Posted on
Penetration Tester
Task description and/or any specific requirements:
• Highly skilled in web application testing, API testing, and network testing
• Prior experience with Burp Suite Professional, or other similar DAST tools
• Experience with AI and penetration testing AI
• Experience with Kali Linux and most of the tools available in the distro for penetration testing
• Experience with tools such as Metasploit Pro and Cobalt Strike for red team operations
• Experience with Red Team engagements from planning to execution
• Experience with phishing network users to gain access for lateral movement on the network
• Experience with Purple Team engagements to test monitoring controls in coordination with engineering teams and CSOC teams.
• Proficiency in scripting, such as Python and/or PowerShell
• Experience with penetration testing supporting PCI-DSS
• Technical writing skills, along with ease in communicating concepts related to security vulnerabilities and attack path scenarios.
• Familiar with OWASP Application Security Verification Standard (ASVS) and MITRE Telecommunication&CK framework
• Penetration testing certification recommended. Acceptable certifications: Offensive Security Certified Professional (OCSP), Global Information Assurance Certification (GIAC) Certifications (e.g., GIAC Certified Penetration Tester (GPEN), GIAC Web Application Penetration Tester (GWAPT), or GIAC Exploit Researcher and Advanced Penetration Tester (GXPN))
Experience:
o A minimum of eight (8) years relevant experience.
o A degree from an accredited College/University in the applicable field of services is required. If the individual's degree is not in the applicable field then four additional years of related experience is required.
Additional Provisions:
• Pass a client mandated clearance process to include drug screening, criminal history check and credit check.
• Once candidate's resume is approved and interview passed, the agency is responsible for providing drug screening. Failure to submit the drug screening results will delay the security clearance process.
• If a candidate is given an interim clearance, continuation of employment is then based on the candidate receiving a sensitive clearance.
• All candidates must be a US Citizen or permanent status Green Card holder.
• Cannot have more than 6 months travel outside the United States within the last five years. Military Service excluded. (Exception does not include military family members.)
• All overtime must be pre-approved in writing by the client manager or his/her designated representative.
• Agency will not be reimbursed for overtime charges without previous written authorization. Authorized overtime will be reimbursed at straight time.
• The enforced dress code is business casual, i.e., collared shirt with slacks for men, no skirts above the knee for women.
Apply now
Task description and/or any specific requirements:
• Highly skilled in web application testing, API testing, and network testing
• Prior experience with Burp Suite Professional, or other similar DAST tools
• Experience with AI and penetration testing AI
• Experience with Kali Linux and most of the tools available in the distro for penetration testing
• Experience with tools such as Metasploit Pro and Cobalt Strike for red team operations
• Experience with Red Team engagements from planning to execution
• Experience with phishing network users to gain access for lateral movement on the network
• Experience with Purple Team engagements to test monitoring controls in coordination with engineering teams and CSOC teams.
• Proficiency in scripting, such as Python and/or PowerShell
• Experience with penetration testing supporting PCI-DSS
• Technical writing skills, along with ease in communicating concepts related to security vulnerabilities and attack path scenarios.
• Familiar with OWASP Application Security Verification Standard (ASVS) and MITRE Telecommunication&CK framework
• Penetration testing certification recommended. Acceptable certifications: Offensive Security Certified Professional (OCSP), Global Information Assurance Certification (GIAC) Certifications (e.g., GIAC Certified Penetration Tester (GPEN), GIAC Web Application Penetration Tester (GWAPT), or GIAC Exploit Researcher and Advanced Penetration Tester (GXPN))
Experience:
o A minimum of eight (8) years relevant experience.
o A degree from an accredited College/University in the applicable field of services is required. If the individual's degree is not in the applicable field then four additional years of related experience is required.
Additional Provisions:
• Pass a client mandated clearance process to include drug screening, criminal history check and credit check.
• Once candidate's resume is approved and interview passed, the agency is responsible for providing drug screening. Failure to submit the drug screening results will delay the security clearance process.
• If a candidate is given an interim clearance, continuation of employment is then based on the candidate receiving a sensitive clearance.
• All candidates must be a US Citizen or permanent status Green Card holder.
• Cannot have more than 6 months travel outside the United States within the last five years. Military Service excluded. (Exception does not include military family members.)
• All overtime must be pre-approved in writing by the client manager or his/her designated representative.
• Agency will not be reimbursed for overtime charges without previous written authorization. Authorized overtime will be reimbursed at straight time.
• The enforced dress code is business casual, i.e., collared shirt with slacks for men, no skirts above the knee for women.