CybersecurityJobs.io
← Back to all jobs

Job Description

Support the Case Management Modernization (CMM) Program with hands-on penetration testing and security assessment activities ahead of Application ATO.

Responsibilities

  • Perform application, API, and cloud penetration tests on CMM systems prior to ATO submission.
  • Conduct web, mobile, API, and microservices security testing using industry-standard tools and manual exploitation techniques.
  • Execute AWS cloud penetration testing within approved boundaries including IAM, S3, Lambda, API Gateway, ECS/EKS, and networking.
  • Run static and dynamic analysis, including security-focused code review.
  • Conduct credentialed and uncredentialed scans, privilege escalation testing, and lateral movement analysis.
  • Validate implementation of NIST 800-53 controls across AC, AU, IA, SC, SI, and CM families.
  • Support RMF Step 3 (Security Assessment) activities and provide evidence for ATO packages.
  • Identify vulnerabilities across application layers, cloud infrastructure, and CI/CD pipelines.
  • Partner with developers, cloud engineers, and DevSecOps teams to validate fixes and retest vulnerabilities.
  • Provide detailed remediation guidance aligned with secure coding and cloud security best practices.
  • Track findings in Jira or equivalent tools and ensure closure prior to ATO milestones.
  • Prepare Security Assessment Reports (SAR), penetration test summaries, and risk findings for AO stakeholders.
  • Document exploitation steps, proof-of-concepts, and risk severity aligned with federal scoring methodologies.
  • Contribute to System Security Plans (SSP), POA&Ms, and ATO evidence packages.
  • Support pre-ATO readiness reviews, including control validation and security walkthroughs.
  • Participate in tabletop exercises, threat modeling sessions, and architecture reviews.
  • Validate system resilience through stress, failover, and adversarial resilience testing.
  • Ensure compliance with federal security standards including NIST, FISMA, and AO-specific guidelines.
  • Integrate security testing into Agile sprints and provide security input during sprint planning, backlog refinement, and release readiness reviews.
  • Support secure CI/CD pipeline enhancements, including automated security scanning.

Requirements

  • 8+ years of experience in penetration testing, application security, or ethical hacking security roles.
  • Experience documenting test plans, test procedures, and detailed security findings.
  • Experience supporting federal security assessments or enterprise-scale security testing.
  • Hands-on penetration testing experience for web applications, APIs, microservices, and cloud environments.
  • Strong proficiency with tools such as Burp Suite, OWASP ZAP, Metasploit, Nmap, Nessus, Nikto, K6 Security, or custom scripts.
  • Experience testing applications built with NodeJS, ReactJS, REST APIs, and microservices.
  • Strong AWS security understanding including IAM, VPC, S3, Lambda, API Gateway, ECS/EKS, CloudTrail, and CloudWatch.
  • Experience with NIST 800-53, RMF, FedRAMP, or federal ATO processes.
  • Ability to interpret logs, metrics, and security telemetry to identify attack paths.
  • Familiarity with SIEM and monitoring tools such as Datadog, ELK, CloudWatch, and Grafana.
  • Experience with container security (Docker, Kubernetes, OpenShift).
  • Understanding of network security, distributed tracing, and adversarial testing techniques.
  • Strong analytical, communication, and documentation skills.
  • 8+ years general experience with BS/BA degree, or 6+ years with MA/MS degree (may be considered in lieu of degree).
  • 6+ years experience in integration, regression, and system testing using automated testing tools in web-based applications.
  • Experience writing test cases, test plans, executing test scripts, reporting defects, and preparing test result reports.
  • Experience across the QA Life Cycle, including designing, developing, executing, and documenting QA processes (test plans, test cases, test procedures, and test scripts).
  • OSCP, OSWE, GWAPT, GPEN, or similar offensive security certifications.
  • AWS Security Specialty.
  • SAFe, DevSecOps, or Agile certifications are beneficial.
  • AWS Certified Security - Specialty (AWS Security Specialty | Amazon Web Services).

Technologies

  • React, NodeJS, microservices, REST APIs
  • AWS: IAM, VPC, S3, Lambda, API Gateway, ECS/EKS, CloudTrail, CloudWatch
  • Container and orchestration: Docker, Kubernetes, OpenShift
  • Testing and security tools: Burp Suite, OWASP ZAP, Metasploit, Nmap, Nessus, Nikto, K6 Security, custom Python/JavaScript tools
  • Observability/monitoring: Datadog, ELK Stack, Prometheus, Grafana
  • CI/CD and tooling: Jenkins, GitLab CI/CD, GitHub Actions, SonarQube, Checkmarx, Fortify
  • Collaboration/work tracking: Jira, Confluence, SharePoint, MS Teams
  • Analytics: Power BI

Location and Work Details

  • Location: Remote (working from the USA)
  • Travel required: None

Salary

  • Range: $123,250 - $166,750 per year

Additional Information

  • Category: Cyber and IT Risk Management
  • Req#: RQ223925
  • Requisition type: Regular
  • Public trust: Other
  • Clearance level: None
  • Key skills for success: Automated Testing, AWS Cloud Computing, Infrastructure Penetration Testing, Security Controls, Security Testing

Work Requirements (Interview/Verification)

  • Virtual interviews require being on camera.
  • Identity verification may include taking your picture to prevent fraud.
  • Authorization to collect, process, and use biometric data for identity verification and security purposes.

Similar Jobs