Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Penetration Tester / Security Assessor

$90k - $109k

ASM Research, An Accenture Federal Services Company

Creates cyber-intelligence tools / methods and performs research and analysis in order to mitigate and eliminate data and cyber security risks. Designs and develops acceptance criteria for cybersecurity architecture.

  • Perform infrastructure penetration testing to discover and exploit vulnerabilities to test the effectiveness of the organization's security posture.

  • Perform web application penetration testing to identify and exploit OWASP Top 10 web application vulnerabilities.

  • Leverage threat intelligence to emulate known threat actors' tactics, techniques, and procedures.

  • Partner with various cybersecurity teams to improve automation and detection of threat actors.

  • Engage with technical and non-technical audiences to articulate both techniques and results.

Minimum Qualifications

  • Bachelor's Degree in Computer Science or a related field or equivalent experience.

  • 5-10 years of experience in systems security with a minimum of 2+ years in information security, penetration testing, or ethical hacking.

Other Job Specific Skills

  • Must possess demonstrated experience planning and conducting penetration tests against networks and web applications.

  • Demonstrated experience conducting vulnerability assessments and penetration tests.

  • Expertise with tools such as Bloodhound, Burp Suite, Cobalt Strike, Metasploit, and Mimikatz.

  • Hands-on experience with penetration testing tools and frameworks.

  • Portfolio of security assessments or CTF achievements (preferred).

  • Experience with network scanning, enumeration, and exploiting vulnerabilities.

  • Proficiency in Windows, Linux, and macOS environments.

  • Understanding of system hardening techniques and common misconfigurations.

  • Knowledge of programming languages like Python, Ruby, or JavaScript for creating custom scripts and exploits.

  • Familiarity with bash, PowerShell, or other scripting languages for automation.

  • Understanding of web technologies, including HTML, JavaScript, and SQL.

Preferred Skills

  • Experience in identifying and exploiting vulnerabilities in web applications, networks, and systems.

  • Familiarity with CVSS (Common Vulnerability Scoring System) and understanding how to prioritize vulnerabilities based on risk.

  • Ability to analyze and critique code for security vulnerabilities.

  • Familiarity with common vulnerabilities such as SQL injection, XSS (Cross-Site Scripting), CSRF (Cross-Site Request Forgery), and buffer overflows.

  • Strong understanding of network protocols, architecture, and components (e.g., TCP/IP, DNS, VPNs, firewalls, routers, switches).

Compensation Ranges

Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.

EEO Requirements

It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.

All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment.

Physical Requirements

The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, "light office duties' or "lifting up to 50 pounds" or "some travel" required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions.

Disclaimer

The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.

$90k - $109k

EEO Requirements

It is the policy of ASM that an individual's race, color, religion, sex, disability, age, gender identity, veteran status, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.

All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, veteran status, disability, gender identity, or age. All decisions on employment are made to abide by the principle of equal employment.

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Penetration Tester / Security Assessor in Richmond, VA vacancy
  • $76.4k - $138.6k

     ...more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost 950 people who collaborate to support the business of EY by protecting... 
    Suggested
    Summer holiday
    Local area
    Flexible hours

    Ernst & Young Oman

    Richmond, VA
    4 days ago
  • $82.42k - $162.55k

     ...powered advice on this job and more exclusive features. Why USAA? At USAA, our mission is to empower our members to achieve financial security through highly competitive products, exceptional service and trusted advice. We seek to be the #1 choice for the military... 
    Suggested
    Hourly pay
    Full time
    H1b
    Live in
    Work at office
    Local area
    Relocation

    USAA

    Richmond, VA
    5 days ago
  •  ...Chief Information Security Officer (CISO) About the Company Independent state agency responsible for public sector employee benefits Industry Government Administration Type Government Agency Founded 1942 Employees 201-500 Categories Financial... 
    Suggested

    Confidential

    Richmond, VA
    4 days ago
  •  ...Senior Web Application Penetration Tester Annapolis, Maryland SIXGEN's mission is to deliver agile, mission-ready cybersecurity solutions...  ...candidate will possess deep expertise in web application security testing, vulnerability research, and exploitation techniques... 
    Suggested
    Full time
    Temporary work
    Remote work
    Flexible hours

    SIXGEN

    Richmond, VA
    1 day ago
  •  ...growing government contractor providing leading-edge support to federal customers, with a particular focus on Defense and National Security mission sets. We leverage more than 17 years of support to stakeholders across the federal government, with established and... 
    Suggested
    For contractors
    Worldwide

    Navstar

    Richmond, VA
    4 days ago
  •  ...Seneca Resources Company, LLC is seeking a Cybersecurity Engineer specialized in Data Loss Prevention & Messaging Security. This remote contract role will focus on securing email communications and implementing security controls in a regulated banking environment. Candidates... 
    Contract work
    Remote work

    Seneca

    Glen Allen, VA
    9 hours ago
  • $115k - $150k

     ...Hagerty Consulting, Inc. (Hagerty) is the nation's leading emergency management and homeland security consulting firm. Known for its public spirit, innovative thinking, problem-solving, and exceptional people, Hagerty is sought after to work on some of the largest and... 
    Permanent employment
    Temporary work
    Local area
    Immediate start
    Remote work
    Flexible hours

    Hagerty Consulting

    Richmond, VA
    2 days ago
  • $152.41k - $179.3k

     ...times annually to foster collaboration, connection, and alignment. Attendance is expected and fully supported. Coinbase Corporate Security (CorpSec) is seeking a Security Engineer to design, implement, and automate security solutions that protect corporate... 
    Local area

    Coinbase

    Richmond, VA
    3 days ago
  • $161.8k - $184.6k

     ...Mainframe Security Engineer Do you love building and pioneering in the technology space? Do you enjoy solving complex business problems in a fast-paced, collaborative, inclusive, and iterative delivery environment? At Capital One, you'll be part of a big group of makers... 
    Full time
    Part time
    H1b
    Local area

    Capital One Financial Corp

    Richmond, VA
    5 days ago
  • $81k - $120k

     ...Security Engineer (Senior Level) Are you looking for limitless career opportunities with a company that values growth, innovation, and teamwork? At Ntiva, we're more than a Managed Services Provider, we're a community dedicated to helping each other, our clients, and... 
    Contract work
    Temporary work
    Remote work

    Ntiva

    Henrico, VA
    3 days ago
  • $98.9k

     ...What you can expect The Security Engineer is responsible for security design and reviews across our products and services. The ideal candidate brings broad technical expertise and hands-on experience in end-to-end product security. In this role, you’ll collaborate... 
    Work at office
    Remote work

    Zoom Corporation

    Richmond, VA
    1 day ago
  •  ...), to assist them in a search for a Deputy Chief Information Security Officer (Deputy CISO) to lead security operations for its Investments...  ...and industry best practices Advance Cyber Defense: Lead penetration testing, counterintelligence efforts, and proactive threat... 
    Work at office
    Remote work

    Fahrenheit Advisors

    Richmond, VA
    2 days ago
  •  ...Security Management Specialist Seeking a Security Management Specialist with strong expertise in securing and managing enterprise environments. The ideal candidate will have hands-on experience with HashiCorp Vault, Terraform, RHEL, and Ansible, and will contribute... 
    2 days per week

    TechWish

    Richmond, VA
    4 days ago
  • $106k - $126k

     ...Evaluates application security in all phases of the software development life cycle. Works closely with team members to define application security best practices, performs software architecture and design reviews, and supports the identification, interpretation, and... 
    Contract work
    Work at office

    ASM Research, An Accenture Federal Services Company

    Richmond, VA
    1 day ago
  • $98k - $163k

     ...IT Cyber Security Travel Required: Up to 10% Clearance Required: Active Public Trust What You Will Do: Lead the design, deployment, and maintenance of Trellix security architecture. Monitor, analyze, and respond to security events and threats across... 
    Temporary work
    Flexible hours

    Guidehouse

    Richmond, VA
    3 days ago
  •  ...Senior Security Engineer CoStar Group (NASDAQ: CSGP) is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces. Included in the S&P 500 Index and the NASDAQ 100, CoStar Group is on a mission to digitize the... 
    Full time
    Work at office
    Work from home
    Monday to Thursday

    CoStar Group

    Richmond, VA
    4 days ago
  • $150k - $250k

     ...and your family. World-class facilities and the technology you need to thrive - in our offices or yours. Job Summary The Security Engineer - Google collaborates with account and specialty teams to assess customer cybersecurity needs. They will be a customer-facing... 
    Work experience placement
    Work at office
    Remote work
    Worldwide
    Flexible hours

    SHI GmbH

    Richmond, VA
    3 days ago
  • $127k - $155k

     ...Enforces application security in all phases of the software development life cycle. Works closely with team members to define application security best practices, performs software architecture and design reviews, and supports the identification, interpretation, and remediation... 
    Contract work
    Work at office

    ASM Research, An Accenture Federal Services Company

    Richmond, VA
    1 day ago
  •  ...Penetration Tester Marathon TS is looking for a Penetration Tester to support our government client. The Penetration Tester will: Conduct highly complex offensive security operations testing consistent with known adversary tactics techniques and procedures and... 
    Local area

    Marathon TS

    Richmond, VA
    4 days ago
  • $218.03k - $256.5k

     ...underpins our position as the world's most trusted crypto platform. The Identity and Access Management (IAM) program, housed within Security, is a cross-functional team that designs, builds, and governs workforce identity services, privileged access controls, and... 
    For contractors
    Local area

    Coinbase

    Richmond, VA
    2 days ago
  • $115k - $135k

     ...think global but act local – come join our team! This role will support the design, implementation, and continuous improvement of security architecture across AWS and Microsoft Azure environments, enterprise applications, and infrastructure platforms. This role will focus... 
    Full time
    Local area
    Remote work

    SitusAMC

    Richmond, VA
    6 days ago
  • $184k - $230k

     ...Datavant is the data collaboration platform trusted for healthcare. Guided by our mission to make the world's health data secure, accessible and actionable, we provide critical data solutions for organizations across the healthcare ecosystem - including providers, health... 
    Remote work

    Datavant

    Richmond, VA
    2 days ago
  •  ...Platform Security Architect Duties/Responsibilities: • As part of a team, ensure the adoption of security architecture and engineering initiatives in order to effectively and securely support the organization in meeting specific business technology needs.... 

    3B Staffing LLC

    Richmond, VA
    4 days ago
  •  ...technologies. EDB delivers the confidence of up to 99.999% high availability with mission critical capabilities built in such as security, compliance controls, and observability. For more information, visit Job Summary As a Staff Security Engineer at EDB, you will... 
    Remote work

    EDB

    Richmond, VA
    5 days ago
  •  ...approach and unwavering dedication to excellence. Job Responsibilities This role will design, implement, and strengthen technical security capabilities that support RMF execution, FISMA requirements, and secure enterprise operations. This position calls for a senior... 

    True Zero Technologies, LLC

    Richmond, VA
    1 day ago
  •  ...Ensono is looking for a Security Senior Solution Architect, preferably remote within Central or Eastern time zones, to enhance client security solutions. This role involves working with senior executives to identify technology gaps, present solutions, and lead implementation... 
    Remote work

    Ensono

    Richmond, VA
    3 hours ago
  • $218.03k - $256.5k

     ...annually to foster collaboration, connection, and alignment. Attendance is expected and fully supported. Coinbase Infrastructure Security (InfraSec) is at the forefront of protecting the foundation of Coinbase’s infrastructure and platform services. This role partners... 
    Local area

    Coinbase

    Richmond, VA
    3 days ago
  •  ...SENIOR DIRECTOR, INFORMATION SECURITY CISO WHO WE ARE Everforth Apex Systems is a leading global technology and digital engineering firm dedicated to helping organizations adapt, innovate, and thrive in a world of constant change. Leveraging deep industry... 
    Temporary work
    Remote work
    Flexible hours

    Apex Systems

    Glen Allen, VA
    4 days ago
  • $118.72k - $190.04k

     ...implementation services. Red Hat is a rapidly growing company supporting more than 90% of Fortune 500 companies. The Red Hat Product Security Compliance team is seeking a knowledgeable and proactive Product Security Engineer to achieve our security and compliance... 
    Permanent employment
    Full time
    Contract work
    Work experience placement
    Work at office
    Remote work
    Work from home
    Worldwide
    Flexible hours

    Red Hat

    Richmond, VA
    5 days ago
  •  ...Network Security Engineering Professional This position may be offered to a candidate authorized to work in the US for his/her/their stated employer, without any restrictions which would prevent the candidate from working on the proposed assignment for the duration... 
    Remote work

    Samprasoft

    Henrico, VA
    9 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Penetration Tester / Security Assessor. Be the first to apply!