Vulnerability Assessment Analyst and Penetration Tester
SteelToad
Vulnerability Assessment Analyst and Penetration Tester Position Description The Vulnerability Assessment Analyst and Penetration Tester is responsible for the delivery of continuous cyber assessments, solving complex technology problems, building tools, and identifying and influencing response to and mitigation of threats. Perform manual assessment of systems, services, and software; specializing in security issues beyond those identified by static analysis tools. The individual ensures services, applications, and websites are designed and implemented to the highest security standards. Responsible for application and hardware penetration testing, automating repetitive tasks using various scripting languages, mentoring, and leading other engineers to deliver complex penetration tests and vulnerability assessments. The individual will be expected to drive automation, tooling, efficiency, and advance the team’s penetration testing capabilities. Responsible for creating threat mitigation plans. Qualifications Five years of hands‑on penetration testing experience with operating systems, web applications, and network infrastructure. Administrator‑level knowledge of Windows and Linux Server operating systems. Experience with operating system security. Competent with testing frameworks and tools, such as Burp Suite, Metasploit, Cobalt Strike, Kali Linux, Nessus, PowerShell Empire. Knowledge of the functionality and capabilities of computer network defense technologies, including router Access Control Lists (ACLs), firewalls, Intrusion Detection System (IDS)/Intrusion Prevention System (IPS), antivirus/Endpoint Detection and Response (EDR), and web content filtering. Strong written and verbal communication skills, including the ability to explain complex technical topics to non‑technical audiences. Possess one of the following certifications upon onboarding: Offensive Security Certified Professional (OSCP) Offensive Security Web Assessor (OSWA) Obtain one of the following certifications within 9 months of onboarding: GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) Offsec Experienced Penetration Tester (OSEP) Reports To Assigned Program Manager Security Clearance Requirements Secret Travel Requirements Travel is anticipated to be 10% - 15% within the Continental United States and 5% - 10% outside the Continental United States. Benefits & Compensation New employees are eligible to participate in the company’s benefits plan on their day of hire unless noted otherwise. Medical Insurance Long Term & Short-Term Disability, Group Life and AD&D Insurance – 100% Employer Paid Health Savings Account 401(k) Savings Plan – 100% match for the first 3% contributed plus 50% of the next 2% contributed. (no vesting period and eligibility is your date of hire). Paid holidays – Eleven (11) per year Paid Time Off – One hundred‑twenty (120) accrued hours per year Professional Development Program Salary will be determined based on the individual’s education and experience level Overview Lumbee Holdings is a leading provider of IT Support, Cybersecurity and Training and Development to the Department of Defense (DoD) and other government agencies. Equal Employment Opportunity Policy Statement It is the policy of Lumbee Tribe Holdings, Inc. and its subsidiaries (the “Company”) not to discriminate against any employee or applicant for employment because of race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, marital status, genetic information, mental or physical disability (and medical condition, for employees in California) or because he or she is a protected veteran. It is also the policy of the Company to take affirmative action to employ and to advance in employment, all persons regardless of race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, marital status, genetic information, mental or physical disability (and medical condition, for employees in California) or protected veteran status, and to base all employment decisions only on valid job requirements. This policy shall apply to all employment actions, including but not limited to recruitment, hiring, upgrading, promotion, transfer, demotion, layoff, recall, termination, rates of pay or other forms of compensation and selection for training, including apprenticeship, at all levels of employment. Employees and applicants of the Company will not be subject to harassment on the basis of race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, marital status, genetic information, mental or physical disability (and medical condition, for employees of California) or because he or she is a protected veteran. Additionally, retaliation, including intimidation, threats, or coercion, because an employee or applicant has objected to discrimination, engaged or may engage in filing a complaint, assisted in a review, investigation, or hearing or have otherwise sought to obtain their legal rights under any Federal, State, or local EEO law is prohibited. NOTE: These statements are intended to describe the general nature and level of work involved for this job. It is not an exhaustive list of all responsibilities, duties, and skills required of this job. Seniority Level Mid‑Senior level Employment Type Full‑time Job Function Business Development and Sales Industries Computer and Network Security #J-18808-Ljbffr SteelToad
- A technology services provider is seeking IT Professionals for vulnerability assessment roles in Annapolis, MD. The positions involve conducting credentialed scans of systems, analyzing and reporting network vulnerabilities, and ensuring compliance with COBIT 5 standards...Suggested
$50k - $290k
A leading consulting firm is seeking a Network Evaluator to assess and improve operational networks in Annapolis Junction, MD. Candidates must evaluate vulnerabilities, recommend countermeasures, and support security solutions. A Bachelor’s degree with relevant experience...Suggested- ...ATT&CK, CVSS, and NIST frameworks to assess vulnerability severity and risk impact. In-depth understanding... ...plus. Completed multiple Hack-The-Box penetration testing labs and challenges,... ...seeking a Cybersecurity Vulnerability Analyst in our Linthicum, MD office in support...SuggestedWork at office
- A cybersecurity firm located in Annapolis, Maryland, seeks a Vulnerability Assessment Analyst and Penetration Tester to enhance security measures through continuous assessments and penetration testing. The ideal candidate will possess five years of hands-on experience with...SuggestedFull time
- PD Inc International is seeking a Senior Unix and Linux Vulnerability Analyst to support U.S. government cybersecurity operations at Fort Meade... ...report vulnerabilities in UNIX, Linux, and related assets, assess security controls, and explain risk implications to stakeholders...Suggested
- Senior Unix and Linux Vulnerability Analyst Job Title: Senior Unix and Linux Vulnerability Analyst Location: Fort Meade, MD 20755 Clearance... ...Subtask 3 - UNIX and Linux Compliance Validation and Support. Assess, audit, review, analyze, validate, and report UNIX and Linux...Full timeTemporary workWork experience placementCasual workWork at office
- Job Title: Senior Database Vulnerability Analyst Location: Fort Meade, MD 20755 Clearance Level: Active Secret Clearance Job Type: Full-Time... ...Partners. Application Compliance Validation and Support Assess, audit, review, analyze, validate, and report database Security...Full timeWork experience placementCasual work
- Senior Network Vulnerability Analyst Location: Fort Meade, MD 20755 Clearance Level: Active Secret Clearance Job Type: Full‑Time PD Inc International is seeking an experienced and mission‑driven Senior Network Vulnerability Analyst to provide Cybersecurity Management...Full timeWork experience placementCasual workWork at office
- Junior Penetration Tester—Cyber Engineer at CACI in Aberdeen Proving Ground, MD. You will join a dedicated team of engineers performing hands-on assessments of complex systems using penetration testing and threat-hunting techniques on site. Required active Secret clearance...
$76k - $155.7k
Job Title: Junior Penetration Tester - Cyber Engineer Job Category: Engineering Time Type:... ...role will involve performing in-depth assessments and analyses of sophisticated systems... ...Top 10, DoD, NSA, or industry-standard Vulnerability and Penetration Testing Standards...Full timeContract workWork experience placementFlexible hours- PD Inc International is seeking a Senior Network Vulnerability Analyst to support a U.S. government (DoD) environment, based in Fort Meade, MD. The role requires Active Secret Clearance, full-time commitment, and advanced cybersecurity capabilities. Ideal candidates have...Full timeWork at office
- Overview Tharros is seeking Cyber Security Vulnerability Researcher, Forensic Analyst to conduct digital forensic analysis and incident response in support of NAWCAD Cyber Warfare Division programs at NAS Patuxent River, MD. The CSVR Forensic Analyst applies advanced...
- Tharros is seeking a Cyber Security Vulnerability Researcher, Forensic Analyst to conduct digital forensic analysis and incident response in support of NAWCAD Cyber Warfare Division programs at NAS Patuxent River, MD. The role involves reverse engineering, malware analysis...
$90k - $120k
...professionals in the following areas: Network Analysts (Cyber, Forensic, Signals, Exploitation etc) Vulnerability Analysts Data Analysts Penetration Testers Malware Analysts Others… Overview Be... ..., comprehensive vulnerability assessments and/or analysis of network...Local areaRemote work- ...Vulnerability Management AnalystLocation: Crownsville, MD (Remote) Duration: 6+ MonthsJob Description: Need 12+ years of experience with NIST Risk Management Framework (RMF) supporting technical assessment (vulnerability scans) of control implementations and continuous...Remote workWeekend work
$90k - $120k
...professionals in the following areas: Network Analysts (Cyber, Forensic, Signals, Exploitation etc) Vulnerability Analysts Data Analysts Penetration Testers Malware Analysts Others… Overview Be... ..., comprehensive vulnerability assessments and/or analysis of network...Local areaRemote work- Public Works OT Cyber Security Manager (Systems Analyst) is responsible for the department’s digital defense... ..., including those for endpoint security, vulnerability management, email security, vendor risk assessment, and security awareness. Their primary objective...Work experience placementWork at officeNight shiftWeekend work
- ...503 compliance frameworks, along with active TS/SCI clearance with CI Polygraph.Key Responsibilities• Conduct technical security assessments and risk analysis • Ensure system compliance with RMF and ICD 503 frameworks • Support full lifecycle ATO/IATT processesDocumentation...Full time
$131.3k - $237.35k
...implementing strategies to detect and mitigate threats to information systems, protect critical data sets, and provide assessments of system and network vulnerabilities. Primary Roles and Responsibilities Provide support for implementing and enforcing information...Immediate startFlexible hours$111.16k - $150.39k
...cybersecurity advisor on system security posture, threats, vulnerabilities, and compliance requirements Maintain and update security... ...managing authorization package documentation, vulnerability assessments, and STIG compliance Ability to evaluate system risks,...Temporary workImmediate startRemote workWorldwideFlexible hours- ...Responsibilities: Conduct comprehensive technical security assessments and contribute to the design of secure systems. Manage risk... ...Collaborate with application leads, DBAs, developers, and testers to achieve and maintain Authority to Operate (ATO). Develop...Full timeInterim roleFlexible hours
- ...compliance teams to monitor system security, conduct audits, manage vulnerabilities, and support accreditation efforts, including System... ..., procedures, and SSP requirements Perform vulnerability assessments and scans, including user accounts, application access, file...
$115k - $240k
...multiple Computer Network Defense Analysts (CNDAs) to support a... ...sources to identify and analyze vulnerabilities, detect potential or active... ...form hypotheses, critically assess and choose analysis... ...security, vulnerability analysis, penetration testing, computer forensics,...Contract workFor contractorsWork experience placementFlexible hours- ...a Public Works OT Cyber Security Manager (Systems Analyst) to lead digital defense operations for county resources... ...and assets. The role oversees endpoint security, vulnerability management, email security, and risk assessment across divisions, with on-call requirements and...Casual work
$120k - $160k
...seeking a candidate to fill a Cyber Defense Analyst position on a joint Contractor-... ...Malware triage Cyber threat emulation to assess defensive posture and capabilities... ...Knowledge: Practical experience identifying vulnerabilities and implementing proactive measures to...For contractors$120k - $160k
...Cyber Defense Analyst SAIC is seeking a candidate to fill a Cyber Defense Analyst... ...Malware triage Cyber threat emulation to assess defensive posture and capabilities... ...Knowledge: Practical experience identifying vulnerabilities and implementing proactive measures to...For contractors$72 - $80 per hour
.... Evaluate security solutions to ensure they meet security requirements for processing classified information. Performs vulnerability/risk assessment analysis to support certification and accreditation. Provides configuration management (CM) for information system security...Part timeFlexible hours$119.6k - $179.4k
...and the ability to analyze complex systems for potential vulnerabilities. Key Responsibilities: Design, develop, and implement cyber... ...'s systems and data. Conduct threat modeling, security assessments, penetration testing, and vulnerability scans to identify and mitigate...Full timeFor contractorsRelocation packageShift work$115k - $150k
...recovery (e.g., cost recovery, infrastructure redevelopment, economic development, housing, social services, etc.), delegating tasks, assessing staffing needs and developing methodologies to meet unmet needs and maximize funding. Maintain strong project management best...Permanent employmentTemporary workLocal areaImmediate startRemote workFlexible hours- ...configuration, and troubleshooting of data and security networks.Provide assessment, design, and implementation of secure networking environments... ...ACLs.MFA, cloud virtual networking, micro-segmentation, PKI, vulnerability tools (Nessus, Nmap), packet analysis (Wireshark, Riverbed)....Remote workMonday to FridayShift work3 days per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vulnerability Assessment Analyst and Penetration Tester. Be the first to apply!

