Job Details

ID #19634855
Estado Distrito de Columbia
Ciudad Washington
Tipo de trabajo Permanent
Salario USD TBD TBD
Fuente Dunhill Professional Search
Showed 2021-09-15
Fecha 2021-09-15
Fecha tope 2021-11-13
Categoría Etcétera
Crear un currículum vítae

Senior Penetration Tester

Distrito de Columbia, Washington, 56901 Washington USA

Vacancy caducado!

Senior Penetration Tester

Hybrid Schedule - DC

Top Secret Clearance Required

Enforces application security in all phases of the software development life cycle. Works closely with team members to define application security best practices, performs software architecture and design reviews, and supports the identification, interpretation, and remediation of vulnerabilities across a variety of applications, programming languages, and platforms.

Job Responsibilities:

  • Develop rules of engagement, and configure, tune, and operate industry standard pen test assessment tools.
  • Coordinate, schedule, and support pen test requests.
  • Emulate adversary tactics, techniques, and procedures (TTPs) to validate security controls effectiveness; develop rules of engagement, brief partners on findings and mitigation techniques.
  • Analyze pen test reports and produce summary guidance for System Owners and administrators.
  • Develop, capture, and deliver summary metrics of pen test activities.
  • Draft and deliver executive and technical briefings on pen testing related topics.
  • Emulate adversary tactics, techniques, and procedures (TTPs) to validate security controls efficacy.
  • Perform penetration test assessments of DOE assets and evaluate findings to determine applicability, saturation, and potential impact.
  • Monitor remediation efforts of findings and communicate progress to stakeholders and advise System Owners and Administrators of findings to provide remediation guidance.
  • Work with Information System Security Officers (ISSOs) and System Owners to develop Plan of Action & Milestones (POA&Ms) or formalized exceptions to document findings.

Minimum Qualifications:

  • Bachelor's Degree in Computer Science, Engineering, or other Engineering or Technical discipline or equivalent relevant experience. Master's Degree preferred.
  • 5-10 years of experience as an Application Security Developer, Application Security Analyst, or equivalent.
  • Washington, DC Work Location (potential for part-time remote / hybrid work schedule) and a minimum 25% Travel Requirement (CONUS).
  • Candidate should have operational familiarity with current team tools: Nipper, Nessus, Netsparker, Knowbe4, Burpsuite Pro; Maltego; Canvas; Core Impact, Cobalt Strike.
  • Must be a US Citizen possessing an active TS Security Clearance.

Vacancy caducado!

Suscribir Reportar trabajo