Vulnerability Assessment Analyst and Penetration Tester
SteelToad
Position Description The Vulnerability Assessment Analyst and Penetration Tester is responsible for the delivery of continuous cyber assessments, solving complex technology problems, building tools, and identifying and influencing response to and mitigation of threats.Perform manual assessment of systems, services, and software; specializing in security issues beyond those identified by static analysis tools.The individual ensures services, applications, and websites are designed and implemented to the highest security standards.Responsible for application and hardware penetration testing, automating repetitive tasks using various scripting languages, mentoring, and leading other engineers to deliver complex penetration tests and vulnerability assessments.The individual will be expected to drive automation, tooling, efficiency, and advance the teams penetration testing capabilities.Responsible for creating threat mitigation plans. Five years of hands-on penetration testing experience with operating systems, web applications, and network infrastructure. Administrator-level knowledge of Windows and Linux Server operating systems. Experience with operating system security. Competent with testing frameworks and tools, such as Burp Suite, Metasploit, Cobalt Strike, Kali Linux, Nessus, PowerShell Empire. Knowledge of the functionality and capabilities of computer network defense technologies, including router Access Control Lists (ACLs), firewalls, Intrusion Detection System (IDS)/Intrusion Prevention System (IPS), antivirus/Endpoint Detection and Response (EDR), and web content filtering. Strong written and verbal communication skills, including the ability to explain complex technical topics to non-technical audiences. Possess one of the following certifications upon onboarding: Offensive Security Certified Professional (OSCP) Offensive Security Web Assessor (OSWA) Obtain one of the following certifications within 9 months of onboarding: GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) Offsec Experienced Penetration Tester (OSEP) Reports To Assigned Program Manager Security Clearance Requirements Secret Travel Requirements Travel is anticipated to be 10% - 15% within the Continental United States and 5%-10% outside the Continental United States Benefits & Compensation New employees are eligible to participate in the company’s benefits plan on their day of hire unless noted otherwise. Medical Insurance Long Term & Short-Term Disability, Group Life and AD&D Insurance – 100% Employer Paid Health Savings Account 401(k) Savings Plan – 100% match for the first 3% contributed plus 50% of the next 2% contributed. (no vesting period and eligibility is your date of hire). Paid holidays – Eleven (11) per year Paid Time Off - One hundred-twenty (120) accrued hours per year Professional Development Program Salary will be determined based on the individual’s education and experience level Equal Employment Opportunity Policy Statement It is the policy of SteelToad Consulting LLC. and its subsidiaries (the “Company”) not to discriminate against any employee or applicant for employment because of race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, marital status, genetic information, mental or physical disability (and medical condition, for employees in California) or because he or she is a protected veteran. It is also the policy of the Company to take affirmative action to employ and to advance in employment, all persons regardless of race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, marital status, genetic information, mental or physical disability (and medical condition, for employees in California) or protected veteran status, and to base all employment decisions only on valid job requirements. This policy shall apply to all employment actions, including but not limited to recruitment, hiring, upgrading, promotion, transfer, demotion, layoff, recall, termination, rates of pay or other forms of compensation and selection for training, including apprenticeship, at all levels of employment. Employees and applicants of the Company will not be subject to harassment on the basis of race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, marital status, genetic information, mental or physical disability (and medical condition, for employees of California) or because he or she is a protected veteran. Additionally, retaliation, including intimidation, threats, or coercion, because an employee or applicant has objected to discrimination, engaged or may engage in filing a complaint, assisted in a review, investigation, or hearing or have otherwise sought to obtain their legal rights under any Federal, State, or local EEO law is prohibited. NOTE: These statements are intended to describe the general nature and level of work involved for this job. It is not an exhaustive list of all responsibilities, duties, and skills required of this job. #J-18808-Ljbffr SteelToad
$115k - $155k
...Job Description Job Description Sigma Defense is seeking a Senior Systems Analyst: Training Technical Assessments SME capable of walking into a Navy training site, understanding the operational C4I system and its installed Fleet configuration, assessing the training...SuggestedContract workWork at office- ...Successfully baseline five (5) client environments using the CIS Critical Security Controls, documented in Bird Rock-approved assessment artifacts, internally reviewed, and presented to customer executive stakeholders. Identify, scope, and roadmap at least one critical...SuggestedTemporary workFor contractorsWork at office
$145k - $165k
...coordinating, implementing, and enforcing information system security policies, standards and methodologies. Conducting vulnerability assessments using automated benchmarks and tools such as Assured Compliance Assessment Solution (ACAS), Defense Information Systems...Suggested$104.2k - $172.9k
...Responsibilities include but are not limited to: Maintain Assessment & Authorization (A&A) documentation in accordance with JSIG,... ...Maintain security tools, patch management processes, and vulnerability management programs in coordination with the Cybersecurity team...SuggestedHourly payContract workTemporary workWork experience placementWork at officeLocal areaRemote work$95.86k - $208.27k
...expand your capabilities, then consider a career in Advisory. KPMG is currently seeking a Senior Specialist, MAST Application Penetration Tester to join our Managed Services practice. Responsibilities: Conduct manual application penetration testing against API'...SuggestedH1bLocal area$95k - $141k
...not limited to: Support Risk Management Framework (RMF), Assessment & Authorization (A&A), and Authorization to Operate (ATO) activities... ...management. Track, document, and support remediation of vulnerabilities, STIG findings, POA&M items, and other cybersecurity risks....Contract workWork at officeRemote work- ...Job Description Job Description Software System Tester The Software/System Tester will be responsible for validating the functionality, reliability, and performance of Piper’s technology solutions. The tester will execute structured testing of software, hardware...Full timeTemporary work
$45 - $60 per hour
...Job Summary The Senior IT Systems Analyst - Contractor reports to the Head of Information... ...SOX 404 compliance, including gap assessments and mitigations; learn / assist with... ...monitoring, identifying and remediating vulnerabilities, configuring Group Policy and Active Directory...Full timeFor contractorsWork experience placement- ...security features on internal test platforms, conduct security assessments, and drive the resolution of security issues, including those... ..., firmware, and software, including security assessment, vulnerability analysis, and developing and applying fixes Experience provisioning...Work at office
$131k - $169k
...surface reduction and MFA. Identify and assess security risks introduced by AI tools -... ...testing fixes ~ Working with external penetration test companies to validate and prioritize findings ~ Conducting risk and vulnerability assessments of web applications and APIs...Work at officeWork from homeFlexible hoursDay shift$95k - $125k
...compliance activities. The ISSE will also contribute to STIG assessments and remediation efforts, including support for Microsoft 365... ...posture of assigned systems, identifying and tracking vulnerabilities to closure ~Assist in the development and maintenance of...Contract workInterim roleWork at office- ..., to include auditing the network for vulnerabilities, identifying relevant threats, recommending... ...metrics and reporting to demonstrate assessment coverage and remediation effectiveness... ...security assessment, scanning and penetration testing Design, implementation, management...Contract workWork experience placementRemote work
$123k - $163k
...You will partner with Compliance, Legal, and Risk to ensure workflows align with business and regulatory needs. You will assess vulnerabilities, recommend remediation, and stay up to date on emerging threats and defenses. You will train and mentor other incident...Hourly payContract workPart time- ...decisions * Collaborate with Compliance, Legal, and Risk to ensure response workflows meet business and regulatory requirements * Assess vulnerabilities, propose remediation, and stay current on emerging threats and countermeasures * Provide training and mentorship to other...Contract workTemporary workPart timeRemote work
- ...potential findings from programs such as bug bounty, vulnerability disclosure and penetration testing. Additionally, you will provide augmented support... ...: * Triage incoming bug bounty reports while assessing severity and impact * Provide input into high-quality...Temporary work
- ...an alternative application process. Cybersecurity Analyst 7 days ago Requisition ID: 1151 About OWT Global Founded... ...800-53 and DoD 8500.2 / RMF requirements. Support vulnerability management programs, security assessments, remediation tracking, and the development of...Contract workTemporary workImmediate start
$153.47k - $255.75k
...implementing zero-trust architectures and secure DevOps practices across diverse IT environments. Threat modeling, risk assessment, and vulnerability management, coupled with experience in SIEM implementation, log analysis, and incident response in complex enterprise...Work from homeFlexible hours$110k - $155k
...Cybersecurity Analyst ROLE We need an experienced Cybersecurity Analyst... ...expert reviewing cybersecurity assessment reports, identify vulnerabilities and residual risks affecting DoW missions... ...assessment methodologies, penetration testing results, vulnerability assessments...Full timeContract workInterim roleWork at officeRelocationRelocation package- ...Summary The Cybersecurity Analyst will serve as a technical subject... ...will review cybersecurity assessment reports and supporting... ...evidence, evaluate potential vulnerabilities and risks, and provide... ...related technologies. Interpret penetration testing results,...Contract workImmediate start
- ...Boarhog is in the market for a mid-level Cybersecurity Analyst in San Diego, CA. with an active SECRET level... ...systems, including continuous monitoring vulnerability management Prepare and present risk assessment briefs, including High-Risk Escalation, for executives...Full timeWork at officeImmediate startRelocation package
$120k - $155k
...exciting new opportunity for a Cybersecurity Analyst to join our team of smart and... ...Security Plan (SSP), development of Security Assessment Plan (SAP), documentation of NIST 800-5... .... Help identify Cybersecurity vulnerabilities and compliance issues. Work with the program...Full timeContract workFor contractorsWork experience placementRemote work$135k - $160k
...including system categorization, security control implementation, assessment, authorization, and continuous monitoring to maintain... ...through eMASS. Strengthens Enterprise Security: Performs vulnerability scanning, system hardening, patch management, and remediation...Full timeFor contractorsInterim roleWork visaFlexible hours$117.7k - $154.4k
...across a range of project types and sizes. Manage potential changes to the scope of work requested by clients and consultants; assess the impact on the project budget and schedule for larger projects. Review and evaluate documents for accuracy, coordinating with...For contractors- ...Architect with strong expertise in AWS cloud infrastructure, cost optimization, and architecture reviews. The ideal candidate will lead assessments across AWS environments, identify cost-saving opportunities, and recommend scalable, high-performance cloud solutions. Key...
$97k - $110k
...holidays, tuition reimbursement, and more. GENERAL JOB SUMMARY Conducts audits of internal information technology system and risk assessments. Develops and implements an audit and control framework to monitor IT production environments for potential system integrity,...Full timeTemporary workWork experience placementWork at office- ...construction defects. Day-to-day responsibilities include reviewing architectural and construction documents, performing diagnostic assessments, coordinating with consultants, and preparing technical reports that support litigation, mediation, and settlement discussions....Full timeWork at office
$105.78k - $189.35k
...on cloud best practices, AI implementation patterns, and modern software design principles. Conduct architecture reviews, risk assessments, and proof‑of‑concept initiatives to validate technology decisions and drive innovation. Lead application rationalization initiatives...Full timeWork at officeLocal area- ...The AI Solutions Architect will identify high-value use cases, assess technical feasibility during workshops, and develop prototypes... ...latest widely available features including Cortex Agents, Cortex Analyst (plus semantic views), Cortex Search, Snowflake SECRET, and...Contract work
- ...Architect with strong expertise in AWS cloud infrastructure, cost optimization, and architecture reviews. The ideal candidate will lead assessments across AWS environments, identify cost-saving opportunities, and recommend scalable, high-performance cloud solutions. Key...
$120k
...Skills/Must Have: New deployment or refresh of existing network equipment (route, switch, wireless) Network and systems assessment and design Physical to virtual (P2V) migration Storage (NAS) deployment and upgrade Azure AD migration Endpoint detection...Full timeWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vulnerability Assessment Analyst and Penetration Tester. Be the first to apply!


