Penetration Tester / Security Assessor
$90k - $109kASM Research, An Accenture Federal Services Company
Creates cyber-intelligence tools / methods and performs research and analysis in order to mitigate and eliminate data and cyber security risks. Designs and develops acceptance criteria for cybersecurity architecture.
Perform infrastructure penetration testing to discover and exploit vulnerabilities to test the effectiveness of the organization's security posture.
Perform web application penetration testing to identify and exploit OWASP Top 10 web application vulnerabilities.
Leverage threat intelligence to emulate known threat actors' tactics, techniques, and procedures.
Partner with various cybersecurity teams to improve automation and detection of threat actors.
Engage with technical and non-technical audiences to articulate both techniques and results.
Minimum Qualifications
Bachelor's Degree in Computer Science or a related field or equivalent experience.
5-10 years of experience in systems security with a minimum of 2+ years in information security, penetration testing, or ethical hacking.
Other Job Specific Skills
Must possess demonstrated experience planning and conducting penetration tests against networks and web applications.
Demonstrated experience conducting vulnerability assessments and penetration tests.
Expertise with tools such as Bloodhound, Burp Suite, Cobalt Strike, Metasploit, and Mimikatz.
Hands-on experience with penetration testing tools and frameworks.
Portfolio of security assessments or CTF achievements (preferred).
Experience with network scanning, enumeration, and exploiting vulnerabilities.
Proficiency in Windows, Linux, and macOS environments.
Understanding of system hardening techniques and common misconfigurations.
Knowledge of programming languages like Python, Ruby, or JavaScript for creating custom scripts and exploits.
Familiarity with bash, PowerShell, or other scripting languages for automation.
Understanding of web technologies, including HTML, JavaScript, and SQL.
Preferred Skills
Experience in identifying and exploiting vulnerabilities in web applications, networks, and systems.
Familiarity with CVSS (Common Vulnerability Scoring System) and understanding how to prioritize vulnerabilities based on risk.
Ability to analyze and critique code for security vulnerabilities.
Familiarity with common vulnerabilities such as SQL injection, XSS (Cross-Site Scripting), CSRF (Cross-Site Request Forgery), and buffer overflows.
Strong understanding of network protocols, architecture, and components (e.g., TCP/IP, DNS, VPNs, firewalls, routers, switches).
Compensation Ranges
Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.
EEO Requirements
It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.
All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment.
Physical Requirements
The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, "light office duties' or "lifting up to 50 pounds" or "some travel" required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions.
Disclaimer
The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.
$90k - $109k
EEO Requirements
It is the policy of ASM that an individual's race, color, religion, sex, disability, age, gender identity, veteran status, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.
All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, veteran status, disability, gender identity, or age. All decisions on employment are made to abide by the principle of equal employment.
- ...Remote Role Role Purpose The Senior Consultant – Cyber Security & PCI Qualified Security Assessor (QSA) is a senior delivery and trusted-advisor role within our GRC Advisory practice, accountable for leading high-quality cyber security and compliance engagements...SuggestedRemote work
- ...Technology Controls Vice President Drive the security of critical banking applications and... ...will be to plan, execute, and report on penetration tests targeting high-impact applications... ...test reports and mentoring junior testers. ~ Continuous learner who keeps up with...Suggested
$104k - $156k
...Posting Type Remote/Hybrid Job Overview As an Advanced Security Engineer focused on Endpoint Security, you will design, build,... ...Required Skills: Endpoint Security, Network Security, Penetration Testing, Security Architecture Design, Security Automation,...SuggestedRemote work$76.4k - $138.6k
...more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost 950 people who collaborate to support the business of EY by protecting...SuggestedSummer holidayFlexible hours$82.42k - $162.55k
...Why USAA? At USAA, our mission is to empower our members to achieve financial security through highly competitive products, exceptional service and trusted advice. We seek to be the #1 choice for the military community and their families. Embrace a fulfilling career...SuggestedHourly payH1bLive inLocal areaRemote workRelocation- ...business model for re-engineering systems and performing back-office services at a reduced cost, while reinforcing accuracy, speed and security. Seven of the top ten US insurers are among Infosys McCamish's many BPM clients. Infosys McCamish has its operations spread across...Immediate start
- ...Senior Cyber Security Engineer - AI Security Architecture Job Type: Full-Time Location Type: Hybrid Primary Location: Atlanta, Georgia, US Alternate Locations: Newell Brands is a leading consumer products company with a portfolio of iconic brands like Graco®, Coleman...Full time
$140.6k - $175.8k
...desire to protect it for future generations. Role Summary As a Security Engineer at Rivian, you will spearhead the adversarial... ...working in Offensive Security, Red Teaming, Vulnerability Research, Penetration Testing or adjacent role, with a demonstrated ability to...Full timeContract workTemporary workPart timeLocal areaShift work- ...Candescent Chief Information Security Officer (CISO) Candescent is the leading cloud... ...customers, regulators, and independent assessors. Define and monitor security risk metrics... ...and privacy standards. Oversee penetration testing and bug bounty programs, emphasizing...
$43.5k - $48k
...all related activities within the assigned caseload. Your role in our mission Ensure all processes meet HIPAA and government security requirements regarding the sharing and storage of Personal Health Information (PHI). Utilize strong analytical and case...Full timeContract workWork at officeMonday to FridayFlexible hours2 days per week- Southern Company is seeking an Offensive Security Analyst to bolster their Cybersecurity team. This role focuses on identifying and addressing security vulnerabilities in a dynamic environment, with responsibilities including validating risks, conducting threat assessments...
- Southern Company is seeking an Offensive Security Analyst based in Atlanta, GA, focused on evaluating security vulnerabilities within enterprise systems. The role requires a Bachelor’s degree in Computer Science or Cybersecurity and 2+ years of relevant experience. This...
- ...Computer Systems Analyst Assist and/or install, deploy, and test new security operations and other cyber security related support systems. A full and thorough knowledge of modern cyber security computer systems and applications must be maintained to be able to quickly...
$115k - $150k
...Hagerty Consulting, Inc. (Hagerty) is the nation's leading emergency management and homeland security consulting firm. Known for its public spirit, innovative thinking, problem-solving, and exceptional people, Hagerty is sought after to work on some of the largest and...Permanent employmentTemporary workLocal areaImmediate startRemote workFlexible hours$95.86k - $208.27k
...a Senior Specialist, MAST Application Penetration Tester to join our Managed Services practice.... ...GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security... ...Expert (OSWE), Offensive Security Web Assessor (OSWA) Ability to travel as required...H1bLocal area- ...A recruitment agency is seeking a Security Analyst for a remote position in the United States. The role focuses on Zero Trust Network Access (ZTNA) engineering, requiring experience with Zscaler and automation using Terraform and Ansible. This position is initially offered...Remote work
- ...You Will Impact The Firm Remediation, Resolution & Reporting: Analyze scheduled and ad hoc Vulnerability Scans as well as Penetration Tests, including researching findings and their mitigations and remediations as well as assigning out to the appropriate platform...Work at officeRemote workRelocation
- ...Application Security Engineer Position will be hybrid (4 days in office and 1 day remote (remote day can be flexible). 10+ years of experience Strong experience designing and implementing AppSec programs within DevSecOps, including integration of SAST, SCA, DAST, and...Work at officeRemote workFlexible hoursShift work
- ...Senior Security Consultant-Security Solutions- Remote (Anywhere in the U.S.)RemoteGuidePoint Security provides trusted cybersecurity... ...solutions consulting role and 5 years in network and application penetration testing.Proven experience in a client-facing consultative role...Remote workFlexible hours
- ...Information Security Specialist Works within the Governance, Risk and Compliance team to ensure proper controls are in place for solutions moving into company's cloud production platform. Work across teams to ensure teams understand Information Security requirements...
- ...Role: Security Engineer Location: Atlanta, GA, 30328 (5 Days Onsite) Duration: 7+ Months Only W2 Kinexys Workstream:... ...Management: Conduct threat modelling, security reviews, and penetration testing to surface vulnerabilities before exploitation. Drive...
- ...(CA) implementation in compliance with the federal PKI (FPKI) common policy authority. · Conduct technical research and set cloud security direction and strategy · Experience in automating certificate renewal and certificate life cycle management. · Experience with Microsoft...Work experience placement
- ...Senior Security Engineer Immediate need for a talented Senior Security Engineer. This is a 12+months contract opportunity with long... ...compliance, incident response, identity & access management, penetration testing, or e-discovery & forensics. Experience across IT domains...Contract workLocal areaImmediate start
$106k - $126k
...Evaluates application security in all phases of the software development life cycle. Works closely with team members to define application security best practices, performs software architecture and design reviews, and supports the identification, interpretation, and...Contract workWork at office- ...and troubleshooting within Snowflake- ensure person maintain RBAC Can perform KT between existing and new team Existing SAP Security Team- SAP Security team will be taking on Snowflake security configurations- this person is going to help lead that Project...Contract workWork at office
- ...Responsible for the design, testing, evaluation, implementation, support, management, and deployment of security systems/devices used to safeguard the organizations information assets. Also responsible for analyzing the information security environment and assisting with...
- ...healthcare facilities, as requested/needed for meetings. Candidate must work EST business hours.Our direct client has an opening for a Security Engineer w/ Healthcare Exp position # 750759. This position is for 12+ months, with option of extension, and will be worked remote...Hourly payFor contractorsWork experience placementImmediate startRemote work
- ...Capable of leading projects to implement tools in CICD pipelines to aid in conducting Static Application Security Test (SAST), Dynamic Application Security Test (DAST) and Source Code Analysis (SCA) using VeraCode • Experience working with tools such as Sonatype nexus...
- ...Senior Security Engineer Immediate need for a talented Senior Security Engineer. This is a 12+ Months Contract opportunity with long-term potential and is located in Atlanta, GA. Please review the job description below and contact me ASAP if you are interested....Contract workLocal areaImmediate start
- ...Orange Cyber Defense Mid-Level Network Security Engineer Join us at Orange Business! We are a network and digital integrator that understands the entire value chain of the digital world, freeing our customers to focus on the strategic initiatives that shape their business...Work at officeRemote workWork from homeFlexible hours2 days per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Penetration Tester / Security Assessor. Be the first to apply!

