Vulnerability Assessment Analyst and Penetration Tester
SteelToad
Vulnerability Assessment Analyst and Penetration Tester Position Description The Vulnerability Assessment Analyst and Penetration Tester is responsible for the delivery of continuous cyber assessments, solving complex technology problems, building tools, and identifying and influencing response to and mitigation of threats. Perform manual assessment of systems, services, and software; specializing in security issues beyond those identified by static analysis tools. The individual ensures services, applications, and websites are designed and implemented to the highest security standards. Responsible for application and hardware penetration testing, automating repetitive tasks using various scripting languages, mentoring, and leading other engineers to deliver complex penetration tests and vulnerability assessments. The individual will be expected to drive automation, tooling, efficiency, and advance the team’s penetration testing capabilities. Responsible for creating threat mitigation plans. Qualifications Five years of hands‑on penetration testing experience with operating systems, web applications, and network infrastructure. Administrator‑level knowledge of Windows and Linux Server operating systems. Experience with operating system security. Competent with testing frameworks and tools, such as Burp Suite, Metasploit, Cobalt Strike, Kali Linux, Nessus, PowerShell Empire. Knowledge of the functionality and capabilities of computer network defense technologies, including router Access Control Lists (ACLs), firewalls, Intrusion Detection System (IDS)/Intrusion Prevention System (IPS), antivirus/Endpoint Detection and Response (EDR), and web content filtering. Strong written and verbal communication skills, including the ability to explain complex technical topics to non‑technical audiences. Possess one of the following certifications upon onboarding: Offensive Security Certified Professional (OSCP) Offensive Security Web Assessor (OSWA) Obtain one of the following certifications within 9 months of onboarding: GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) Offsec Experienced Penetration Tester (OSEP) Reports To Assigned Program Manager Security Clearance Requirements Secret Travel Requirements Travel is anticipated to be 10% - 15% within the Continental United States and 5% - 10% outside the Continental United States. Benefits & Compensation New employees are eligible to participate in the company’s benefits plan on their day of hire unless noted otherwise. Medical Insurance Long Term & Short-Term Disability, Group Life and AD&D Insurance – 100% Employer Paid Health Savings Account 401(k) Savings Plan – 100% match for the first 3% contributed plus 50% of the next 2% contributed. (no vesting period and eligibility is your date of hire). Paid holidays – Eleven (11) per year Paid Time Off – One hundred‑twenty (120) accrued hours per year Professional Development Program Salary will be determined based on the individual’s education and experience level Overview Lumbee Holdings is a leading provider of IT Support, Cybersecurity and Training and Development to the Department of Defense (DoD) and other government agencies. Equal Employment Opportunity Policy Statement It is the policy of Lumbee Tribe Holdings, Inc. and its subsidiaries (the “Company”) not to discriminate against any employee or applicant for employment because of race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, marital status, genetic information, mental or physical disability (and medical condition, for employees in California) or because he or she is a protected veteran. It is also the policy of the Company to take affirmative action to employ and to advance in employment, all persons regardless of race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, marital status, genetic information, mental or physical disability (and medical condition, for employees in California) or protected veteran status, and to base all employment decisions only on valid job requirements. This policy shall apply to all employment actions, including but not limited to recruitment, hiring, upgrading, promotion, transfer, demotion, layoff, recall, termination, rates of pay or other forms of compensation and selection for training, including apprenticeship, at all levels of employment. Employees and applicants of the Company will not be subject to harassment on the basis of race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, marital status, genetic information, mental or physical disability (and medical condition, for employees of California) or because he or she is a protected veteran. Additionally, retaliation, including intimidation, threats, or coercion, because an employee or applicant has objected to discrimination, engaged or may engage in filing a complaint, assisted in a review, investigation, or hearing or have otherwise sought to obtain their legal rights under any Federal, State, or local EEO law is prohibited. NOTE: These statements are intended to describe the general nature and level of work involved for this job. It is not an exhaustive list of all responsibilities, duties, and skills required of this job. Seniority Level Mid‑Senior level Employment Type Full‑time Job Function Business Development and Sales Industries Computer and Network Security #J-18808-Ljbffr SteelToad
$50k - $290k
A leading consulting firm is seeking a Network Evaluator to assess and improve operational networks in Annapolis Junction, MD. Candidates must evaluate vulnerabilities, recommend countermeasures, and support security solutions. A Bachelor’s degree with relevant experience...Suggested- ...Overview Tharros is seeking Cyber Security Vulnerability Researcher, Forensic Analyst to conduct digital forensic analysis and incident response in support of NAWCAD Cyber Warfare Division programs at NAS Patuxent River, MD. The CSVR Forensic Analyst applies advanced...Suggested
$90k - $120k
...the following areas: Network Analysts (Cyber, Forensic, Signals, Exploitation etc) Vulnerability Analysts Data Analysts Penetration Testers Malware Analysts Others..... ..., comprehensive vulnerability assessments and/or analysis of network cybersecurity...SuggestedLocal areaRemote work$40 per hour
...work directly with advanced AI models to assess their accuracy, strengthen their... ...cybersecurity content, including threat analysis, vulnerability assessments, and offensive security... ...‑on experience in cybersecurity (e.g., penetration testing, red teaming, incident response...SuggestedHourly payFull timePart timeRemote work$71.2k - $166.1k
...supporting project teams during system design and throughout the connectivity approval lifecycle, but does not participate in the Assess & Authorize (A&A) process itself. The ISSE will collaborate with internal project teams, external agency partners, network engineers...SuggestedContract workTemporary workWork experience placementRelocationFlexible hours$90k - $120k
...professionals in the following areas: Network Analysts (Cyber, Forensic, Signals, Exploitation etc) Vulnerability Analysts Data Analysts Penetration Testers Malware Analysts Others… Overview Be... ..., comprehensive vulnerability assessments and/or analysis of network...Local areaRemote work- ...compliance teams to monitor system security, conduct audits, manage vulnerabilities, and support accreditation efforts, including System... ..., procedures, and SSP requirements Perform vulnerability assessments and scans, including user accounts, application access, file...
- ...Responsibilities: Conduct comprehensive technical security assessments and contribute to the design of secure systems. Manage risk... ...Collaborate with application leads, DBAs, developers, and testers to achieve and maintain Authority to Operate (ATO). Develop...Full timeInterim roleFlexible hours
- ...telecommunications, and information systems security education awareness programs. Performs periodic and on-demand system audits and vulnerability assessments, including user accounts, application access, file system, and external Web integrity scans to determine compliance...
$130k - $270k
...Evaluates security solutions to ensure they meet security requirements for processing classified information. Performs vulnerability/risk assessment analysis to support certification and accreditation. Provides configuration management (CM) for information system...Hourly payTemporary work- ...ISSO is responsible for maintaining and implementing all Information System Security policies, standards, and directives to ensure assessment and authorization of information systems processing classified information. Position Responsibilities: Contributes to...Work experience placement
$131.3k - $237.35k
...implementing strategies to detect and mitigate threats to information systems, protect critical data sets, and provide assessments of system and network vulnerabilities. Primary Roles and Responsibilities Provide support for implementing and enforcing information...Immediate startFlexible hours$115k - $240k
...multiple Computer Network Defense Analysts (CNDAs) to support a... ...sources to identify and analyze vulnerabilities, detect potential or active... ...form hypotheses, critically assess and choose analysis... ...security, vulnerability analysis, penetration testing, computer forensics,...Contract workFor contractorsWork experience placementFlexible hours$115k - $150k
...recovery (e.g., cost recovery, infrastructure redevelopment, economic development, housing, social services, etc.), delegating tasks, assessing staffing needs and developing methodologies to meet unmet needs and maximize funding. Maintain strong project management best...Permanent employmentTemporary workLocal areaImmediate startRemote workFlexible hours- ...and Accreditation (C&A). Continuously review threat, system vulnerabilities, and residual risk. Other duties as assigned. The FRCS... ...Manager shall perform tasks to implement, maintain, and assess cybersecurity on systems and components, and shall follow procedures...Contract workWork at officeRemote work
- ..._______________________________________________ You will perform, or review, technical security assessments of computing environments to identify points of vulnerability, non-compliance with established Information Assurance (IA) standards and regulations, and recommend...Work at officeFlexible hours
- ...the implementation of required and or applicable security controls. Support the development, review, and approval of Security Assessment Plan. Implement, maintain, and upgrade the approved IS security scanning tool and perform periodic security scans of the IS and...Full timeContract workPart timeInterim roleLocal areaFlexible hours
- ...enforcement of the design and implementation of trusted relationships among external systems and architectures Security planning, assessment, risk analysis, and risk management Identify overall security requirements for the proper handling of Government data...Full timeContract workWork at officeLocal areaImmediate start
$145k - $175k
...structure to design, develop, and implement secure networking, computing, and enclave environments Support security planning, assessment, risk analysis, and risk management Identify overall security requirements for the proper handling of Government data Interact...- ...data security networks. Providing assessment, design and implementation services of... ...or Palo Alto Networks Network Security Analyst Certification. Cisco Certified Network... ...Key Infrastructure (PKI). o Vulnerability management using Nessus, NMAP, Windows,...Hourly payLong term contractTemporary work
- ...with technical teams and stakeholders to assess requirements, design secure networking... ...Key Infrastructure (PKI) Performing vulnerability assessment and remediation using tools such... ...or Palo Alto Networks Network Security Analyst Certification. Cisco Certified...Remote workRelocation2 days per week3 days per week
- ...or Palo Alto Networks Network Security Analyst Certification. (2) Cisco Certified Network... ...data security networks. 3. Providing assessment, design and implementation services of... ...Public Key Infrastructure (PKI). Vulnerability management using Nessus, NMAP, Windows,...Remote workMonday to Friday
$112.5k - $202.5k
...Partner with the best As a Senior Security Engineer you will be assessing and mitigating the risk of doing business in today's hyper-... ...and staying current on adversarial techniques, emerging vulnerabilities, and related detection and response strategies. Conducting...Work experience placementWork at officeWorldwide$98.9k
...modeling, architecture review, security code review, security assessment, and security testing (web application, native application,... ...and functionalities. This includes identifying security vulnerabilities such as those in the Owasp Top Ten, common issues from the NVD...Work at officeRemote work$99k - $225k
...artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.Candidate AI Usage PolicyAI is a part of our...Full timeContract workPart timeWork at officeLocal areaRemote work$186.07k - $218.9k
...cross-function efforts to address them Perform security assessments, framework development, and threat modeling of assets, including... ...blogs and give talks (internal and external) on newfound vulnerabilities, incident investigations, unique integration risks, and related...Contract workLocal area$218.03k - $256.5k
...conversation. A human recruiter will review your interview responses, provided in the form of a voice recording and/or transcript, to assess them against the qualifications and characteristics outlined in the job description. For select roles, Coinbase is also piloting...For contractorsLocal area$157.5k - $283.5k
...get to lead the shift from static, point-in-time compliance assessments to a dynamic, real-time risk authorization posture RMF. What... ...CD) pipelines Oversee real-time configuration tracking, live vulnerability assessments, and threat analytics to ensure ongoing compliance...For contractorsFlexible hoursShift work$106.3k - $234.6k
...ensuring prompt response and resolution. Contributes to compliance assessments, evaluating the effectiveness of security controls and... ...of various products and services, analyzing potential vulnerabilities and recommending mitigation strategies. – Develops advanced...Temporary workFlexible hoursShift work- ...certification (DoD 8570 IAM Level III). Experience with SAP and/or DCSA assessments and authorizations. 5+ years experience with Authority to... ...with eMASS Experience with ACAS, Nessus, and/or other vulnerability scanners 3+ years of solid Linux system administration...Full timeWork experience placementWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vulnerability Assessment Analyst and Penetration Tester. Be the first to apply!

