Principal Penetration Testing and Vulnerability Analyst

What are the top three skillsets the candidate should have? Lead Red Cell assessments, PenTests, and Vulnerability Assessments using Automated and Manual TTPs.Provide mentoring and guidance to junior, and senior staff members by creating and teaching latest techniques in ethical hacking and vulnerability analysis.Recommend mitigation and remediation strategies based upon the class and category of vulnerability, Secret Clearance
Contract W2
Depends on Experience
Work from home not available Travel not required

Job Description

Program Name: CSOS supporting US Department of State

1801 N Lynn St Arlington VA 22209


Must possess eight (8) years of substantive IT knowledge including two (2) years of hands-on Penetration Testing experience, and demonstrate hands-on expertise and/or training in areas of emerging technologies. Primarily, the candidate must have experience leading a team of penetration testers/vulnerability analysts and lead security assessments including provide guidance and mentoring to junior, mid, and senior team members. Secondarily, the candidate should have hands-on experience and expertise with ethical hacking, firewall and intrusion detection/prevention technologies, risk assessments, secure coding practices or threat modeling. Be a self-starter with, keen analytical skills, curiosity, agility, and adaptability. The ability to work quickly, willingness to work on ad hoc assignments, work independently as needed, strong written and verbal communication skills, and recognizing the importance of being a team player.

Required Qualifications:

  • Must show strong skills in Network and Web based Penetration Testing and be able to conduct Penetration Tests using Automated and Manual Methods
  • Have an understanding of common Web Application vulnerabilities like SQLi, XSS, CSRF, and HTTP Flooding.
  • Must be able to use at least two of the following proficiently and instruct others on them: Nessus, Burp, Metasploit Framework/Pro, and the Social Engineering Toolkit.
  • Must have solid working experience and knowledge of Windows and Unix/Linux operating system
  • Scripting (Windows/*nix), Bash, Python, Perl or Ruby, Systems Programming
  • Strong familiarity with OWASP top 10, PTES and NIST 800-53.
  • A demonstrated ability to mentor and train junior team members
  • Firm understanding of network and system architecture and analysis. Fundamentals of network routing & switching, vulnerability management, assessing network device configurations, and operating systems (Windows/*nix)
  • Must be able to work alone or in a small group.

Preferred Qualifications:

  • OSCP, GIAC GPEN, GWAPT or other Penetration Testing certifications
  • Ability to perform static and/or dynamic code review.
  • Familiarity with Cloud solutions and how to test their security (Amazon Web Services, Microsoft O365 and Azure, Google Cloud, etc.)


  • Lead Red Cell assessments
  • Assess and enhance current processes for penetration testing and vulnerability assessment
  • Recommend mitigation and remediation strategies based upon the class and category of vulnerability
  • Performs Leadership Support and Penetration Testing on web and other applications, network infrastructure and operating system infrastructures.
  • Briefs executive summary and findings to stakeholders to include Sr. Leadership
  • Have an understanding of how to create unique exploit code, bypass AV and mimic adversarial threats.
  • Assesses the current state of the customer s system security by identifying all vulnerabilities and security measures.
  • Helps customer perform analysis and mitigation of security vulnerabilities.
  • Researches and maintains proficiency in tools, techniques, countermeasures, and trends in computer network vulnerabilities, data hiding and network security and encryption.
  • Provide support to incident response teams through capability enhancement and reporting.
  • Provide mentoring and guidance to junior, mid, and senior staff members by creating and teaching latest techniques in ethical hacking and vulnerability analysis.

Posted By

Salig Chada

Dice Id : asdinc
Position Id : 201959756
Have a Job? Post it

Similar Positions

Senior Cyber Security Engineer
  • Take2 Consulting
  • Washington D.c., DC
Penetration Application Security Tester
  • NetSource, Inc.
  • Falls Church, VA
Lead Application Security Engineer
  • The Consortium Inc
  • Rockville, MD
Senior Security Engineer
  • Robert Half Technology
  • Washington, D.c., DC
Security Engineer - Penetration Tester
  • Softworld, Inc.
  • Garrett Park, MD
Penetration Tester/Application Security Tester
  • U.S. Tech Solutions Inc.
  • Falls Church, Virginia
Security Engineer (Vulnerability Management)
  • ALTEK Information Technology, Inc
  • Washington D.c., DC
Java Security Engineer
  • CompuGain Corporation
  • Rockville, MD
Security Engineer/Analyst
  • TalTeam
  • Reston, VA
IT Security Manager
  • Sparks Group
  • Suitland, MD
Application Security Analyst
  • Integrated Systems, Inc.
  • Washington, D.c., DC