration-testing and red-team workstreams. This position will provide continuous technical assessment support for full‑time, proactive testing of externally and internally visible federal cyber assets. This expands federal visibility by conducting continual assessments of .gov domains, subdomains, and internet‑facing assets to uncover unknown exposures, validate vulnerabilities, and provide agencies with actionable remediation guidance.  

This role supports the Continuous Diagnostics and Mitigation (CDM) Program’s mission to safeguard and secure cyberspace in an environment where the threat of cyber-attack is continuously growing and evolving and is responsible for enhancing the security, resilience, and reliability of the Nation’s cyber and communications infrastructure.  The CDM Program defends the United States (U.S.) Federal Information Technology (IT) networks from cybersecurity threats by providing continuous monitoring sensors (tools), diagnosis, mitigation tools, and associated services to strengthen the security posture of Government networks.

Responsibilities:
The Technical Lead establishes methodology, approves complex plans and rules of engagement, governs technical risk, allocates specialized expertise across concurrent assessments, resolves escalations, and accepts final technical deliverables while remaining credible and hands-on with offensive-security tradecraft.

  • Serve as the senior technical authority for penetration testing and red-team delivery across the RFS portfolio; maintain alignment among customer objectives, authorization, safety, methodology, staffing, and deliverables.
  • Define and mature assessment standards, rules-of-engagement patterns, technical review gates, evidence requirements, severity methodology, reporting expectations, and reusable playbooks.
  • Review and approve engagement plans, adversary scenarios, infrastructure designs, tooling exceptions, exploitation approaches, data-handling controls, and high-risk technical actions.
  • As a Technical Lead you lead the team for guidance, assign scarce specialties, mentor staff, conduct technical readiness reviews, and resolve complex cross-domain problems.
  • Provide hands-on support for the most difficult network, application, Active Directory/identity, cloud, exploit-development, adversary-infrastructure, and defense-evasion challenges.
  • Own final technical quality and acceptance for assessment reports, attack-path narratives, severity decisions, remediation recommendations, customer out-briefs, and purple-team scenarios.
  • Lead technical customer discussions, communicate mission and business risk, and coordinate with project management on schedule, staffing, dependencies, and issue escalation without assuming administrative PM ownership.
  • Capture lessons learned, measure technical quality and repeatability, and evolve the capability as customer processes and tools become known.


Qualifications:

Required: 

U.S. citizenship is required.

  • No security clearance is required to begin employment. As a condition of continued employment, the selected candidate must meet eligibility requirements for access to sensitive or classified information and be able to obtain a Department of Homeland Security Entrance on Duty (DHS EOD) authorization.
  • Ability to work in customer-provided remote environments, use customer-approved tools, and comply with rules of engagement, data-handling requirements, evidence controls, deconfliction procedures, and stop-work criteria.
  • Eight or more years of progressively responsible offensive-security experience, including significant hands-on penetration testing and red-team/adversary-emulation delivery.
  • Five or more years leading complex technical engagements, multiple concurrent assessments, or senior offensive-security teams.
  • Expert ability to scope and govern safe testing across enterprise networks, applications/APIs, Windows/Active Directory and identity, Linux, AWS/Azure, external attack surfaces, and production environments.
  • Demonstrated technical authority in rules of engagement, operational risk, deconfliction, exploit validation, evidence quality, severity decisions, report acceptance, and customer out-briefing.
  • Strong scripting, automation, or tool-

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

CACI International Inc

View company profile →