Jobs
>
Beltsville

    Penetration Tester - BELTSVILLE, United States - SAIC Career Site

    SAIC Career Site
    SAIC Career Site BELTSVILLE, United States

    1 week ago

    Default job background
    Technology / Internet
    Description

    Description

    SAIC is seeking a highly motivated Penetration Tester. The successful candidate will provide support to the Cybersecurity Integrity Center (CIC) in the Department of State Bureau of Information Resource Management (IRM). Duties are in the Washington, D.C. metropolitan area (30% in downtown D.C; 70% in Beltsville, MD. The CIC supports cybersecurity monitoring, threat analysis, incident response, and infrastructure remediation within and across all of the State Department's information technology (IT) infrastructure. The CIC coordinates and collaborates with other State Department bureaus as well as other organizations within the Federal Government, and commercial partners.

    The position allows hybrid remote work. Team is currently reporting onsite 3 days per week or more as needed.

    Description of Duties

    The Penetration Tester will provide support for HVA Assessments using methodology by Cybersecurity and Infrastructure Security Agency (CISA) Assessment Evaluation and Standardization (AES) program with broad and in-depth knowledge to conduct offensive cyber operations across the organization globally. In this role, you will conduct offensive security operations to emulate adversary tactics and procedures to test preventative, detective, and response controls across the global technology landscape. The Penetration Tester will:

    • Conduct highly complex offensive security operations testing consistent with known adversary tactics techniques and procedures and contribute to the development of objectives and approaches taken to remediate risk.
    • Apply sound technical and management principles to identify and remediate cybersecurity --vulnerabilities across the State Department global IT enterprise infrastructure.
    • Apply organizational and process change principals.
    • Evaluate system performance results, perform risk assessments, and evaluate performance metrics.

    Responsibilities include:

    • Provide ad-hoc penetration testing and assessment services on Department of State systems identified by the leadership.
    • Develop, Identify and resolve security vulnerabilities related to deployment and testing processes.
    • Streamline and optimize processes and procedures in order to rapidly remediate vulnerabilities from cybersecurity threats.
    • Collaborate with Department and external cyber stakeholders on cybersecurity technology implementations to meet specific operational needs.
    • Perform technical evaluations of recommended vulnerability mitigation actions and make recommendations based on impact and/or other countermeasures.
    • Develop strategies for CIC cyber defense technologies, ensuring integration and alignment for continued operation.
    • Conduct assessments of threats and vulnerabilities; determine deviations from acceptable configurations, enterprise, or local policy; assess the level of risk; and develop and/or recommend appropriate mitigation countermeasures in operational and non-operational situations.
    • Network Mapping include but are not limited to a network map of the organization's system that includes a visual representation of the organization's physical devices and digital network.
    • Perform operation and maintenance activities in support of existing CIC cyber tools and technologies (MSV, Qualys, Tenable Nessus and others).
    • Identify, diagnose, and prioritize anomalies in cyber defense infrastructure and resources.
    • Perform cybersecurity testing of developed applications and/or systems.
    • Identify and direct the remediation of technical problems encountered during testing and implementation of new systems.
    • Document security issues and impacts identified through offensive operations in a clear and concise manner to facilitate reporting to impacted stakeholders.
    • Provide guidance and recommendations to stakeholders responsible for security remediation actions to close identified gaps and remediation validation testing.
    • Independently handle complex issues with minimal supervision, while escalating only the most complex issues to appropriate staff.

    Qualifications

    Required Education & Experience

    • Bachelor's and five (5) years or more experience; Master's and three (3) years or more experience.
    • A degree in Cybersecurity or related field.
    • 4-6+ years penetration testing experience.
    • Web application penetration testing, LPT, Source code vulnerability analysis, serious problem-solving skills experience.
    • All penetration testers/operators must be DHS/CISA AES qualified within 90 days of onboarding.

    Required Clearance

    • US Citizenship.
    • Active Top Secret Clearance

    Desired

    • 4 years Microsoft Operating Systems (OS) engineering and support experience focusing on Active Directory (AD), System Center Configuration Manager (SCCM), System Center Operations Manager (SCOM).
    • 4-6 years Network penetration testing experience.
    • In-depth experience in planning, implementing, and managing large/global enterprise infrastructures.
    • Familiarity of various analytical tools (Splunk, USBDeview, Netwitness, MimiKatz).
    • Understanding of Security Information and Event Management (SIEM) tools (Splunk, McAfee).
    • Familiarity of Cobalt Strike, Nessus, Kali Linux, Burp Suite, Nmap and OpenVAS for databases.
    • Knowledge of general attack stages.
    • Skill in the use of social engineering techniques and using penetration testing tools.
    • Familiarity with OMB, NIST, DHS, and related security guidelines and directives.
    • Interpersonal skills including the ability to collaborate effectively, and excellent written and oral communications.
    • Network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
    • Server/endpoint OS (Microsoft, Linux, IOS) along with mobile and cloud technologies.
    • Cloud application security, Vulnerability Management and Security Information, and Event Management capabilities.
    • Countermeasures / mitigations to identified cybersecurity risks.
    • Knowledge of network protocols such as TCP/IP, Dynamic Host Configuration Protocol (DHCP), domain name system, and directory services.
    • Certifications: LPT (Licensed Penetration Testers, Microsoft Certifications (MCSE, MCSA, MCSD),OSCP (Offensive Security Certification Professional), ISACA Certified Information Systems Auditor (CISA), SCP Security Certified Network Architect (SCNA), ISACA Certified Information Security Manager (CISM)
    SAIC accepts applications on an ongoing basis and there is no deadline.

    Covid Policy: SAIC does not require COVID-19 vaccinations or boosters. Customer site vaccination requirements must be followed when work is performed at a customer site.

  • Professional Stewards Services (PSS), LLC

    Penetration Tester

    3 days ago


    Professional Stewards Services (PSS), LLC Washington, United States

    **Penetration Tester** · **We are seeking an energetic, self-starter to join our growing team.** · **Job Type**: Full-time, 40 hours per week · **Hours**: Monday through Friday · **Salary Range**: $135,000 · **Work location**: Remotely/Virtual · **Requirements**: Must be a US cit ...

  • SAIC

    Penetration Tester

    5 days ago


    SAIC Beltsville, United States

    · SAIC is seeking a highly motivated Penetration Tester. The successful candidate will provide support to the Cybersecurity Integrity Center (CIC) in the Department of State Bureau of Information Resource Management (IRM). Duties are in the Washington, D.C. metropolitan area (30 ...

  • Dark Wolf Solutions

    Penetration Tester

    1 week ago


    Dark Wolf Solutions Herndon, United States

    **Duties/Responsibilities**: · **Required Qualifications**: · - 2+ years' experience in three or more specific areas to include: intelligence analysis, network engineering, networking security, penetration testing, red team operations, hardware engineering, software engineering, ...


  • Infinity Systems Garten, WV, United States Freelance

    **Your task**: · As a **Senior Penetration Tester (m/f/d)**, you will independently advise our business customers at decision-maker and specialist level on all questions of cyber security and cyber defense. · In detail, your range of tasks includes the following areas: · - Indepe ...

  • Delmock Technologies

    Penetration Tester

    1 week ago


    Delmock Technologies Laurel, United States

    · About Our Company: · Join Delmock Technologies, Inc. (DTI), a leading HUBZone business in Baltimore, known for delivering sophisticated IT and Health solutions with a commitment to ethics, expertise, and superior service. Actively engaged in the local community, DTI creates o ...

  • Strategic Analytix

    Penetration Tester

    2 weeks ago


    Strategic Analytix Fort George G Meade, United States

    About Strategic Analytix Strategic Analytix (SA) is an IT engineering and management consulting firm focuses on mission critical services and solutions to the Federal Government including the Department of Defense (DOD), the Intelligence Community (IC) and Civilian Healthcare age ...

  • Booz Allen Hamilton

    Penetration Tester

    4 days ago


    Booz Allen Hamilton Annapolis Junction, United States Full time

    Job Number: R0193630 · Penetration TesterKey Role: · Find possible vulnerabilities while using penetration testing tools and techniques, to ensure security of computer systems, applications, servers, or networks. Apply advanced consulting skills, extensive technical expertise, an ...


  • SAIC Beltsville, United States

    You will need to login · before you can apply for a job. · Penetration Tester with Security Clearance · Description SAIC is seeking a highly motivated Penetration Tester. The successful candidate will provide support to the Cybersecurity Integrity Center (CIC) in the Department ...

  • Synergy Interactive

    Penetration Tester

    4 days ago


    Synergy Interactive Rockville, United States

    Synergy Interactive is partnered with a notable financial institution and they are seeking a skilled Penetration Tester (Ethical Hacker) to enhance their cybersecurity team. In this role, you will conduct rigorous assessments to identify vulnerabilities, ensuring the protection o ...

  • Peraton

    Penetration Tester

    2 days ago


    Peraton Washington, United States Full time

    Responsibilities · Peraton is seeking a Penetration Tester who will have the opportunity to provide support to technical processes and technical management processes in support of comprehensive test and evaluation associated with test support, operational verification of installa ...

  • Synergy Interactive

    Penetration Tester

    2 weeks ago


    Synergy Interactive Rockville, United States

    Key Responsibilities: · Conduct comprehensive penetration testing on financial systems and applications. · Identify vulnerabilities, weaknesses, and potential threats in security infrastructure. · Develop and execute penetration testing plans, including manual and automated testi ...

  • Foxhole Technology

    Penetration Tester

    17 hours ago


    Foxhole Technology Herndon, United States

    Job Title: Senior Penetration Tester · Clearance: Secret · Location: Leesburg, VA (Onsite 3 days per week) · Discover an exciting career at Foxhole Technology, an innovative IT Engineering firm founded in 2007. As leaders in cybersecurity, DEVSEC OPS, Agile Developemnt, Cloud and ...

  • Synergy Interactive

    Penetration Tester

    1 week ago


    Synergy Interactive Rockville, United States

    Synergy Interactive is partnered with a notable financial institution and they are seeking a skilled Penetration Tester (Ethical Hacker) to enhance their cybersecurity team. In this role, you will conduct rigorous assessments to identify vulnerabilities, ensuring the protection o ...

  • General Dynamics Information Technology

    Penetration Tester

    5 days ago


    General Dynamics Information Technology Pimmit, United States

    Seize your opportunity to make a personal impact as a Penetration Tester supporting customer activities. GDIT is your place to make meaningful contributions to challenging projects and grow a rewarding career. · At GDIT, people are our differentiator. As a Penetration Tester, you ...

  • Booz Allen Hamilton

    Penetration Tester

    4 days ago


    Booz Allen Hamilton Fort Belvoir, United States Full time

    Job Number: R0194138 · Penetration TesterThe Opportunity: · Are you looking for an opportunity to use your technical expertise and grow your skills to provide technical solutions in support of our warfighters? We're looking for an Red Team Penetration Tester to help test, configu ...

  • QinetiQ

    Penetration Tester

    1 week ago


    QinetiQ Reston, United States

    Company Overview · We are a world-class team of professionals who deliver next generation technology and products in robotic and autonomous platforms, ground, soldier, and maritime systems in 50+ locations world-wide. Much of our work contributes to innovative research in the fie ...

  • CACI International

    Penetration Tester

    4 days ago


    CACI International Chantilly, United States

    Penetration Tester · Job Category: Information Technology · Time Type: Full time · Minimum Clearance Required to Start: TS/SCI with Polygraph · Employee Type: Regular · Percentage of Travel Required: None · Type of Travel: None · * * · What Youll Get to Do: · + Perform c ...

  • Cyber Defense Technologies

    Penetration Tester

    10 hours ago


    Cyber Defense Technologies Chantilly, United States

    Overview: CDT is looking for a Penetration Tester to support a government customer onsite in Chantilly, VA. Candidates with OSCP certification are highly recommended to apply. · Clearance: An active Top Secret/SCI with CI poly is required. Candidates who do not meet these requ ...

  • The Applied Research Laboratory at Penn State University

    Penetration Tester

    4 days ago


    The Applied Research Laboratory at Penn State University Annapolis, United States

    The Offensive Security Department in the Applied Research Laboratory (ARL) at Penn State University is seeking an experienced self-motivated Applications Developer/Penetration Tester to join our team to design, develop, implement, document, and maintain cyberspace operations soft ...

  • iNovex Information Systems

    Penetration Tester

    5 days ago


    iNovex Information Systems Columbia, United States

    · Job Brief · iNovex is seeking a Penetration Tester to break into computer systems and applications, and in the end, help make those systems more secure. · Job Description · ORANGE you glad that you chose iNovex? · iNovex was built on the principle that people matter first ...