Penetration Tester
Job Description
Support the Case Management Modernization (CMM) Program with hands-on penetration testing and security assessment activities ahead of Application ATO.
Responsibilities
- Perform application, API, and cloud penetration tests on CMM systems prior to ATO submission.
- Conduct web, mobile, API, and microservices security testing using industry-standard tools and manual exploitation techniques.
- Execute AWS cloud penetration testing within approved boundaries including IAM, S3, Lambda, API Gateway, ECS/EKS, and networking.
- Run static and dynamic analysis, including security-focused code review.
- Conduct credentialed and uncredentialed scans, privilege escalation testing, and lateral movement analysis.
- Validate implementation of NIST 800-53 controls across AC, AU, IA, SC, SI, and CM families.
- Support RMF Step 3 (Security Assessment) activities and provide evidence for ATO packages.
- Identify vulnerabilities across application layers, cloud infrastructure, and CI/CD pipelines.
- Partner with developers, cloud engineers, and DevSecOps teams to validate fixes and retest vulnerabilities.
- Provide detailed remediation guidance aligned with secure coding and cloud security best practices.
- Track findings in Jira or equivalent tools and ensure closure prior to ATO milestones.
- Prepare Security Assessment Reports (SAR), penetration test summaries, and risk findings for AO stakeholders.
- Document exploitation steps, proof-of-concepts, and risk severity aligned with federal scoring methodologies.
- Contribute to System Security Plans (SSP), POA&Ms, and ATO evidence packages.
- Support pre-ATO readiness reviews, including control validation and security walkthroughs.
- Participate in tabletop exercises, threat modeling sessions, and architecture reviews.
- Validate system resilience through stress, failover, and adversarial resilience testing.
- Ensure compliance with federal security standards including NIST, FISMA, and AO-specific guidelines.
- Integrate security testing into Agile sprints and provide security input during sprint planning, backlog refinement, and release readiness reviews.
- Support secure CI/CD pipeline enhancements, including automated security scanning.
Requirements
- 8+ years of experience in penetration testing, application security, or ethical hacking security roles.
- Experience documenting test plans, test procedures, and detailed security findings.
- Experience supporting federal security assessments or enterprise-scale security testing.
- Hands-on penetration testing experience for web applications, APIs, microservices, and cloud environments.
- Strong proficiency with tools such as Burp Suite, OWASP ZAP, Metasploit, Nmap, Nessus, Nikto, K6 Security, or custom scripts.
- Experience testing applications built with NodeJS, ReactJS, REST APIs, and microservices.
- Strong AWS security understanding including IAM, VPC, S3, Lambda, API Gateway, ECS/EKS, CloudTrail, and CloudWatch.
- Experience with NIST 800-53, RMF, FedRAMP, or federal ATO processes.
- Ability to interpret logs, metrics, and security telemetry to identify attack paths.
- Familiarity with SIEM and monitoring tools such as Datadog, ELK, CloudWatch, and Grafana.
- Experience with container security (Docker, Kubernetes, OpenShift).
- Understanding of network security, distributed tracing, and adversarial testing techniques.
- Strong analytical, communication, and documentation skills.
- 8+ years general experience with BS/BA degree, or 6+ years with MA/MS degree (may be considered in lieu of degree).
- 6+ years experience in integration, regression, and system testing using automated testing tools in web-based applications.
- Experience writing test cases, test plans, executing test scripts, reporting defects, and preparing test result reports.
- Experience across the QA Life Cycle, including designing, developing, executing, and documenting QA processes (test plans, test cases, test procedures, and test scripts).
- OSCP, OSWE, GWAPT, GPEN, or similar offensive security certifications.
- AWS Security Specialty.
- SAFe, DevSecOps, or Agile certifications are beneficial.
- AWS Certified Security - Specialty (AWS Security Specialty | Amazon Web Services).
Technologies
- React, NodeJS, microservices, REST APIs
- AWS: IAM, VPC, S3, Lambda, API Gateway, ECS/EKS, CloudTrail, CloudWatch
- Container and orchestration: Docker, Kubernetes, OpenShift
- Testing and security tools: Burp Suite, OWASP ZAP, Metasploit, Nmap, Nessus, Nikto, K6 Security, custom Python/JavaScript tools
- Observability/monitoring: Datadog, ELK Stack, Prometheus, Grafana
- CI/CD and tooling: Jenkins, GitLab CI/CD, GitHub Actions, SonarQube, Checkmarx, Fortify
- Collaboration/work tracking: Jira, Confluence, SharePoint, MS Teams
- Analytics: Power BI
Location and Work Details
- Location: Remote (working from the USA)
- Travel required: None
Salary
- Range: $123,250 - $166,750 per year
Additional Information
- Category: Cyber and IT Risk Management
- Req#: RQ223925
- Requisition type: Regular
- Public trust: Other
- Clearance level: None
- Key skills for success: Automated Testing, AWS Cloud Computing, Infrastructure Penetration Testing, Security Controls, Security Testing
Work Requirements (Interview/Verification)
- Virtual interviews require being on camera.
- Identity verification may include taking your picture to prevent fraud.
- Authorization to collect, process, and use biometric data for identity verification and security purposes.