Allyon Medical - Linthicum Heights, MD

posted 4 months ago

Full-time - Mid Level
Linthicum Heights, MD

About the position

Allyon, Inc. is seeking a skilled Penetration Tester to join our team in Linthicum Heights, MD. This position is primarily remote, but candidates must be local to the DMV area for onboarding purposes. As a Penetration Tester, you will conduct Adversary Emulation Tests (AETs) against Defense Industrial Base (DIB) Partners' external and internal networks. These tests are crucial for assessing the cybersecurity posture and network configurations of our clients, particularly in relation to the processing of Covered Defense Information (CDI). You will leverage adversarial tactics, techniques, and procedures (TTPs) in accordance with an established penetration testing framework to identify vulnerabilities within the network infrastructures of DIB Partners. In this role, you will be responsible for drafting detailed reports based on your assessments, which will require extensive experience in reviewing and examining data that supports cybersecurity evaluations. You will also need to demonstrate a strong understanding of pen testing fundamentals and be proficient in using tools such as Kali Linux, Metasploit, Nessus, and Nmap. Your expertise will be essential in performing authorized penetration testing on enterprise networks, gaining access to targeted networks, and creating exploitation strategies for identified vulnerabilities. This position requires a proactive approach to monitoring target networks and profiling network users or system administrators to ensure comprehensive security assessments. This is a temporary position expected to last until February 2025, offering competitive pay and benefits, including 401k eligibility after six months with a company match. If you are passionate about cybersecurity and eager to help organizations strengthen their defenses, we encourage you to apply and join the Allyon team!

Responsibilities

  • Conduct Adversary Emulation Tests (AETs) against DIB Partners' external and internal networks.
  • Assess the company's cybersecurity posture and network configurations to identify vulnerabilities.
  • Leverage adversarial tactics, techniques, and procedures (TTPs) in accordance with an established penetration testing framework.
  • Draft written reports based on cybersecurity assessments.
  • Review and examine data and information that supports cybersecurity assessments.
  • Perform authorized penetration testing on enterprise networks.
  • Gain access to targeted networks and maintain access as needed.
  • Provide infrastructure analysis and perform analysis of physical and logical digital technologies.
  • Conduct in-depth target and technical analysis and create exploitation strategies for identified vulnerabilities.
  • Monitor target networks and profile network users or system administrators and their activities.

Requirements

  • 5 years of experience with a BS/BA; 3 years with an MS/MA; 0 years with a PhD (additional experience may be used in lieu of a degree).
  • Secret clearance required (TS/SCI preferred).
  • Experience with assessment methods defined in NIST SP 800-30 and NIST SP 800-53A.
  • Experience in drafting written reports.
  • Extensive experience in reviewing and examining data and information that supports cybersecurity assessments.
  • Experience in pen testing fundamentals.
  • Experience in Kali Linux and its toolsets, including Metasploit.
  • Experience in pen testing tools including scanners like Nessus and Nmap.
  • A minimum of three years of experience performing authorized pen testing on enterprise networks.

Nice-to-haves

  • Experience architecting, implementing, and deploying cloud native solutions.
  • Familiarity with containerized development (Docker, Kubernetes).
  • Use Gitlab CI/CD for automated testing and cloud deployments via Helm.
  • SQL/NoSQL database modeling and administration.

Benefits

  • Competitive pay and benefits
  • 401k eligibility after 6 months, including company match
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service