Penetration Tester / Security Assessor
$90k - $109kASM Research, An Accenture Federal Services Company
Creates cyber-intelligence tools / methods and performs research and analysis in order to mitigate and eliminate data and cyber security risks. Designs and develops acceptance criteria for cybersecurity architecture.
Perform infrastructure penetration testing to discover and exploit vulnerabilities to test the effectiveness of the organization's security posture.
Perform web application penetration testing to identify and exploit OWASP Top 10 web application vulnerabilities.
Leverage threat intelligence to emulate known threat actors' tactics, techniques, and procedures.
Partner with various cybersecurity teams to improve automation and detection of threat actors.
Engage with technical and non-technical audiences to articulate both techniques and results.
Minimum Qualifications
Bachelor's Degree in Computer Science or a related field or equivalent experience.
5-10 years of experience in systems security with a minimum of 2+ years in information security, penetration testing, or ethical hacking.
Other Job Specific Skills
Must possess demonstrated experience planning and conducting penetration tests against networks and web applications.
Demonstrated experience conducting vulnerability assessments and penetration tests.
Expertise with tools such as Bloodhound, Burp Suite, Cobalt Strike, Metasploit, and Mimikatz.
Hands-on experience with penetration testing tools and frameworks.
Portfolio of security assessments or CTF achievements (preferred).
Experience with network scanning, enumeration, and exploiting vulnerabilities.
Proficiency in Windows, Linux, and macOS environments.
Understanding of system hardening techniques and common misconfigurations.
Knowledge of programming languages like Python, Ruby, or JavaScript for creating custom scripts and exploits.
Familiarity with bash, PowerShell, or other scripting languages for automation.
Understanding of web technologies, including HTML, JavaScript, and SQL.
Preferred Skills
Experience in identifying and exploiting vulnerabilities in web applications, networks, and systems.
Familiarity with CVSS (Common Vulnerability Scoring System) and understanding how to prioritize vulnerabilities based on risk.
Ability to analyze and critique code for security vulnerabilities.
Familiarity with common vulnerabilities such as SQL injection, XSS (Cross-Site Scripting), CSRF (Cross-Site Request Forgery), and buffer overflows.
Strong understanding of network protocols, architecture, and components (e.g., TCP/IP, DNS, VPNs, firewalls, routers, switches).
Compensation Ranges
Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.
EEO Requirements
It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.
All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment.
Physical Requirements
The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, "light office duties' or "lifting up to 50 pounds" or "some travel" required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions.
Disclaimer
The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.
$90k - $109k
EEO Requirements
It is the policy of ASM that an individual's race, color, religion, sex, disability, age, gender identity, veteran status, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.
All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, veteran status, disability, gender identity, or age. All decisions on employment are made to abide by the principle of equal employment.
- Constellation Technologies, Inc in Maryland is seeking a Security Engineer with a focus on Risk Management Framework (RMF) and penetration testing. The ideal candidate must have an active TS/SCI clearance and extensive knowledge of security tools such as NMAP and Wireshark...Suggested
- What You Will Do At Independent Software, we understand that proactive security testing is critical to defending mission systems. As a Penetration Tester, you will serve as a subject matter expert in assessing the security of networks, systems, and applications. You will...SuggestedContract work
$95k - $105k
Overview AGE Solutions is looking for Senior Security Control Assessors to join our team in support of a cybersecurity risk management and assessment program with our DoD customer. Responsibilities Conduct cybersecurity assessments, audits, and inspections for DoD organizations...SuggestedContract workImmediate start$85k - $130k
Job Title Security Control Assessor Level 2 Location Annapolis Junction, MD Hours Regular Full-Time Salary Range $85k/yr - $130k/yr Clearance... ...Provide vulnerability assessment of the system, coordinate penetration testing, and provide a comprehensive verification and validation...SuggestedFull timeFlexible hours- A leading consulting firm located in Maryland is seeking a Security Control Assessor Level 2. The role requires conducting security compliance evaluations and vulnerability assessments, validating that systems meet security requirements. Candidates must have at least five...Suggested
- A leading cybersecurity firm is seeking a Senior Security Control Assessor to support their DoD customer in cybersecurity risk management. Responsibilities include conducting assessments, evaluating systems, and providing risk analysis. Candidates should possess significant...
$76.4k - $138.6k
...more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost 950 people who collaborate to support the business of EY by protecting...Summer holidayLocal areaFlexible hours$131.3k - $237.35k
...Leidos has a new and exciting opportunity for a Senior Information Systems Security Officer (ISSO) in our Intelligence Sector, Cyber & Analytics Business Area (CABA) . Our talented team is at the forefront in Security Engineering, Computer Network Operations (CNO)...Contract workImmediate startRelocation packageFlexible hours$1,500 - $3,000 per month
...to inspiring growth on our team, while balancing lifestyle by supporting personal and family goals with flexibility. Tulzi offers secure network systems and software engineering solutions in both the public and private sectors. With certified expert consulting the team...Hourly payTemporary workLocal area$7.5k
...Job Brief Evaluating security solutions to ensure compliance with requirements for processing classified information. Job Description RealmOne was built on the principle that people matter first and foremost. We believe in providing a strong work/life balance...Work experience placementImmediate startFlexible hours- ...What You Will Do: At Independent Software, as a Senior Information System Security Officer (ISSO), you will support the security posture of mission-critical systems, programs, and enclaves. In this role, you will implement, maintain, and enforce information assurance...
- ...developing tip-of-the-spear capabilities to providing support for ongoing mission-critical operations. With high demand from our National Security customers for our talent and expertise, our employees are shaping the future in support of our customer's most critical needs and...Contract workWork at officeImmediate startFlexible hours
- ...Open Systems Technologies Corporation is a leader in the government contracting marketplace, providing Enterprise Security and Cloud Computing solutions to support large organizations. Our capabilities include supplying federal government entities and private businesses...Immediate startRelocation package
$170k - $230k
...Information Systems Security Officer (ISSO) Ft. Meade Area, MD • Government/Military Clearance Required: TS/SCI with Polygraph Full-Time | Fully Funded | $170K-$230K Secure the Mission. Set the Standard in Cybersecurity. Helm Point Solutions...Full timeFlexible hours- ...Description Kaizen Approach is currently seeking an Information Systems Security Officer (ISSO) to provide support for a program, organization, system, or enclave's information assurance program. In this role, the ISSO will support proposing, coordinating, implementing...Contract workFor contractorsWork experience placement
$160k - $200k
...information assurance program. Provides support for proposing, coordinating, implementing, and enforcing information systems security policies, standards, and methodologies. Maintains operational security posture for an information system or program to ensure...Local area- ...What you will be doing! As an Information System Security Officer, you will support a program, organization, system, or enclave's information assurance program. You will support proposing, coordinating, implementing, and enforcing information systems security policies...
- ...What You Will Do: As an Information Systems Security Officer at Independent Software, you will play a critical role in strengthening and defending the security posture of mission-critical systems supporting the Department of Defense and Intelligence Community. You...
$100k - $145k
...POSITION OVERVIEW Position: Senior Web Application Penetration Tester Job Type: Full Time Location: Remote US. Proximity to... ...to date with evolving web technologies, threat trends, and security tools to ensure cutting‑edge testing practices. REQUIRED...Full timeTemporary workWork experience placementRemote workFlexible hours- .... POSITION OVERVIEW Position: Senior Web Application Penetration Tester Job Type: Full-time Location: Maryland, Northern Virginia... ...candidate will possess deep expertise in web application security testing, vulnerability research, and exploitation techniques...Full timeTemporary workRemote workFlexible hours
$134.1k - $241.4k
...for a Cyber Vulnerability Analyst with a background in Red Team/Penetration Testing to join our team. In this role you will be responsible... ...experience working in the areas of intelligence, information security, network forensics, insider threat or security operations....Flexible hours$170k - $215k
Information Assurance, IAVA, System Security Plans (SSPs), RMF, Windows, Linux, Authorization to Operate, Verification and Validation, Security+, Security X, CASP+, NIST 800-53 Due to federal contract requirements, United States citizenship and an active TS/SCI security...Contract workTemporary workImmediate start- ...of TEMPEST engineers and SMEs helping perform TEMPEST testing and provide TEMPEST engineering recommendations to help ensure the security of our nation's systems . You'll learn from our existing TEMPEST subject matter experts to grow your knowledge and skills, as well...Visa sponsorshipWork visa
$115k - $150k
...Hagerty Consulting, Inc. (Hagerty) is the nation's leading emergency management and homeland security consulting firm. Known for its public spirit, innovative thinking, problem-solving, and exceptional people, Hagerty is sought after to work on some of the largest and...Permanent employmentTemporary workLocal areaImmediate startRemote workFlexible hours- Job Overview Application Penetration Tester at ASM Research, an Accenture Federal Services Company located in Annapolis, MD. In this role you... ...OWASP Top10 and SANS25 to identify, mitigate, and remediate security vulnerabilities. Responsibilities Perform thorough security...Contract workWork at office
$183.6k - $221.6k
...requirements and provide advanced design and implementation across technologies. The role demands direct engagement with customers, formal security testing, and the ability to troubleshoot technical issues effectively. Applicants should have an active TS/SCI clearance and at...- A leading technology security firm is seeking a Senior Systems Analyst to support a DOD customer in Maryland. The ideal candidate will have at least 10 years of experience in data analytics and SharePoint development, with an Active Top-Secret clearance required. The role...
$106k - $126k
...Evaluates application security in all phases of the software development life cycle. Works closely with team members to define application security best practices, performs software architecture and design reviews, and supports the identification, interpretation, and...Contract workWork at office$40 per hour
...train AI models. In this role, you will evaluate AI-generated security content, solve technical cybersecurity problems, and provide feedback... ...2+ years of hands‑on experience in cybersecurity (e.g., penetration testing, red teaming, incident response, detection engineering...Hourly payFull timePart timeRemote work$225k - $235k
...capabilities to traditional on premises and cloud environments. The ideal candidate should have a strong background in endpoint security, cloud applications, Windows forensics, large enterprise endpoint deployments, and SOC analyst support. Required Experience...Full timeImmediate startRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Penetration Tester / Security Assessor. Be the first to apply!

