Penetration Tester
Job Description
ASRC Federal is hiring a Penetration Tester for a hybrid role in Quantico, VA. Telework is available, with an onsite requirement of up to two (2) days a week at Quantico Marine Corps Base VA. This position supports hands-on testing across modern application, network, and cloud environments, with compensation in the range of USD 130,000 to 147,568 per year.
Responsibilities
- Plan, execute, and document penetration tests to identify vulnerabilities and recommend remediation.
- Conduct penetration testing across web applications, mobile applications, networks, cloud environments, and other in-scope systems.
- Use a range of tools and techniques to uncover vulnerabilities, including SQL injection, cross-site scripting (XSS), buffer overflows, and other common attack vectors.
- Perform reconnaissance to gather information about target systems and networks.
- Develop and run exploit code to demonstrate the impact of identified vulnerabilities.
- Bypass security controls and evade detection during authorized testing.
- Conduct vulnerability assessments using automated scanning tools and manual techniques.
- Analyze scan results to identify false positives and prioritize findings.
- Develop custom scripts and tools to automate vulnerability assessment tasks.
- Produce detailed reports covering vulnerabilities, exploitation methods, and remediation recommendations.
- Present findings to stakeholders, including technical teams and management.
- Create and maintain documentation for penetration testing methodologies, tools, and techniques.
- Provide guidance and technical assistance to system owners and developers during remediation.
- Validate remediation efforts and conduct retests to verify the effectiveness of implemented security controls.
- Stay current on evolving threats, vulnerabilities, and attack techniques.
- Research and evaluate new penetration testing tools and methodologies, and improve testing capabilities through custom tooling.
- Contribute to security policies and procedures.
- Collaborate with cybersecurity professionals, including security architects, incident responders, and security engineers, and share knowledge with team members.
- Participate in security training and awareness programs.
- Perform all activities legally and ethically, following established rules of engagement; protect sensitive data confidentiality and integrity and respect user privacy.
Requirements
- Minimum 5 to 7 years of experience in security principles, including attack frameworks, threat landscapes, and attacker tactics, techniques and procedures.
- Proven experience conducting penetration tests of web applications, networks, and other systems.
- Experience with a variety of penetration testing tools and techniques, including Rapid7 Nexpose, Appspider Pro, Metasploit, Cobalt Strike, and/or Burp Suite.
- Active Top-Secret Clearance REQUIRED, eligible to be upgraded to TS/SCI.
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field, or equivalent experience.
- Must meet 8570 certification requirements at the time of hire. IAT II Information Assurance Baseline (for example: CASP+ CE, CCMP Security, CISA, CISSP, GCED, GCIH, Security+ CE, CCSP).
- A CSSP Auditor certification is preferred (examples include: CEH, CySA+, CISA, GSNA, CFR, PenTest).
Benefits
- Health care
- Dental
- Vision
- Life insurance
- 401(k)
- Education assistance
- Paid time off including PTO
- Holidays
- Any other paid leave required by law
Work Environment and Physical Demands
- Primarily a Telework position with onsite requirements up to two (2) days a week.
- If the alternate worksite is other than DCSA facilities or corporate office space, the role requires reliable communication over voice (cell phone preferred) and a stable, capable internet connection.
- Must be able to communicate complex technical ideas to a diverse customer base verbally and in written form.