Penetration Tester Expert

$155,000 - $165,000/Yr

Unclassified - McLean, VA

posted 3 months ago

Full-time - Mid Level
McLean, VA

About the position

The Penetration Tester, Expert position is a full-time role based in McLean, VA, requiring a TS/SCI with CI Polygraph security clearance. The primary responsibility of this role is to conduct internal penetration testing and vulnerability assessments across various platforms, including servers, web applications, web services, and databases. The successful candidate will manually exploit and compromise operating systems, web applications, and databases to identify vulnerabilities, misconfigurations, and compliance issues. This role demands a thorough examination of results from web/OS scanners, scans, and static source code analysis, followed by the documentation of findings in comprehensive reports. In addition to technical skills, the position requires the ability to effectively communicate and coordinate with diverse audiences, including developers, system administrators, project managers, and senior government stakeholders. The candidate will be responsible for providing security recommendations tailored to these stakeholders and will need to defend all findings, including the associated risks or vulnerabilities, mitigation strategies, and references. The role also involves writing penetration testing Rules of Engagement (RoE), Test Plans, and Standard Operating Procedures (SOP), as well as conducting security reviews and technical research to enhance security defense mechanisms. The ideal candidate will have experience with NIST 800-53 and the Risk Management Framework, along with a strong foundation in security practices and principles. This position is critical in ensuring the security posture of the organization and requires a proactive approach to identifying and mitigating potential security threats.

Responsibilities

  • Conduct internal penetration testing and vulnerability assessment of servers, web applications, web services, and databases.
  • Manually exploit and compromise operating systems, web applications, and databases.
  • Examine results of web/OS scanners, scans, and static source code analysis.
  • Identify vulnerabilities, misconfigurations, and compliance issues.
  • Write final reports and defend all findings, including risk or vulnerability, mitigation strategies, and references.
  • Meet and coordinate with various audiences, including developers, system administrators, project managers, and senior government stakeholders.
  • Provide security recommendations for developers, system administrators, project managers, and senior government stakeholders.
  • Report vulnerabilities identified during security assessments.
  • Write penetration testing Rules of Engagement (RoE), Test Plans, and Standard Operating Procedures (SOP).
  • Conduct security reviews, technical research, and provide reporting to increase security defense mechanisms.

Requirements

  • TS/SCI with CI Polygraph security clearance.
  • 4 years of experience with a PhD, 8 years with a BS degree, 6 years with a master's degree, 10 years with an AA degree, or 12 years with a high school diploma.
  • Experience in vulnerability assessment.
  • Strong writing skills.
  • Experience with NIST 800-53 and Risk Management Framework.

Nice-to-haves

  • CEH - Certified Ethical Hacker Certification
  • CPT - Certified Penetration Tester
  • Experience with AWS Cloud Security.

Benefits

  • Full-time employment with benefits.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service