Penetration Tester, Mid

$60,300 - $137,000/Yr

Booz Allen Hamilton - Huntsville, AL

posted 3 months ago

Part-time,Full-time - Mid Level
Remote - Huntsville, AL
1,001-5,000 employees
Professional, Scientific, and Technical Services

About the position

As a Penetration Tester at Booz Allen, you will play a key role in supporting both remote and onsite testing efforts of client networks to identify and expose weaknesses in security. Your primary responsibility will be to maintain baseline system security in accordance with organizational policies, while also monitoring and evaluating the effectiveness of the enterprise's cybersecurity safeguards to ensure they provide the intended level of protection. You will collaborate with stakeholders to resolve computer security incidents and ensure compliance with vulnerability standards. Additionally, you will be tasked with identifying, assessing, and recommending cybersecurity products for use within systems, ensuring that these products adhere to the organization's evaluation and validation requirements. In this role, you will leverage your experience in penetration testing, utilizing various security testing tools such as Burp Suite, SQLMap, Nmap, Nessus, Metasploit, and Cobalt Strike. You will conduct penetration testing across networks, applications, and external environments, and create detailed Technical Assessment Reports that outline your findings and remediation efforts. A solid understanding of penetration test methodologies is essential, as is the ability to keep up with the latest vulnerability information sources, including alerts, advisories, and bulletins. Your role will also involve creating Rules of Engagement (ROE), test plans, and scripts to facilitate testing efforts. You will conduct web application and API penetration testing, analyze network hardware devices and functions, and apply network traffic analysis methods. Knowledge of defense evasion techniques in enterprise environments, incident categories, and identity and access management protocols will be crucial to your success. Excellent verbal communication and organizational skills are necessary to effectively convey your findings and collaborate with team members and clients.

Responsibilities

  • Support remote and onsite testing efforts of a client's network to expose weaknesses in security.
  • Maintain baseline system security according to organizational policies.
  • Monitor and evaluate the effectiveness of the enterprise's cybersecurity safeguards.
  • Work with stakeholders to resolve computer security incidents and ensure vulnerability compliance.
  • Identify, assess, and recommend cybersecurity products for use within a system, ensuring compliance with evaluation and validation requirements.
  • Create Technical Assessment Reports detailing findings and remediation efforts.
  • Conduct penetration testing across networks, applications, and external environments.
  • Create Rules of Engagement (ROE), test plans, and scripts to aid in testing efforts.
  • Conduct web application and API penetration testing.
  • Analyze network hardware devices and functions, and apply network traffic analysis methods.

Requirements

  • 1+ years of experience with penetration testing.
  • Experience with security testing tools such as Burp Suite, SQLMap, Nmap, Nessus, Metasploit, or Cobalt Strike.
  • Experience with penetration testing methodologies for network, application, and external environments.
  • Ability to create Technical Assessment Reports detailing findings and remediation efforts.
  • Knowledge of penetration test methodology.
  • Possession of a Secret clearance.
  • Bachelor's degree or 3+ years of experience in a cybersecurity or system administrator role in lieu of a degree.

Nice-to-haves

  • Experience creating Rules of Engagement (ROE), test plans, and scripts to aid in testing efforts.
  • Experience conducting web application and API penetration testing.
  • Knowledge of defense evasion in enterprise environments and custom payload generation.
  • Knowledge of incident categories, incident responses, and timelines for responses.
  • Knowledge of network access, identity, and access management such as public key infrastructure, Oauth, OpenID, SAML, and SPML.
  • Possession of GWAPT, GPEN, OSCP, or CRTP certifications.

Benefits

  • Flexible spending account
  • Health insurance
  • Retirement plan
  • Tuition reimbursement
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service