CybersecurityJobs.io
← Back to all jobs

Job Description

Connsci is seeking a Penetration Tester to support a government program through hands-on penetration testing, vulnerability and compliance testing, and audit and reporting activities. This position is primarily remote, with travel required on an as-needed basis across Florida and the Washington DC metro region.

Role Overview

The Penetration Tester will perform security testing across networks, systems, endpoints, and cloud environments, with an emphasis on web application, API, and control validation. Responsibilities include documenting findings, preparing audit evidence, and providing recommendations to improve governance, risk, and compliance posture.

Responsibilities

  • Conduct authenticated vulnerability scans and compliance evaluations across networks, systems, endpoints, and cloud platforms.
  • Assess agency web applications using OWASP Top 10 and industry best practices.
  • Perform authenticated and unauthenticated scanning activities using tools such as Burp Suite and OWASP ZAP.
  • Identify vulnerabilities including injection flaws, authentication weaknesses, session mismanagement, and sensitive data exposure.
  • Validate application security controls against NIST CSF subcategories.
  • Evaluate REST and GraphQL APIs for authentication, authorization, and input validation weaknesses.
  • Conduct fuzzing and misuse testing to identify broken object-level authorization (BOLA) and mass assignment vulnerabilities.
  • Assess security of API tokens, keys, and session management practices.
  • Review error handling, data leakage, and logging practices to support compliance requirements.
  • Execute controlled penetration testing (internal and external) to simulate adversary behaviors and assess defensive effectiveness.
  • Document findings, prepare audit evidence, and provide recommendations for improving governance, risk, and compliance posture.
  • Provide technical assistance to Agency OIGs and coordinate with operational IT and security teams to ensure findings are actionable and evidence-based.

Required Qualifications

  • Bachelor's degree in Cybersecurity, Information Systems, or a related field, or equivalent experience.
  • At least 5 years of penetration testing experience, including web application testing and API testing.
  • At least 2 years supporting audit, compliance, or oversight functions, including preparing audit-ready documentation, evidence, and reports for executive leadership.
  • At least 2 years experience with NIST Cybersecurity Framework, including NIST 800-53.
  • At least one cybersecurity certification, such as CISSP, CISA, CISM, CCE, CFCE, GCFE, or CEH.

Technology & Tools

  • OWASP Top 10
  • Burp Suite
  • OWASP ZAP
  • NIST CSF
  • NIST 800-53
  • REST
  • GraphQL
  • BOLA

Location and Travel

  • Primarily remote work.
  • As-needed travel to company and government client site locations across Florida and the Washington DC metro region.
  • Preference for candidates local to the DC Metro Region or who reside in Florida.

Preferred Qualifications

  • Master's degree in Cybersecurity, Information Technology, or Computer Science.
  • 7+ years of experience in penetration testing.
  • 3+ years of experience with cloud technologies and Cloud Security Posture Management.

Compensation

USD 100,000 - 130,000 per year.

Similar Jobs