- Conduct highly complex offensive security operations testing consistent with known adversary tactics techniques and procedures and contribute to the development of objectives and approaches taken to remediate risk.
- Apply sound technical and management principles to identify and remediate cybersecurity --vulnerabilities across the State Department global IT enterprise infrastructure.
- Apply organizational and process change principals.
- Evaluate system performance results, perform risk assessments, and evaluate performance metrics.
- Provide ad-hoc penetration testing and assessment services on Department of State systems identified by the leadership.
- Develop, Identify and resolve security vulnerabilities related to deployment and testing processes.
- Streamline and optimize processes and procedures in order to rapidly remediate vulnerabilities from cybersecurity threats.
- Collaborate with Department and external cyber stakeholders on cybersecurity technology implementations to meet specific operational needs.
- Perform technical evaluations of recommended vulnerability mitigation actions and make recommendations based on impact and/or other countermeasures.
- Develop strategies for CIC cyber defense technologies, ensuring integration and alignment for continued operation.
- Conduct assessments of threats and vulnerabilities; determine deviations from acceptable configurations, enterprise, or local policy; assess the level of risk; and develop and/or recommend appropriate mitigation countermeasures in operational and non-operational situations.
- Network Mapping include but are not limited to a network map of the organization's system that includes a visual representation of the organization's physical devices and digital network.
- Perform operation and maintenance activities in support of existing CIC cyber tools and technologies (MSV, Qualys, Tenable Nessus and others).
- Identify, diagnose, and prioritize anomalies in cyber defense infrastructure and resources.
- Perform cybersecurity testing of developed applications and/or systems.
- Identify and direct the remediation of technical problems encountered during testing and implementation of new systems.
- Document security issues and impacts identified through offensive operations in a clear and concise manner to facilitate reporting to impacted stakeholders.
- Provide guidance and recommendations to stakeholders responsible for security remediation actions to close identified gaps and remediation validation testing.
- Independently handle complex issues with minimal supervision, while escalating only the most complex issues to appropriate staff.
- Bachelor's and five (5) years or more experience; Master's and three (3) years or more experience.
- A degree in Cybersecurity or related field.
- 4-6+ years penetration testing experience.
- Web application penetration testing, LPT, Source code vulnerability analysis, serious problem-solving skills experience.
- All penetration testers/operators must be DHS/CISA AES qualified within 90 days of onboarding.
- US Citizenship.
- Active Top Secret Clearance
- 4 years Microsoft Operating Systems (OS) engineering and support experience focusing on Active Directory (AD), System Center Configuration Manager (SCCM), System Center Operations Manager (SCOM).
- 4-6 years Network penetration testing experience.
- In-depth experience in planning, implementing, and managing large/global enterprise infrastructures.
- Familiarity of various analytical tools (Splunk, USBDeview, Netwitness, MimiKatz).
- Understanding of Security Information and Event Management (SIEM) tools (Splunk, McAfee).
- Familiarity of Cobalt Strike, Nessus, Kali Linux, Burp Suite, Nmap and OpenVAS for databases.
- Knowledge of general attack stages.
- Skill in the use of social engineering techniques and using penetration testing tools.
- Familiarity with OMB, NIST, DHS, and related security guidelines and directives.
- Interpersonal skills including the ability to collaborate effectively, and excellent written and oral communications.
- Network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
- Server/endpoint OS (Microsoft, Linux, IOS) along with mobile and cloud technologies.
- Cloud application security, Vulnerability Management and Security Information, and Event Management capabilities.
- Countermeasures / mitigations to identified cybersecurity risks.
- Knowledge of network protocols such as TCP/IP, Dynamic Host Configuration Protocol (DHCP), domain name system, and directory services.
- Certifications: LPT (Licensed Penetration Testers, Microsoft Certifications (MCSE, MCSA, MCSD),OSCP (Offensive Security Certification Professional), ISACA Certified Information Systems Auditor (CISA), SCP Security Certified Network Architect (SCNA), ISACA Certified Information Security Manager (CISM)
-
Penetration Tester
3 days ago
Professional Stewards Services (PSS), LLC Washington, United States**Penetration Tester** · **We are seeking an energetic, self-starter to join our growing team.** · **Job Type**: Full-time, 40 hours per week · **Hours**: Monday through Friday · **Salary Range**: $135,000 · **Work location**: Remotely/Virtual · **Requirements**: Must be a US cit ...
-
Penetration Tester
5 days ago
SAIC Beltsville, United States· SAIC is seeking a highly motivated Penetration Tester. The successful candidate will provide support to the Cybersecurity Integrity Center (CIC) in the Department of State Bureau of Information Resource Management (IRM). Duties are in the Washington, D.C. metropolitan area (30 ...
-
Penetration Tester
1 week ago
Dark Wolf Solutions Herndon, United States**Duties/Responsibilities**: · **Required Qualifications**: · - 2+ years' experience in three or more specific areas to include: intelligence analysis, network engineering, networking security, penetration testing, red team operations, hardware engineering, software engineering, ...
-
Senior Penetration Tester
2 weeks ago
Infinity Systems Garten, WV, United States Freelance**Your task**: · As a **Senior Penetration Tester (m/f/d)**, you will independently advise our business customers at decision-maker and specialist level on all questions of cyber security and cyber defense. · In detail, your range of tasks includes the following areas: · - Indepe ...
-
Penetration Tester
1 week ago
Delmock Technologies Laurel, United States· About Our Company: · Join Delmock Technologies, Inc. (DTI), a leading HUBZone business in Baltimore, known for delivering sophisticated IT and Health solutions with a commitment to ethics, expertise, and superior service. Actively engaged in the local community, DTI creates o ...
-
Penetration Tester
2 weeks ago
Strategic Analytix Fort George G Meade, United StatesAbout Strategic Analytix Strategic Analytix (SA) is an IT engineering and management consulting firm focuses on mission critical services and solutions to the Federal Government including the Department of Defense (DOD), the Intelligence Community (IC) and Civilian Healthcare age ...
-
Penetration Tester
4 days ago
Booz Allen Hamilton Annapolis Junction, United States Full timeJob Number: R0193630 · Penetration TesterKey Role: · Find possible vulnerabilities while using penetration testing tools and techniques, to ensure security of computer systems, applications, servers, or networks. Apply advanced consulting skills, extensive technical expertise, an ...
-
Penetration Tester with Security Clearance
4 days ago
SAIC Beltsville, United StatesYou will need to login · before you can apply for a job. · Penetration Tester with Security Clearance · Description SAIC is seeking a highly motivated Penetration Tester. The successful candidate will provide support to the Cybersecurity Integrity Center (CIC) in the Department ...
-
Penetration Tester
4 days ago
Synergy Interactive Rockville, United StatesSynergy Interactive is partnered with a notable financial institution and they are seeking a skilled Penetration Tester (Ethical Hacker) to enhance their cybersecurity team. In this role, you will conduct rigorous assessments to identify vulnerabilities, ensuring the protection o ...
-
Penetration Tester
2 days ago
Peraton Washington, United States Full timeResponsibilities · Peraton is seeking a Penetration Tester who will have the opportunity to provide support to technical processes and technical management processes in support of comprehensive test and evaluation associated with test support, operational verification of installa ...
-
Penetration Tester
2 weeks ago
Synergy Interactive Rockville, United StatesKey Responsibilities: · Conduct comprehensive penetration testing on financial systems and applications. · Identify vulnerabilities, weaknesses, and potential threats in security infrastructure. · Develop and execute penetration testing plans, including manual and automated testi ...
-
Penetration Tester
17 hours ago
Foxhole Technology Herndon, United StatesJob Title: Senior Penetration Tester · Clearance: Secret · Location: Leesburg, VA (Onsite 3 days per week) · Discover an exciting career at Foxhole Technology, an innovative IT Engineering firm founded in 2007. As leaders in cybersecurity, DEVSEC OPS, Agile Developemnt, Cloud and ...
-
Penetration Tester
1 week ago
Synergy Interactive Rockville, United StatesSynergy Interactive is partnered with a notable financial institution and they are seeking a skilled Penetration Tester (Ethical Hacker) to enhance their cybersecurity team. In this role, you will conduct rigorous assessments to identify vulnerabilities, ensuring the protection o ...
-
Penetration Tester
5 days ago
General Dynamics Information Technology Pimmit, United StatesSeize your opportunity to make a personal impact as a Penetration Tester supporting customer activities. GDIT is your place to make meaningful contributions to challenging projects and grow a rewarding career. · At GDIT, people are our differentiator. As a Penetration Tester, you ...
-
Penetration Tester
4 days ago
Booz Allen Hamilton Fort Belvoir, United States Full timeJob Number: R0194138 · Penetration TesterThe Opportunity: · Are you looking for an opportunity to use your technical expertise and grow your skills to provide technical solutions in support of our warfighters? We're looking for an Red Team Penetration Tester to help test, configu ...
-
Penetration Tester
1 week ago
QinetiQ Reston, United StatesCompany Overview · We are a world-class team of professionals who deliver next generation technology and products in robotic and autonomous platforms, ground, soldier, and maritime systems in 50+ locations world-wide. Much of our work contributes to innovative research in the fie ...
-
Penetration Tester
4 days ago
CACI International Chantilly, United StatesPenetration Tester · Job Category: Information Technology · Time Type: Full time · Minimum Clearance Required to Start: TS/SCI with Polygraph · Employee Type: Regular · Percentage of Travel Required: None · Type of Travel: None · * * · What Youll Get to Do: · + Perform c ...
-
Penetration Tester
10 hours ago
Cyber Defense Technologies Chantilly, United StatesOverview: CDT is looking for a Penetration Tester to support a government customer onsite in Chantilly, VA. Candidates with OSCP certification are highly recommended to apply. · Clearance: An active Top Secret/SCI with CI poly is required. Candidates who do not meet these requ ...
-
Penetration Tester
4 days ago
The Applied Research Laboratory at Penn State University Annapolis, United StatesThe Offensive Security Department in the Applied Research Laboratory (ARL) at Penn State University is seeking an experienced self-motivated Applications Developer/Penetration Tester to join our team to design, develop, implement, document, and maintain cyberspace operations soft ...
-
Penetration Tester
5 days ago
iNovex Information Systems Columbia, United States· Job Brief · iNovex is seeking a Penetration Tester to break into computer systems and applications, and in the end, help make those systems more secure. · Job Description · ORANGE you glad that you chose iNovex? · iNovex was built on the principle that people matter first ...
Penetration Tester - BELTSVILLE, United States - SAIC Career Site
Description
Description
SAIC is seeking a highly motivated Penetration Tester. The successful candidate will provide support to the Cybersecurity Integrity Center (CIC) in the Department of State Bureau of Information Resource Management (IRM). Duties are in the Washington, D.C. metropolitan area (30% in downtown D.C; 70% in Beltsville, MD. The CIC supports cybersecurity monitoring, threat analysis, incident response, and infrastructure remediation within and across all of the State Department's information technology (IT) infrastructure. The CIC coordinates and collaborates with other State Department bureaus as well as other organizations within the Federal Government, and commercial partners.
The position allows hybrid remote work. Team is currently reporting onsite 3 days per week or more as needed.
Description of Duties
The Penetration Tester will provide support for HVA Assessments using methodology by Cybersecurity and Infrastructure Security Agency (CISA) Assessment Evaluation and Standardization (AES) program with broad and in-depth knowledge to conduct offensive cyber operations across the organization globally. In this role, you will conduct offensive security operations to emulate adversary tactics and procedures to test preventative, detective, and response controls across the global technology landscape. The Penetration Tester will:
Responsibilities include:
Qualifications
Required Education & Experience
Required Clearance
Desired
Covid Policy: SAIC does not require COVID-19 vaccinations or boosters. Customer site vaccination requirements must be followed when work is performed at a customer site.