Job Title: Penetration Tester Location: REMOTE
Job Description:
Task description and/or any specific requirements:
Highly skilled in web application testing, API testing, and network testing
Prior experience with Burp Suite Professional, or other similar DAST tools
Experience with AI and penetration testing AI
Experience with Kali Linux and most of the tools available in the distro for penetration testing
Experience with tools such as Metasploit Pro and Cobalt Strike for red team operations
Experience with Red Team engagements from planning to execution
Experience with phishing network users to gain access for lateral movement on the network
Experience with Purple Team engagements to test monitoring controls in coordination with engineering teams and CSOC teams.
Proficiency in scripting, such as Python and/or PowerShell
Experience with penetration testing supporting PCI-DSS
Technical writing skills, along with ease in communicating concepts related to security vulnerabilities and attack path scenarios.
Familiar with OWASP Application Security Verification Standard (ASVS) and MITRE ATT&CK framework
Penetration testing certification recommended. Acceptable certifications: Offensive Security Certified Professional (OCSP), Global Information Assurance Certification (GIAC) Certifications (e.g., GIAC Certified Penetration Tester (GPEN), GIAC Web Application Penetration Tester (GWAPT), or GIAC Exploit Researcher and Advanced Penetration Tester (GXPN))
Experience:
A minimum of eight (8) years relevant experience.
A degree from an accredited College/University in the applicable field of services is required. If the individual's degree is not in the applicable field then four additional years of related experience is required.
Additional Provisions:
Pass a client mandated clearance process to include drug screening, criminal history check and credit check.
Once candidate s resume is approved and interview passed, the agency is responsible for providing drug screening. Failure to submit the drug screening results will delay the security clearance process.
If a candidate is given an interim clearance, continuation of employment is then based on the candidate receiving a sensitive clearance.
Cannot have more than 6 months travel outside the United States within the last five years. Military Service excluded. (Exception does not include military family members.) All overtime must be pre-approved in writing by the client manager or his/her designated representative.
Agency will not be reimbursed for overtime charges without previous written authorization. Authorized overtime will be reimbursed at straight time.
The enforced dress code is business casual, i.e., collared shirt with slacks for men, no skirts above the knee for women.