CybersecurityJobs.io
← Back to all jobs

Job Description

Cyber Defense Technologies (CDT) is supporting a government customer and is hiring a Penetration Tester to perform onsite work in Chantilly, VA. In this role, you will help identify security weaknesses through penetration testing and security-focused services, then document findings and recommendations in alignment with applicable government processes and requirements.

The position involves both technical testing and evaluation work across software, hardware, networks, and applications. CDT also recommends candidates with OSCP certification to apply, especially for experience aligned to red teaming and penetration testing support.

Role overview

  • Support a government customer onsite in Chantilly, VA
  • Conduct penetration testing using active and passive capabilities to expose and exploit IA vulnerabilities
  • Evaluate information systems and recommend changes to improve confidentiality, integrity, and availability
  • Perform security-focused services to improve security posture
  • Conduct tests and evaluations of software, hardware, networks, and applications

Responsibilities

  • Conduct penetration testing that uses both active and passive capabilities to expose and exploit IA vulnerabilities
  • Review and evaluate information systems and recommend changes to improve information confidentiality, integrity and availability
  • Perform security focused services to improve security posture
  • Conduct test and evaluations of software, hardware, networks and applications
  • Review documents to ensure completeness and compliance with the RMF process, ICD 503 requirements, and/or other applicable regulations

Required qualifications

  • High School Diploma/GED with 5 years of relevant work experience
  • Bachelor’s Degree with 3 years of relevant work experience
  • Experience in cyber security with a focus on red teaming, penetration testing, or threat hunting

Technologies and tools

  • Python, PHP, Ruby
  • MITRE ATT&CK, OWASP
  • Docker, Kubernetes
  • VMware, Xen, Hyper V
  • Windows, Linux, Unix, Mac OS X

Clearance

  • Active Top Secret/SCI with CI poly is required
  • Applicants who do not meet these requirements will not be considered

Desired qualifications

  • Strong understanding of network protocols and troubleshooting, server and workstation operating systems, exploits and vulnerabilities
  • Strong working knowledge of common penetration tools, tactics, techniques, and procedures
  • Experience with cloud environments
  • Strong understanding of penetration testing methodologies (MITRE ATT&CK, OWASP)
  • Ability to incorporate threat intelligence data into attached or penetration testing scenarios
  • Excellent problem solving and troubleshooting skills with strong attention to detail
  • Ability to read/write code using interpreted languages (Python, PHP, Ruby, etc.)
  • Experience with simulated/emulated environments and/or virtualization technologies
  • Experience with orchestration and virtualization environments (Docker, Kubernetes, etc.)
  • Experience with industrial control systems deployment, security best practices, vulnerabilities, and penetration testing
  • Experience with ICD 503 and the Government’s certification and accreditation process
  • Knowledge of networks, computer components, system protocols, and COTS technology
  • System methodologies including client/server, web hosting, web content servers, policy servers, directory servers, firewalls, WAN, MAN, LAN, switches, and routers
  • Software integration of COTS and Government Off-the-Shelf (GOTS) products
  • Windows, Linux, Unix, and Mac OS X administration
  • VMware, Xen, Hyper V and other virtualization platforms
  • Configuring and supporting Windows, Linux, Unix, Mac OS, and other operating systems, VMware, Xen, Hyper V and other virtualization platforms
  • Experience with software engineering, program design and implementation, configuration management, system maintenance, integration testing, and information system engineering
  • System certification activities and system certification and accreditation efforts
  • Research, develop, and maintain knowledge of penetration testing tools, tactics, techniques, and procedures
  • Research, development, integration, and distribution of information systems security tools and associated documentation
  • Security procedures for systems and software within area of expertise to ensure consistent security policy implementation
  • Experience in technical project management
  • Education relevant to computer engineering, information security, information management, cyber security, and/or computer science

Compensation and benefits

  • Salary: USD 90,000 - 130,000 per year
  • Comprehensive benefits package, including health, dental, and retirement plans
  • Opportunities for professional development and career advancement

Similar Jobs