Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Vulnerability Assessment Analyst and Penetration Tester

SteelToad

Position Description The Vulnerability Assessment Analyst and Penetration Tester is responsible for the delivery of continuous cyber assessments, solving complex technology problems, building tools, and identifying and influencing response to and mitigation of threats.Perform manual assessment of systems, services, and software; specializing in security issues beyond those identified by static analysis tools.The individual ensures services, applications, and websites are designed and implemented to the highest security standards.Responsible for application and hardware penetration testing, automating repetitive tasks using various scripting languages, mentoring, and leading other engineers to deliver complex penetration tests and vulnerability assessments.The individual will be expected to drive automation, tooling, efficiency, and advance the teams penetration testing capabilities.Responsible for creating threat mitigation plans. Five years of hands-on penetration testing experience with operating systems, web applications, and network infrastructure. Administrator-level knowledge of Windows and Linux Server operating systems. Experience with operating system security. Competent with testing frameworks and tools, such as Burp Suite, Metasploit, Cobalt Strike, Kali Linux, Nessus, PowerShell Empire. Knowledge of the functionality and capabilities of computer network defense technologies, including router Access Control Lists (ACLs), firewalls, Intrusion Detection System (IDS)/Intrusion Prevention System (IPS), antivirus/Endpoint Detection and Response (EDR), and web content filtering. Strong written and verbal communication skills, including the ability to explain complex technical topics to non-technical audiences. Possess one of the following certifications upon onboarding: Offensive Security Certified Professional (OSCP) Offensive Security Web Assessor (OSWA) Obtain one of the following certifications within 9 months of onboarding: GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) Offsec Experienced Penetration Tester (OSEP) Reports To Assigned Program Manager Security Clearance Requirements Secret Travel Requirements Travel is anticipated to be 10% - 15% within the Continental United States and 5%-10% outside the Continental United States Benefits & Compensation New employees are eligible to participate in the company’s benefits plan on their day of hire unless noted otherwise. Medical Insurance Long Term & Short-Term Disability, Group Life and AD&D Insurance – 100% Employer Paid Health Savings Account 401(k) Savings Plan – 100% match for the first 3% contributed plus 50% of the next 2% contributed. (no vesting period and eligibility is your date of hire). Paid holidays – Eleven (11) per year Paid Time Off - One hundred-twenty (120) accrued hours per year Professional Development Program Salary will be determined based on the individual’s education and experience level Equal Employment Opportunity Policy Statement It is the policy of SteelToad Consulting LLC. and its subsidiaries (the “Company”) not to discriminate against any employee or applicant for employment because of race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, marital status, genetic information, mental or physical disability (and medical condition, for employees in California) or because he or she is a protected veteran. It is also the policy of the Company to take affirmative action to employ and to advance in employment, all persons regardless of race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, marital status, genetic information, mental or physical disability (and medical condition, for employees in California) or protected veteran status, and to base all employment decisions only on valid job requirements. This policy shall apply to all employment actions, including but not limited to recruitment, hiring, upgrading, promotion, transfer, demotion, layoff, recall, termination, rates of pay or other forms of compensation and selection for training, including apprenticeship, at all levels of employment. Employees and applicants of the Company will not be subject to harassment on the basis of race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, marital status, genetic information, mental or physical disability (and medical condition, for employees of California) or because he or she is a protected veteran. Additionally, retaliation, including intimidation, threats, or coercion, because an employee or applicant has objected to discrimination, engaged or may engage in filing a complaint, assisted in a review, investigation, or hearing or have otherwise sought to obtain their legal rights under any Federal, State, or local EEO law is prohibited. NOTE: These statements are intended to describe the general nature and level of work involved for this job. It is not an exhaustive list of all responsibilities, duties, and skills required of this job. #J-18808-Ljbffr

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Vulnerability Assessment Analyst and Penetration Tester in San Diego, CA vacancy
  • $115k - $155k

     ...Job Description Job Description Sigma Defense is seeking a Senior Systems Analyst: Training Technical Assessments SME capable of walking into a Navy training site, understanding the operational C4I system and its installed Fleet configuration, assessing the training... 
    Suggested
    Contract work
    Work at office

    Sigma Defense

    San Diego, CA
    4 days ago
  • $100k - $110k

     ...Cybersecurity Analyst / Information Systems Security Officer (ISSO)Lyntris is a defense...  ..., Risk Management Framework (RMF), and Assessment & Authorization (A&A) activities across...  ...cybersecurity compliance requirements, vulnerability management, and system authorization... 
    Suggested
    Local area

    Accelint

    San Diego, CA
    3 days ago
  • $145k - $165k

     ...coordinating, implementing, and enforcing information system security policies, standards and methodologies. Conducting vulnerability assessments using automated benchmarks and tools such as Assured Compliance Assessment Solution (ACAS), Defense Information Systems... 
    Suggested

    ASEC Inc

    Chula Vista, CA
    1 day ago
  •  ...Responsibilities include but are not limited to: Maintain Assessment & Authorization (A&A) documentation in accordance with JSIG,...  ...Maintain security tools, patch management processes, and vulnerability management programs in coordination with the Cybersecurity team... 
    Suggested
    Work at office
    Local area

    ManTech

    San Diego, CA
    2 days ago
  • $120k - $130k

     ...CA to monitor and maintain systems security on operational systems such as malicious code eradication, configuration management, assessment and authorization of current and future systems, as well as to review and revise systems security documentation on proposed systems... 
    Suggested
    Civilian Contractor
    Work experience placement
    Work at office

    VTG Defense

    San Diego, CA
    3 days ago
  • $95.86k - $208.27k

     ...expand your capabilities, then consider a career in Advisory. KPMG is currently seeking a Senior Specialist, MAST Application Penetration Tester to join our Managed Services practice. Responsibilities: Conduct manual application penetration testing against API'... 
    H1b
    Local area

    KPMG

    San Diego, CA
    2 days ago
  • $140k - $165k

     ...right individual! Senior Cybersecurity Analyst – CONTINGENT - 26-022 – Hybrid As...  ...Plan (SSP), development of Security Assessment Plan (SAP), documentation of NIST 800-5...  ...stakeholders. Help identify cybersecurity vulnerabilities and compliance issues. Work with the... 
    Full time
    Contract work
    For contractors
    Work experience placement
    Remote work

    AUSGAR Technologies Inc.

    San Diego, CA
    9 hours ago
  • $170k - $250k

     ...system design, cyber resilience, RMF execution, compliance, vulnerability management, and cross-domain integration activities. This position...  ..., such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification... 
    Full time
    Temporary work
    Part time
    Worldwide

    Shield Ai

    San Diego, CA
    9 hours ago
  •  ...compliance programs. We are looking for a Sr. Computer Systems Analyst in San Diego, California . Contingent Upon Contract Award Summary...  ...systems engineering, integration, and application issues. Assesses workflows, evaluates system capabilities, and designs enhancements... 
    Contract work
    For contractors
    For subcontractor

    T3W Business Solutions

    San Diego, CA
    2 days ago
  • $61.9k - $141k

     ...can identify the tools, applications, and systems needed to assess vulnerabilities and recommend the best solution and security strategy. We...  ...intrusion prevention systems, vulnerability scanners, and penetration toolsExperience responding to computer security breaches... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    San Diego, CA
    2 days ago
  • $84k - $139.95k

     ...knowledge, skills, and abilities of the applicant, internal equity, and alignment with market data. Description Developing and updating assessment and authorization documentation (Body of Evidence) for management and continuous monitoring of information systems Performing... 
    For contractors
    Local area

    Scientific Research

    San Diego, CA
    3 days ago
  • $95k - $141k

     ...not limited to: Support Risk Management Framework (RMF), Assessment & Authorization (A&A), and Authorization to Operate (ATO) activities...  ...management. Track, document, and support remediation of vulnerabilities, STIG findings, POA&M items, and other cybersecurity risks.... 
    Contract work
    Work at office
    Remote work

    XSITE LLC

    San Diego, CA
    17 days ago
  • $45 - $60 per hour

     ...Job Summary The Senior IT Systems Analyst - Contractor reports to the Head of Information...  ...SOX 404 compliance, including gap assessments and mitigations; learn / assist with...  ...monitoring, identifying and remediating vulnerabilities, configuring Group Policy and Active Directory... 
    Full time
    For contractors
    Work experience placement

    Artiva Biotherapeutics

    San Diego, CA
    15 days ago
  •  ...and strategic security enforcement solutions, independent of the analyst track.Security Policy Enforcement & EngineeringLead security...  ...stakeholders to understand business and technical requirements, assess cybersecurity risks, and recommend practical security architectures... 
    Part time
    Remote work
    Relocation package

    General Atomics

    San Diego, CA
    6 days ago
  • $107.9k - $195.05k

     ...effectively collaborating with cybersecurity analysts, system administrators, engineers,...  ..., RMF, secure system administration, vulnerability management, configuration management, and...  ...statements, POA&Ms, risk assessments, continuous monitoring artifacts, and supporting... 
    Temporary work
    Work at office
    Local area
    Immediate start

    Leidos

    La Jolla, CA
    1 day ago
  • $150k - $185k

     ...The ISSM is responsible for attaining and maintaining system assessments and authorizations through government authorizing agencies from...  .../ or corrective measures have been taken when an incident or vulnerability has been discovered.Communicate, implement, and manage a... 
    Immediate start
    Flexible hours

    Systems Planning and Analysis, Inc

    San Diego, CA
    3 days ago
  • $140k - $180k

     ...classified information, ensuring compliance with all applicable government regulations and directives.Conduct regular risk assessments and vulnerability analyses to identify and mitigate potential security threats, including those related to classified information systems.... 
    Permanent employment
    Temporary work
    Work at office
    Local area
    Worldwide
    Relocation
    Relocation package

    Firestorm

    San Diego, CA
    3 days ago
  • $95k - $125k

     ...compliance activities. The ISSE will also contribute to STIG assessments and remediation efforts, including support for Microsoft 365...  ...posture of assigned systems, identifying and tracking vulnerabilities to closure ~Assist in the development and maintenance of... 
    Contract work
    Interim role
    Work at office

    The Marlin Alliance, Inc.

    San Diego, CA
    16 days ago
  • $123k - $163k

     ...You will partner with Compliance, Legal, and Risk to ensure workflows align with business and regulatory needs. You will assess vulnerabilities, recommend remediation, and stay up to date on emerging threats and defenses. You will train and mentor other incident... 
    Hourly pay
    Contract work
    Part time

    Kforce Technology Staffing

    San Diego, CA
    9 days ago
  •  ...potential findings from programs such as bug bounty, vulnerability disclosure and penetration testing. Additionally, you will provide augmented support...  ...: * Triage incoming bug bounty reports while assessing severity and impact * Provide input into high-quality... 
    Temporary work
    San Diego, CA
    9 days ago
  •  ...decisions * Collaborate with Compliance, Legal, and Risk to ensure response workflows meet business and regulatory requirements * Assess vulnerabilities, propose remediation, and stay current on emerging threats and countermeasures * Provide training and mentorship to other... 
    Contract work
    Temporary work
    Part time
    Remote work
    San Diego, CA
    9 days ago
  • $160k - $240k

     ...artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by... 
    Full time
    Temporary work
    Part time
    Worldwide

    Shield Ai

    San Diego, CA
    9 hours ago
  • $75 - $90 per hour

     ...stakeholders at all levels* Develop reports, presentations, and deliverables for both technical and executive audiences* Conduct risk assessments, business impact analyses, tabletop exercises, and incident response planning activities* Collaborate with internal teams to... 

    KForce

    San Diego, CA
    2 days ago
  • $110k - $155k

     ...Cybersecurity Analyst ROLE We need an experienced Cybersecurity Analyst...  ...expert reviewing cybersecurity assessment reports, identify vulnerabilities and residual risks affecting DoW missions...  ...assessment methodologies, penetration testing results, vulnerability assessments... 
    Full time
    Contract work
    Interim role
    Work at office
    Relocation
    Relocation package

    West 4th Strategy

    San Diego, CA
    4 days ago
  • $117k - $130k

     ...timeDescriptionThe Cybersecurity Analyst leads Bumble Bee’s day-to-...  ..., and track patching and vulnerability remediation.· Collaborate with...  ....· Conduct security risk assessments for existing and prospective...  ...CIS).· Tabletop exercise and penetration testing experience.· Understanding... 
    Full time
    Local area
    Flexible hours

    Bumble Bee Foods

    San Diego, CA
    2 days ago
  •  ...Summary The Cybersecurity Analyst will serve as a technical...  ...will review cybersecurity assessment reports and supporting technical...  ..., evaluate potential vulnerabilities and risks, and provide technical...  ...technologies. Interpret penetration testing results,... 
    Contract work
    Immediate start

    OSI VISION LLC

    San Diego, CA
    15 days ago
  •  ...Boarhog is in the market for a mid-level Cybersecurity Analyst in San Diego, CA. with an active SECRET level...  ...systems, including continuous monitoring vulnerability management Prepare and present risk assessment briefs, including High-Risk Escalation, for executives... 
    Full time
    Work at office
    Immediate start
    Relocation package

    Boarhog LLC

    San Diego, CA
    17 days ago
  • $135k - $160k

     ...including system categorization, security control implementation, assessment, authorization, and continuous monitoring to maintain...  ...through eMASS. Strengthens Enterprise Security: Performs vulnerability scanning, system hardening, patch management, and remediation... 
    Full time
    For contractors
    Interim role
    Work visa
    Flexible hours

    Innoflight LLC

    San Diego, CA
    a month ago
  • $131k - $169k

     ...surface reduction and MFA. Identify and assess security risks introduced by AI tools - You...  ...and testing fixes Working with external penetration test companies to validate and prioritize findings Conducting risk and vulnerability assessments of web applications and APIs... 
    Work at office
    Work from home
    Flexible hours
    Day shift

    Karbon

    San Diego, CA
    5 days ago
  •  ...list management following established procedures. - Support vulnerability management activities, including scanning coordination, remediation...  ...process-including accessing job postings, completing assessments, or participating in interviews,-please contact People Operations... 
    Minimum wage
    Contract work
    Temporary work
    Work experience placement
    Remote work

    MAXIMUS

    San Diego, CA
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Vulnerability Assessment Analyst and Penetration Tester. Be the first to apply!