576 Penetration Testers jobs in the United States

Senior Vulnerability Assessment Specialist

14211 Buffalo, New York M&T Bank

Posted 16 days ago

Job Viewed

Tap Again To Close

Job Description

_This role offers a hybrid work schedule at our Buffalo, NY Tech Hub_
**Overview:**
Responsible for conducting detailed analysis of vulnerabilities and recommendations on remediation plans to ensure the integrity and resilience of organization's security and information systems. Serves as senior experienced vulnerability analyst by auditing analysis and reports, serving as an escalation point, and training newer/less-experienced analysts.
**Primary Responsibilities:**
+ Refine testing methodologies for vulnerability scanning to provide comprehensive risk-based view of potential vulnerabilities and may lead implementation of new methodologies within team.
+ Create configuration scanning plans that ensure compliance with internal policies and best practices; lead configuration scanning of most systems and networks and build remediation plan for identified vulnerabilities.
+ Organize monitoring techniques to monitor database activities and performance and manage responses to detected issues with cross-functional team.
+ Lead analysis of active and network vulnerability scans to identify potential exploits, misconfigurations, and attacks; partner with cross-functional team to execute remediation plans.
+ In partnership with technology and risk, develop vulnerability management policies and standards and educate technology teams on how integrate into to developing, deploying, and monitoring infrastructure.
+ Design infrastructure testing frameworks that ensure technology teams are developing and deploying infrastructure in alignment with policies and standards.
+ Formulate and recommend advanced best practices to technology teams on how to improve or implement new security practices, tools, and techniques based on industry standards and latest vulnerabilities to protect the bank from vulnerabilities.
+ Produce and interpret advanced reporting with recommendations for cybersecurity and technology leadership, including but not limited to audit reports identifying technical and procedural findings, common vulnerability score, and datasets for regulatory reporting.
+ Understand and adhere to the Company's risk and regulatory standards, policies, and controls in accordance with the Company's Risk Appetite. Design, implement, maintain, and enhance internal controls to mitigate risk on an ongoing basis. Identify risk-related issues needing escalation to management.
+ Promote an environment that supports belonging and reflects the M&T Bank brand.
+ Maintain M&T internal control standards, including timely implementation of internal and external audit points together with any issues raised by external regulators as applicable.
+ Complete other related duties as assigned.
**Scope of Responsibilities:**
+ Partners with peers, manager, cybersecurity organization, technology teams, people leaders, and line of business teams
+ Determines and develops approach to solutions. Work is accomplished with periodic check-ins for alignment and limited direction. Work is evaluated upon completion to ensure objectives have been met.
+ Advanced knowledge of all vulnerability scanning and assessment tools
+ Advanced understanding of multiple vulnerability scanning and assessment tools
+ Subject matter expert understanding of industry best practices related to vulnerability and patch management.
+ Trains analyst to advanced level knowledge of vulnerability scanning and assessment tools, and industry best practices.
+ Second highest individual contributor escalation point in team
**Manager Responsibilities:**
No supervisory responsibilities.
**Education and Experience Required:**
+ Bachelor's degree and a minimum of 3 years' relevant work experience, or in lieu of a degree, a combined minimum of 7 years' higher education and/or work experience
+ Excellent written and verbal communication skills
+ Strong ability to effectively communicate technical information to both non-technical and technical stakeholders, including up to senior leadership in Cybersecurity.
+ Experience effectively collaborating with leadership and with peers across the organization.
+ Prior experience with and demonstrable aptitude for quickly learning new technical skills.
**Education and Experience Preferred:**
+ Advanced certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Global Information Assurance Certification (GIAC), OffSec Certified Professional (OSCP), or Cybersecurity domain-related industry-recognized certification (DoD Level II)
+ Demonstrated experience working in a highly regulated industry (e.g., finance, healthcare, government)
+ Experience evaluating, analyzing, and synthesizing large quantities of data (which may be fragmented and contradictory) and accurately determining the potential range and scope of threats and contributing towards intelligence reporting.
+ Proficient level of thinking critically and solving problems
+ Intermediate understanding of advanced vulnerability concepts and practices, such as vulnerability management solutions, asset identification and management, and mitigation management
+ Experience training analysts to ensure they have intermediate knowledge of and how to use security monitoring systems.
#LI-JB3 #Hybrid
M&T Bank is committed to fair, competitive, and market-informed pay for our employees. The pay range for this position is $93,581.10 - $155,968.51 Annual (USD). The successful candidate's particular combination of knowledge, skills, and experience will inform their specific compensation.
**Location**
Buffalo, New York, United States of America
M&T Bank Corporation is an Equal Opportunity/Affirmative Action Employer, including disabilities and veterans.
View Now

Vulnerability Assessment (VA) Team Lead

20147 Ashburn, Virginia TekSynap

Posted 16 days ago

Job Viewed

Tap Again To Close

Job Description

**Responsibilities & Qualifications**
**ACTIVITIES & RESPONSIBILITIES**
Assist the Government in managing Enterprise Information System Vulnerability Management (ISVM) compliance validation; briefing leadership on current and future vulnerabilities, security policies and industry standards; briefing leadership on most impactful vulnerabilities, configurations, and penetration testing efforts; creating and managing all scans in accordance with the scan standardization documentation; performing regularly scheduled (monthly and ad hoc) vulnerability assessments using a master schedule as directed; managing, customizing, and maintaining scan policies, zones, and repositories as they relate to the network; performing scan functions and review scan results to ensure accurate findings; and creating and customizing scan reports and data feeds to be imported / integrated into third party assessment tools. Assist the Government in employing ad hoc or emergency VA scanning to support targeted incident investigation, escalation, and emergency response to security events in accordance with documented procedures. Assist the Government in performing Penetration Testing Support.
**SKILLS**
+ Analyzing vulnerabilities and providing assessments and remediation instructions
+ Knowledgeable to maintain a repository of VA application issues and report application issues to Government VAT Team Lead and SSD Director in applying Information Systems Security principles and methods
+ Experience with Application Security implementation
+ Understanding of Firewall Management and Advanced Threat Protection
+ Familiarity with Access Control, Authorization, Intrusion Prevention and Intrusion Detection
+ Familiar with Protocol Analysis and requirements when handling sensitive and classified Information
+ Familiar with FISMA compliance and Risk Management Framework
+ Support Cyber Briefs for all vulnerability assessment team activities.
+ Assist the Government in providing Vulnerability Assessment, Compliance, and Reporting support to ISSO / ISSM interpreting scan results and recommend remediation plans.
+ Experience with cloud- based security technologies, architecture, and computing and searching, monitoring, and analyzing machine-generated big data is preferred.
**REQUIRED QUALIFICATIONS**
+ Clearance requirement: Secret
+ Experience: Minimum of 5 years' experience performing vulnerability assessments for an enterprise network
+ Education: Bachelor's of Science in computer engineering, computer science, IT or cyber security preferred (or 5 years of relevant work experience in lieu of a degree)
+ Certifications: one of the following certifications: Certified Information Security Manager (CISM) or Certified Information Systems Security Professional (CISSP)
**Overview**
We are seeking an experienced **Vulnerability Assessment (VA) Team Lead** in support of a government customer to join our team to provide Security Operations Support (SOC) Services to a government agency whose mission is to protect our Nation's borders from terrorist attacks, to provide law enforcement for over forty (40) Federal agencies, and to protect the revenue of the United States while facilitating trade. The SOC is a single point of management and reporting for information security incidents. The SOC exists to prevent, identify, contain, and eradicate cyber threats to networks through monitoring, intrusion detection, and protective security services to information systems, including local area networks / wide area networks (LAN / WAN), commercial Internet connection, public facing websites, wireless, mobile / cellular, cloud, security devices, servers, and workstations. The SOC is responsible for the overall security of Enterprise-wide information systems and collects, investigates, and reports any suspected and confirmed security violations.
TekSynap is a fast-growing high-tech company that understands both the pace of technology today and the need to have a comprehensive well planned information management environment. "Technology moving at the speed of thought" embodies these principles - the need to nimbly utilize the best that information technology offers to meet the business needs of our Federal Government customers.
We offer our full-time employees a competitive benefits package to include health, dental, vision, 401K, life insurance, short-term and long-term disability plans, vacation time and holidays.
Visit us at .
Apply now to explore jobs with us!
The safety and health of our employees is of the utmost importance. Employees are required to comply with any contractually mandated Federal COVID-19 requirements. More information can be foundhere ( .
By applying to a role at TekSynap you are providing consent to receive text messages regarding your interview and employment status. If at any time you would like to opt out of text messaging, respond "STOP".
"As part of the application process, you agree that TekSynap Corporation may retain and use your name, e-mail, and contact information for purposes related to employment consideration".
**Additional Job Information**
**WORK ENVIRONMENT AND PHYSICAL DEMANDS**
The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of the job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.
+ Location: Ashburn Virginia
+ Remote or In-Person: 100% On site. Remote/Telework not available.
+ Type of environment: Office
+ Noise level: Medium
+ Work schedule: Schedule is day shift Monday - Friday.
+ Amount of Travel: Some travel may be required
**PHYSICAL DEMANDS**
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
**WORK AUTHORIZATION/SECURITY CLEARANCE**
Top Secret (SCI eligible)
**OTHER INFORMATION**
Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice.
TekSynap is a drug-free workplace. We reserve the right to conduct drug testing in accordance with federal, state, and local laws. All employees and candidates may be subject to drug screening if deemed necessary to ensure a safe and compliant working environment.
**EQUAL EMPLOYMENT OPPORTUNITY**
In order to provide equal employment and advancement opportunities to all individuals, employment decisions will be based on merit, qualifications, and abilities. TekSynap does not discriminate against any person because of race, color, creed, religion, sex, national origin, disability, age, genetic information, or any other characteristic protected by law (referred to as "protected status"). This nondiscrimination policy extends to all terms, conditions, and privileges of employment as well as the use of all company facilities, participation in all company-sponsored activities, and all employment actions such as promotions, compensation, benefits, and termination of employment.
**Job Locations** _US-VA-Ashburn_
**ID** _ _
**Category** _Technical Support/Help Desk_
**Type** _Regular Full-Time_
View Now

Cybersecurity Consultant, Application Vulnerability Assessment - Tenable & AppSec

78683 McNeil, Texas Dell Technologies

Posted 16 days ago

Job Viewed

Tap Again To Close

Job Description

**Cybersecurity Consultant, Application Vulnerability Assessment - Tenable & AppSec**
The Dell Security & Resiliency organization manages the security risk across all aspects of Dell's business. You will have an excellent opportunity to influence the security culture at Dell and further develop your career.
Join us as a Cybersecurity Consultant, Application Vulnerability Assessment Subject Matter Expert (SME) on our Cybersecurity Engineering and Operations team in Round Rock, Texas, to do the best work of your career and make a profound social impact.
**What you'll achieve**
In this role, you'll lead efforts to identify and assess vulnerabilities across Dell Technologies' systems before they can be exploited. You'll design and implement security assessment tools for networks, applications, and infrastructure, both on-premises and in the cloud, using modern technologies like containers and infrastructure as code. Acting as a technical expert and coordinator, you'll mentor team members and collaborate across functions to enhance Dell's Application Security discovery and detection capabilities, helping shape the company's security culture and drive continuous improvement.
**You will:**
+ Lead and expand the AppSec Vulnerability Assessment program, driving cross-functional engagement and aligning with enterprise security goals and industry best practices.
+ Architect and implement scalable solutions and automation for identifying and remediating web and API vulnerabilities across diverse environments.
+ Act as the strategic SME and liaison for engineering and business teams, providing technical leadership and mentoring junior staff.
+ Integrate Tenable and DAST capabilities into CI/CD pipelines to enable automated, continuous security validation within DevSecOps workflows.
+ Drive adoption of DAST and related technologies, delivering risk-based vulnerability insights for executive decision-making.
+ Establish and maintain security testing capabilities within Federal environments to meet regulatory and compliance requirements.
**Take the first step towards your dream career**
**Every Dell Technologies team member brings something unique to the table. Here's what we are looking for with this role:**
**Essential Requirements**
+ 8+ years of experience in Vulnerability Management, Application Security, or related security engineering roles, with proven leadership in multi-domain security initiatives.
+ Expert in the entire Tenable platform and suite with hands-on expertise with leading vulnerability scanning tools (e.g., Burp Suite, AppScan, Tenable, Prisma Cloud) and strong understanding of OWASP Top 10, secure coding practices, and threat modelling.
+ Proficiency in scripting and automation (Python, Bash, or similar) to enhance scanning capabilities and streamline workflows.
+ Experience engaging senior leadership and cross-functional teams, with strong communication, presentation, and data visualization skills to deliver actionable insights and executive dashboards.
+ Proven ability to thrive in a fast-paced, dynamic environment, balancing strategic planning with hands-on execution.
**Desirable Requirements**
+ Experience securing cloud and containerized environments, with knowledge of best practices and relevant tools.
+ Strategic and abstract thinking skills, including Design Thinking and business acumen, to influence security strategy and risk management decisions.
+ Familiarity with Agile methodologies and IT Service Management workflows, including JIRA and related tools.
**Compensation**
Dell is committed to fair and equitable compensation practices. The salary range for this position is $170,000 - $220,000.
**Benefits and Perks of working at Dell Technologies**
Your life. Your health. Supported by your benefits. You can explore the overall benefits experience that awaits you as a Dell Technologies team member - right now at MyWellatDell.com
**Who we are**
We believe that each of us has the power to make an impact. That's why we put our team members at the center of everything we do. If you're looking for an opportunity to grow your career with some of the best minds and most advanced tech in the industry, we're looking for you.
Dell Technologies is a unique family of businesses that helps individuals and organizations transform how they work, live and play. Join us to build a future that works for everyone because Progress Takes All of Us.
Dell Technologies is committed to the principle of equal employment opportunity for all employees and to providing employees with a work environment free of discrimination and harassment. Read the full Equal Employment Opportunity Policy here ( .
#LI - Onsite
**Job ID:** R
View Now

FLEX Application Security Testing Analyst

20814 Bethesda, Maryland Marriott

Posted 2 days ago

Job Viewed

Tap Again To Close

Job Description

**Additional Information**
**Job Number**
**Job Category** Information Technology
**Location** Marriott International HQ, 7750 Wisconsin Avenue, Bethesda, Maryland, United States, 20814VIEW ON MAP ( Full Time
**Located Remotely?** N
**Position Type** Management
This is a temporary position.
The Application Security Testing Analyst will support the assessment and improvement of Web, API, Mobile application security through hands-on security testing and code analysis. The ideal candidate will have a solid foundation in secure coding practices, vulnerability detection, and testing techniques such as SAST, DAST, and manual testing. This role is designed to offer practical experience in application security testing, with opportunities to work directly with development teams, security tools, and automation in real-world environments.
**CANDIDATE PROFILE**
**Education and Experience**
**Required:**
+ Bachelor's degree in Cybersecurity, Computer Science or related field or equivalent experience/certification
+ 2+ years of information technology or application development experience
+ Strong understanding of programming concepts (e.g., loops, data types, logic, input/output)
+ Basic experience or familiarity with application security testing tools (e.g., Burp Suite, OWASP ZAP, Fortify, Veracode)
+ Understanding of the OWASP Top 10 and common application vulnerabilities (e.g., XSS, SQLi, CSRF)
+ Basic knowledge of vulnerability triage and remediation processes
+ Familiarity with version control (e.g., Git), CI/CD concepts, and the SDLC
+ Proficiency in Microsoft Word, PowerPoint, and Excel
+ Excellent communication skills
**Preferred:**
+ Master's degree in Cybersecurity, Computer Science, or related field or equivalent experience/certification
+ Security certifications (e.g., GWAPT, OSCP, CEH, Security+, or CySA+)
+ 2+ years of experience in an application security, QA, or software testing role
+ Experience performing web application penetration testing or source code review
+ Exposure to secure SDLC practices and integrating testing into CI/CD pipelines
+ Understanding of risk scoring frameworks (e.g., CVSS) and security ticketing workflows
+ Familiarity with compliance standards such as PCI-DSS, NIST 800-53, or ISO 27001
**CORE WORK ACTIVITIES**
**Application Security Risk Management & Tracking**
+ Application Security Testing & Risk Analysis
+ Assist with static and dynamic application security testing (SAST/DAST) using tools such as CodeQL, Trivy, Dependency Check, SonarQube, and Burp Suite
+ Perform basic manual testing and validation of vulnerabilities in development and pre-production environments
+ Support secure code reviews under supervision, identifying potential security flaws in application logic or design
+ Collaborate with software developers to provide guidance on secure coding practices and vulnerability remediation
+ Triage vulnerability reports and escalate findings based on severity and impact
+ Assist in the integration of security testing tools into CI/CD pipelines and automated testing environments
+ Contribute to the development of test cases and security use cases based on threat modeling or abuse case analysis
+ Support documentation of findings, test results, and risk assessments in systems such as JIRA or ServiceNow
+ Help maintain dashboards and reporting for tracking vulnerability trends and remediation status
+ Stay current on emerging security vulnerabilities, exploits, and application security best practices
+ Work closely with the Senior Manager to continuously improve the testing processes and tool coverage
+ Participate in knowledge sharing and security training initiatives with development teams
The pay range for this position is $33.94 to $53.46 per hour.
FLEX opportunities offer coverage for medical, dental, vision, health care flexible spending account, dependent care flexible spending account, life insurance, disability insurance, accident insurance, adoption expense reimbursements, paid parental leave, 401(k) plan, stock purchase plan, discounts at Marriott properties, commuter benefits, employee assistance plan, and childcare discounts. Benefits are subject to terms and conditions, which may include rules regarding eligibility, enrollment, waiting period, contribution, benefit limits, election changes, benefit exclusions, and others.
Marriott HQ is committed to a hybrid work environment that enables associates to Be connected. Headquarters-based positions are considered hybrid, for candidates within a commuting distance to Bethesda, MD.
_Marriott International is an equal opportunity employer. We believe in hiring a diverse workforce and sustaining an inclusive, people-first culture. We are committed to non-discrimination on any protected basis, such as disability and veteran status, or any other basis covered under applicable law._
Marriott International is the world's largest hotel company, with more brands, more hotels and more opportunities for associates to grow and succeed. **Be** where you can do your best work, **begin** your purpose, **belong** to an amazing global team, and **become** the best version of you.
View Now

Penetration Tester

75215 Park Cities, Texas Syntricate Technologies

Posted today

Job Viewed

Tap Again To Close

Job Description

Penetration Tester

Location: Dallas, TX or Tampa, FL

Type: Contract

Desirable Skills:

  • Assisting in technical scoping of security testing activities
  • Curation and assessment of vulnerability data (across multiple platforms/tools) from a manual penetration perspective, to focus on true exploitation.
View Now

Penetration Tester

92713 Irvine, California Hamilton Porter

Posted 5 days ago

Job Viewed

Tap Again To Close

Job Description

Base pay range

$140,000.00/yr - $170,000.00/yr

Role Overview

Under the direction of the Manager of Information Security, the Penetration Test Engineer will protect the company and its subsidiaries from cyberattacks, safeguarding sensitive data, the company brand, and business operations. This critical role includes performing penetration tests, identifying vulnerabilities, conducting risk assessments, developing and testing incident response procedures, and collaborating with internal and external teams to enhance companywide security posture.

Key Responsibilities
  • Conduct penetration tests across web/business applications, servers, APIs, mobile apps, networks, cloud environments, and connected vehicles.
  • Document vulnerabilities with technical reports detailing risk levels and remediation recommendations.
  • Lead or participate in all phases of penetration testing: Reconnaissance, Scanning, Vulnerability Assessment, Exploitation, Remediation, and Reporting.
  • Develop and maintain security incident response policies; lead table-top exercises and forensic investigations.
  • Stay current on emerging security threats and the tools/methods to mitigate them.
  • Collaborate with business units and external service providers to implement security enhancements.
Qualifications
  • Bachelors degree or equivalent experience in information security; advanced degrees or certifications a plus.
  • 8+ years in organizations with mature security practices.
  • 3+ years conducting hands-on penetration tests and vulnerability management; Red Team experience preferred.
  • 3+ years in information security incident response, cybersecurity, or IT risk management.
  • Experience with security auditing, compliance regulations, and evidence collection.
  • Experience in penetration testing on vehicles is a plus.
  • Success in CTF competitions and/or bug bounty programs is highly desirable.
  • Skilled in IT infrastructure, security components, scripting (Python), and penetration testing tools (Burp Suite, Kali Linux, Metasploit, John the Ripper, Nmap, Wireshark, OWASP ZAP, Aircrack-ng, Tenable Nessus, etc.).
  • Excellent communication, leadership, and organizational skills.
Preferred Attributes
  • High emotional intelligence for effective collaboration and stakeholder communication.
  • Proactive, self-motivated, and able to lead multiple concurrent initiatives.
  • Expertise in SIEM, attack chains, emerging threats, and security monitoring best practices.
Why Join
  • Work in a fast-paced, innovative environment shaping the future of mobility.
  • Competitive compensation and benefits package.
  • Opportunities for professional growth and cross-functional collaboration.
Employment type
  • Full-time
Job function
  • Quality Assurance and Engineering
Industries
  • Motor Vehicle Manufacturing, Information Services, and Technology, Information and Media

#J-18808-Ljbffr
View Now

Penetration Tester

77592 Texas City, Texas PSG Global Solutions

Posted 5 days ago

Job Viewed

Tap Again To Close

Job Description

Penetration Tester

Computer Futures is a leading IT recruitment consultancy, specializing in placing IT experts in permanent and contract roles across the US, Europe, and Asia.

With a proven track record in IT recruitment, we enjoy success within all sectors and business types, placing a candidate every 38 minutes. From single job vacancies to large-scale projects, our proficiency in providing exceptional professionals across the board has carved our reputation as a secure and significant supplier partner.

A robust and financially strong business, we have grown organically from our first office in London in 1986, to 7 offices across the US including: New York, Boston, Chicago, San Diego, San Francisco, Houston, and Austin. We also have 18 offices in Europe including: Amsterdam, Brussels, Dublin, Edinburgh, Frankfurt, Hamburg, Munich and Paris.

Passionate about recruitment, our 350+ specialist IT recruitment consultants' priority is to secure the right person for the right role, within a specified timeframe and budget. Through Computer Futures' methodology, our consultants who are there to help provide you with the best service and support whatever your IT requirement is we pride ourselves on our quality of candidates, our speed of delivery and the ability to provide a bespoke service to meet our individual clients' recruitment needs.

-Min 3 years of experience penetration/vulnerability testing for web and applications in an enterprise environment

-Automated and manual testing experience

-Strong understanding of web technologies, e.g. HTTP, HTML, CSS, Forms, Database Connectivity, etc.

-Understanding of compliance and regulatory requirements such as PCI DSS, SOX, HIPAA, etc.

James Benjamin H. Ilagan

Computer Futures

View Now
Be The First To Know

About the latest Penetration testers Jobs in United States !

Penetration Tester

07175 Newark, New Jersey Cardinal Security LLC

Posted 5 days ago

Job Viewed

Tap Again To Close

Job Description

Newark, United States | Posted on 01/10/2025

We are seeking a highly skilled and experienced Senior Penetration Tester to join our cybersecurity team. This individual will lead complex penetration testing activities, conduct advanced red team engagements, and thoroughly assess our clients networks, applications, and systems for vulnerabilities. The ideal candidate is a seasoned security professional with a passion for uncovering weaknesses before adversaries can exploit themand a knack for communicating technical findings to both technical and non-technical audiences.

Key Responsibilities

Advanced Penetration Testing

  • Execute sophisticated penetration tests against web applications, networks, cloud environments, and mobile platforms.
  • Perform in-depth reconnaissance, exploit development, and post-exploitation activities to fully gauge security weaknesses.
  • Collaborate with stakeholders to identify high-risk areas and design targeted testing strategies.
  • Evaluate potential attack vectors, assess impact, and prioritize remediation steps based on industry best practices.

Red Team Engagements

  • Plan and lead complex red team operations, simulating real-world attack scenarios that encompass social engineering, physical intrusion, and cyber infiltration tactics.
  • Coordinate with purple team exercises to help stakeholders detect, respond to, and recover from simulated attacks.

Reporting & Documentation

  • Prepare clear, detailed reports outlining findings, remediation guidance, and risk assessments.
  • Communicate results effectively to executives, security teams, and developers, ensuring stakeholders fully understand threats and mitigation strategies.

Technical Leadership & Mentorship

  • Serve as a subject matter expert for junior testers, guiding them in methodologies, tooling, and emerging threat techniques.
  • Stay current with new offensive security tools, vulnerability trends, and threat landscapes, sharing knowledge to enhance team capabilities.

Security Program Enhancement

  • Advise clients and internal teams on best practices for security architecture, secure coding standards, and incident response.
  • Contribute to the continuous improvement of penetration testing methodologies, processes, and internal tools.
Requirements

Education & Certifications

  • Bachelors degree in Computer Science, Cybersecurity, or equivalent work experience.
  • Relevant certifications such as OSCP, OSCE, GPEN, GXPN, or CEH strongly preferred.

Experience

  • Minimum of 5 years hands-on penetration testing experience, with a proven track record of finding complex vulnerabilities.
  • In-depth knowledge of common frameworks (OWASP Top 10, MITRE ATT&CK, NIST) and industry-standard tools (Burp Suite, Metasploit, etc.).
  • Experience with programming/scripting in languages such as Python, Go, or PowerShell for exploit development and automation.

Security Clearance

  • Current or active government security clearance is strongly preferred .
  • Applicants able to obtain or maintain a clearance may also be considered.

Technical & Soft Skills

  • Proficiency in network protocols, operating systems (Windows, Linux, macOS), and cloud environments (AWS, Azure, GCP).
  • Familiarity with containerized environments (Docker, Kubernetes) and DevSecOps principles.
  • Strong analytical and problem-solving abilities, with excellent attention to detail.
  • Effective communication and presentation skills for delivering technical results to non-technical audiences.
Desired Attributes
  • Adaptability Able to quickly pivot to new technologies, frameworks, and attack vectors.
  • Collaboration Comfortable working cross-functionally and guiding teams through advanced security scenarios.
  • Curiosity Passion for researching cutting-edge offensive security tactics and pushing boundaries to identify critical vulnerabilities.

#J-18808-Ljbffr
View Now

Penetration Tester

Missouri, Missouri Diverse Lynx

Posted 9 days ago

Job Viewed

Tap Again To Close

Job Description

Essential Skills:
  • Expertise in web application security testing
  • Experience in security testing with SAST, SCA, DAST, IAST, Fuzz and penetration testing tools
  • Expertise in mobile application security testing
  • Expertise in Web application firewall
  • Hands-on experience with DevSecOps tools and practices, including static code analysis, security scans, and automated testing.
  • Understanding of application security standards such as OWASP ASVS/Top 10 and CWE 25
  • Ability to Client and patch SQLi, XSS, CSRF, SSRF, authentication and authorization flaws, and other web-based security vulnerabilities (OWASP Top 10 and beyond).
  • Knowledge of common authentication technologies including OAuth, SAML, CAs, OTP/TOTP.
  • Experience with security tools like Fortify, CheckMarx, VeraCode, BurpSuite, Snyk, Nessus
  • Familiar with tools like Git, Jenkins, CircleCI, Maven, Ant, Gradle, Nexus, SonarQube, Artifactory, Chef, Splunk
  • Strong knowledge of cryptography, API security, and secret management
  • Security certifications such as OSCP
  • Excellent interpersonal and communication skills, with the ability to work effectively with all levels of management.
  • Knowledge of payments domain

Diverse Lynx LLC is an Equal Employment Opportunity employer. All qualified applicants will receive due consideration for employment without any discrimination. All applicants will be evaluated solely on the basis of their ability, competence and their proven capability to perform the functions outlined in the corresponding role. We promote and support a diverse workforce across all levels in the company.
View Now

Penetration Tester

23450 Virginia Beach, Virginia Imagine One Technology and Management Ltd

Posted 9 days ago

Job Viewed

Tap Again To Close

Job Description

Imagine One is currently seeking multiple candidates for positions supporting the U.S. Navy at Naval Surface Warfare Center Dahlgren Division (NSWCDD). We are looking for Senior Penetration Tester to provide engineering support for Cyber Situational Awareness (SA), Cyber Command and Control (C2), Mission Assurance, and Homeland Defense in Virginia Beach, Virginia. Work will be performed on-site in Virginia Beach, Virginia.
Experience Requirements:
The Senior Penetration Tester shall have experience with technical processes and technical management processes in support of comprehensive test and evaluation associated with test support, operational verification of installations and support efforts for Developmental Test and Evaluation (DT&E), Operational Test and Evaluation (OT&E), and Penetration testing (PEN testing) to include the following duties:

  • Provide support by utilizing experience working with Entra ID (Azure AD), Active Directory, SSO, MFA, Azure application integration, Identity Federation
  • Provide support by utilizing experience in automation using PowerShell, PowerAutomate, Logic Apps, Graph API
  • Provide support by utilizing experience working with Microsoft Entra ID and Microsoft 365 in a hybrid environment
  • Provide support by utilizing experience extending or integrating on premises AD with Entra ID
  • Provide support by utilizing experience managing identity and access in Microsoft Entra ID
  • Provide support by utilizing experience conducting Red Team operations in an MDE environment
  • Provide support by utilizing experience with AWS, Cloud Audit, Serverless and Microservice Architecture
  • Provide support utilizing experience working with AWS services (such as EC2, S3, KMS, RDS) and security best practices relevant to those service
  • Provide support by performing web application and API penetration testing, and Cloud Security Audits
  • Provide support by utilizing experience with Web Services penetration testing (RESTful and SOAP) Web Authentication protocols (e.g., OAuth2, SAML, LDAP)
  • Providing support by writing proof of concept code to demonstrate the severity of a potential security issues
  • Provide support by utilizing working knowledge with scripting languages (e.g., Python, Perl, PHP, Ruby)
  • Provide support by utilizing working knowledge with Programming language (e.g., C, Java, Python, JavaScript)
Qualifications:
  • Minimum of 8 years with BS/BA; Minimum of 6 years with MS; Minimum of 3 years with PhD
  • Shall have a minimum of five (5) years of experience in penetration testing and/or offensive Cyber operations
  • Shall have demonstrated experience utilizing penetration tools
  • Shall have demonstrated experience in mimicking threat behavior
  • Demonstrated experience performing vulnerability assessments with the Assured Compliance Assessment Solution tool
  • Demonstrated experience with performing STIG assessments to include using SCAP benchmarks
  • Demonstrated experience utilizing packet analyzer tools such as Wireshark and tcpdump
  • Certifications: CEH or GSEC or Security+
  • Minimum certification as 541 (or similar as required by the Technical Instruction) at the Intermediate level per DoDD , or successor
  • Offensive Security Certified Professional (OSCP) or Offensive Security Certified Expert (OSCE) or Offensive Security Exploitation Expert (OSEE) or Offensive Security Wireless Professional (OSWP) certification required
  • Ability to travel up to 10 percent
Security Requirements:
  • ACTIVE Top Secret/SCI DoD Clearance Required (no interim)


Imagine One Technology & Management, Ltd., offers a full package of benefits and competitive salary, excellent group medical, vision, and dental programs. 401K savings plan; $4K annual tuition reimbursement ($5K if pursuing master's degree); employee training, development, and education programs; profit sharing; advancement opportunities; and much more!

ISO 9001:2015, ISO 2000-1:2018, ISO 27001:2013
CMMI Development and Services - Maturity Level 3
An Employee-Owned Business

EEO/Veterans/Disabled

*Imagine One "Contingent" offers for employment may stipulate that one or more requirements be satisfied before final commitment between candidate and Imagine One is established; namely, award of contract to the Imagine One Team. Contingent requirements vary and may also include, but not be limited to additional factors (i.e., the position still being available after negotiations with the Government; final approval of your qualifications by the Government; or ability to successfully acquire and/or transfer a DoD security clearance).
View Now
 

Nearby Locations

Other Jobs Near Me

Industry

  1. request_quote Accounting
  2. work Administrative
  3. eco Agriculture Forestry
  4. smart_toy AI & Emerging Technologies
  5. school Apprenticeships & Trainee
  6. apartment Architecture
  7. palette Arts & Entertainment
  8. directions_car Automotive
  9. flight_takeoff Aviation
  10. account_balance Banking & Finance
  11. local_florist Beauty & Wellness
  12. restaurant Catering
  13. volunteer_activism Charity & Voluntary
  14. science Chemical Engineering
  15. child_friendly Childcare
  16. foundation Civil Engineering
  17. clean_hands Cleaning & Sanitation
  18. diversity_3 Community & Social Care
  19. construction Construction
  20. brush Creative & Digital
  21. currency_bitcoin Crypto & Blockchain
  22. support_agent Customer Service & Helpdesk
  23. medical_services Dental
  24. medical_services Driving & Transport
  25. medical_services E Commerce & Social Media
  26. school Education & Teaching
  27. electrical_services Electrical Engineering
  28. bolt Energy
  29. local_mall Fmcg
  30. gavel Government & Non Profit
  31. emoji_events Graduate
  32. health_and_safety Healthcare
  33. beach_access Hospitality & Tourism
  34. groups Human Resources
  35. precision_manufacturing Industrial Engineering
  36. security Information Security
  37. handyman Installation & Maintenance
  38. policy Insurance
  39. code IT & Software
  40. gavel Legal
  41. sports_soccer Leisure & Sports
  42. inventory_2 Logistics & Warehousing
  43. supervisor_account Management
  44. supervisor_account Management Consultancy
  45. supervisor_account Manufacturing & Production
  46. campaign Marketing
  47. build Mechanical Engineering
  48. perm_media Media & PR
  49. local_hospital Medical
  50. local_hospital Military & Public Safety
  51. local_hospital Mining
  52. medical_services Nursing
  53. local_gas_station Oil & Gas
  54. biotech Pharmaceutical
  55. checklist_rtl Project Management
  56. shopping_bag Purchasing
  57. home_work Real Estate
  58. person_search Recruitment Consultancy
  59. store Retail
  60. point_of_sale Sales
  61. science Scientific Research & Development
  62. wifi Telecoms
  63. psychology Therapy
  64. pets Veterinary
View All Penetration Testers Jobs