Duties:
Performs daily monitoring and review of security events that are escalated by junior analysts. Keeps up with the cyber threat landscape in order to rapidly identify potential threats. Performs security assessments such as penetration testing, vulnerability scanning and advanced threat hunting.
•40% Plans and performs security assessments such as penetration testing, vulnerability scanning and advanced threat hunting. Anticipates and mitigates potential attacks through enterprise connections to ensure the security of the system (s). Exploits weaknesses detected in systems to assess and prevent potential break-ins. Analyzes business impact and exposure based on security threats, vulnerabilities, and risks. Keeps up with the cyber threat landscape in order to rapidly identify potential threats. Ensures security tools are properly tuned to identify and contain cyber-attacks before they happen.
•20% Develops and implements enterprise information security architectures and solutions. Researches, designs, and advocates new technologies, infrastructure, architectures, and security products that will support security requirements for the enterprise and its customers, business partners, and vendors. Identifies, plans and implements security tools.
•20% Performs daily monitoring and review of security events that are escalated by junior analysts. Provides security technical guidance to junior analysts. Performs investigations as needed and responses to potential incidents rapidly and accurately.
•10% Researches new security/cyber intelligence and keeps up with the cyber threat landscape in order to rapidly identify potential threats. Ensures security tools are properly tuned to identify and contain cyber-attacks before they happen.
•5% Evaluates and recommends procedures and processes for the prevention, detection, containment and correction of information security breaches. Advises management and users regarding security procedures.
•5% Monitors security agencies and services in order to keep apprised of current security threats and concerns. Evaluates products and/or procedures to enhance productivity and effectiveness of information security across the organization.
Primary Focus: Security Assessments and Penetration Testing
Leads and executes security assessments with a primary focus on penetration testing, vulnerability analysis, and risk evaluation across enterprise systems.
Security Assessments and Penetration Testing
Plans and conducts penetration testing and vulnerability assessments to identify and exploit weaknesses across systems, applications, and networks. Simulates real-world attack scenarios to evaluate risk, business impact, and exposure. Anticipates potential attack vectors and recommends mitigation strategies. Maintains awareness of emerging threats to ensure testing reflects current attacker techniques.
ecurity Tooling and Assessment Enablement
Researches and supports implementation of tools that enhance assessment capabilities, including penetration testing and vulnerability scanning platforms. Ensures tools are properly configured and aligned with enterprise security requirements.
Advisory and Continuous Improvement
Provides recommendations to improve testing methodologies and coverage. Advises stakeholders on remediation strategies based on assessment results and evolving threats, continuously enhancing the effectiveness of security testing practices.
Skills:
Required Skills and Abilities: Strong analytical, data gathering and problem solving skills with experience analyzing network attacks. Understanding of system and network security, incident management, intrusion detection, log analysis, and related technologies. Creativity to recognize and address new threats and security challenges as they arise. Strong knowledge of enterprise data architecture, systems engineering and data communications as applied to the automated storage and retrieval of information, using multiple platforms and protocols with the inherent security risks of each. Ability to effectively prioritize and execute tasks in a high-pressure environment. Comprehensive understanding of the organization’s goals and objectives. Expertise with threat analysis risk management, configuration management, business continuity and contingency planning. Advanced knowledge of administrative, procedural and technical controls used to reduce security risks. Ability to troubleshoot multi-vendor Security issues. Strong organizational, interpersonal and oral communication skills. Advanced proficiency in network troubleshooting, diagnostic root cause analysis. Excellent analytical and problem-solving abilities.
Required Software and Other Tools: Advanced proficiency with applicable IT Security tools (software and hardware). Microsoft Office.
Work Environment: Fast paced, multi-platformed environment which may require action and response 24X7 to support the technical business needs of the customer. null
Schedule Notes:
****NO SUBCONTRACTOR CANDIDATES
****Information Systems Job Category - Credit Check must be processed during pre-screens.
Required Education: Bachelor''s degree in Computer Science, Information Technology or other job related degree. or 4 years of job related work experience or 2 years of job related experience plus an associate’s degree in Computer Science, Information Technology or other job related degree.
Required Work Experience: 8 years of job related technical experience.
Contract
C2 Eligibility is Required
Partial Onsite: Tuesday, Wednesday, Thursday Onsite and as Needed
Hours: 8-5 - OT, Travel, On Call, Weekends, Off Hours - As needed but not usually.
Interviews: Prefer Local In person, (Remote if needed)
Team: Cyber Threat Intelligence (SecOps)
•This team is made up of highly motivated senior cybersecurity practitioners who bring deep hands-on experience in penetration testing, assessment, threat hunting, forensics, and security operations.
•The team works closely together to support ongoing security testing initiatives, validate risk across applications and infrastructure, and help strengthen the organization’s overall security posture.
•A key selling point for candidates is the team’s collaborative culture, with members openly sharing intelligence, techniques, and findings and actively supporting one another in solving complex security problems.
•This is a strong opportunity for someone who values working alongside experienced professionals in an environment that encourages knowledge sharing, continuous learning, and high-quality security work.
Required: Linux and various penetration testing tools. (BurpSuite, MetaSploit, Nessus)
Day To Day:
A penetration tester / security assessor typically spends the day planning and executing security tests against applications, systems, and infrastructure to uncover vulnerabilities before attackers do. Much of the work involves using Linux-based environments and tools such as Burp Suite, Metasploit, and Nessus to perform web application testing, vulnerability scanning, exploitation validation, and manual verification of findings. They often review scope, analyze prior results, run scans, investigate weaknesses, and document evidence to determine real-world risk.
Soft Skills:
•Strong verbal and written communication skills, with the ability to clearly explain security findings to both technical teams and non-technical stakeholders.
•Ability to translate complex vulnerabilities into business-relevant risk and provide practical, understandable remediation guidance.
•Professional presence and confidence when discussing assessment results, answering questions, and presenting recommendations.
•Ability to document findings thoroughly, accurately, and in a polished manner suitable for reports and stakeholder communication.
Not Looking For:
•Not looking for someone whose experience is limited to running automated vulnerability scans without being able to validate, exploit, or explain the findings.
•Not looking for a candidate who relies entirely on tools like Nessus and cannot perform manual penetration testing against applications, systems, or infrastructure.
•Not looking for someone who cannot distinguish false positives from legitimate security weaknesses or assess real-world risk.
•Not looking for a security analyst with only compliance or checklist-based assessment experience in place of hands-on penetration testing expertise.