Penetration Tester / Security Assessor
$90k - $109kASM Research, An Accenture Federal Services Company
Creates cyber-intelligence tools / methods and performs research and analysis in order to mitigate and eliminate data and cyber security risks. Designs and develops acceptance criteria for cybersecurity architecture.
Perform infrastructure penetration testing to discover and exploit vulnerabilities to test the effectiveness of the organization's security posture.
Perform web application penetration testing to identify and exploit OWASP Top 10 web application vulnerabilities.
Leverage threat intelligence to emulate known threat actors' tactics, techniques, and procedures.
Partner with various cybersecurity teams to improve automation and detection of threat actors.
Engage with technical and non-technical audiences to articulate both techniques and results.
Minimum Qualifications
Bachelor's Degree in Computer Science or a related field or equivalent experience.
5-10 years of experience in systems security with a minimum of 2+ years in information security, penetration testing, or ethical hacking.
Other Job Specific Skills
Must possess demonstrated experience planning and conducting penetration tests against networks and web applications.
Demonstrated experience conducting vulnerability assessments and penetration tests.
Expertise with tools such as Bloodhound, Burp Suite, Cobalt Strike, Metasploit, and Mimikatz.
Hands-on experience with penetration testing tools and frameworks.
Portfolio of security assessments or CTF achievements (preferred).
Experience with network scanning, enumeration, and exploiting vulnerabilities.
Proficiency in Windows, Linux, and macOS environments.
Understanding of system hardening techniques and common misconfigurations.
Knowledge of programming languages like Python, Ruby, or JavaScript for creating custom scripts and exploits.
Familiarity with bash, PowerShell, or other scripting languages for automation.
Understanding of web technologies, including HTML, JavaScript, and SQL.
Preferred Skills
Experience in identifying and exploiting vulnerabilities in web applications, networks, and systems.
Familiarity with CVSS (Common Vulnerability Scoring System) and understanding how to prioritize vulnerabilities based on risk.
Ability to analyze and critique code for security vulnerabilities.
Familiarity with common vulnerabilities such as SQL injection, XSS (Cross-Site Scripting), CSRF (Cross-Site Request Forgery), and buffer overflows.
Strong understanding of network protocols, architecture, and components (e.g., TCP/IP, DNS, VPNs, firewalls, routers, switches).
Compensation Ranges
Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.
EEO Requirements
It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.
All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment.
Physical Requirements
The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, "light office duties' or "lifting up to 50 pounds" or "some travel" required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions.
Disclaimer
The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.
$90k - $109k
EEO Requirements
It is the policy of ASM that an individual's race, color, religion, sex, disability, age, gender identity, veteran status, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.
All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, veteran status, disability, gender identity, or age. All decisions on employment are made to abide by the principle of equal employment.
$76.4k - $138.6k
...more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost 950 people who collaborate to support the business of EY by protecting...SuggestedSummer holidayLocal areaFlexible hours$82.42k - $162.55k
...powered advice on this job and more exclusive features. Why USAA? At USAA, our mission is to empower our members to achieve financial security through highly competitive products, exceptional service and trusted advice. We seek to be the #1 choice for the military...SuggestedHourly payFull timeH1bLive inWork at officeLocal areaRelocation- ...Chief Information Security Officer (CISO) About the Company Independent state agency responsible for public sector employee benefits Industry Government Administration Type Government Agency Founded 1942 Employees 201-500 Categories Financial...Suggested
- ...Senior Web Application Penetration Tester Annapolis, Maryland SIXGEN's mission is to deliver agile, mission-ready cybersecurity solutions... ...candidate will possess deep expertise in web application security testing, vulnerability research, and exploitation techniques...SuggestedFull timeTemporary workRemote workFlexible hours
- ...growing government contractor providing leading-edge support to federal customers, with a particular focus on Defense and National Security mission sets. We leverage more than 17 years of support to stakeholders across the federal government, with established and...SuggestedFor contractorsWorldwide
- ...Seneca Resources Company, LLC is seeking a Cybersecurity Engineer specialized in Data Loss Prevention & Messaging Security. This remote contract role will focus on securing email communications and implementing security controls in a regulated banking environment. Candidates...Contract workRemote work
$115k - $150k
...Hagerty Consulting, Inc. (Hagerty) is the nation's leading emergency management and homeland security consulting firm. Known for its public spirit, innovative thinking, problem-solving, and exceptional people, Hagerty is sought after to work on some of the largest and...Permanent employmentTemporary workLocal areaImmediate startRemote workFlexible hours$152.41k - $179.3k
...times annually to foster collaboration, connection, and alignment. Attendance is expected and fully supported. Coinbase Corporate Security (CorpSec) is seeking a Security Engineer to design, implement, and automate security solutions that protect corporate...Local area$161.8k - $184.6k
...Mainframe Security Engineer Do you love building and pioneering in the technology space? Do you enjoy solving complex business problems in a fast-paced, collaborative, inclusive, and iterative delivery environment? At Capital One, you'll be part of a big group of makers...Full timePart timeH1bLocal area$81k - $120k
...Security Engineer (Senior Level) Are you looking for limitless career opportunities with a company that values growth, innovation, and teamwork? At Ntiva, we're more than a Managed Services Provider, we're a community dedicated to helping each other, our clients, and...Contract workTemporary workRemote work$98.9k
...What you can expect The Security Engineer is responsible for security design and reviews across our products and services. The ideal candidate brings broad technical expertise and hands-on experience in end-to-end product security. In this role, you’ll collaborate...Work at officeRemote work- ...), to assist them in a search for a Deputy Chief Information Security Officer (Deputy CISO) to lead security operations for its Investments... ...and industry best practices Advance Cyber Defense: Lead penetration testing, counterintelligence efforts, and proactive threat...Work at officeRemote work
- ...Security Management Specialist Seeking a Security Management Specialist with strong expertise in securing and managing enterprise environments. The ideal candidate will have hands-on experience with HashiCorp Vault, Terraform, RHEL, and Ansible, and will contribute...2 days per week
$106k - $126k
...Evaluates application security in all phases of the software development life cycle. Works closely with team members to define application security best practices, performs software architecture and design reviews, and supports the identification, interpretation, and...Contract workWork at office$98k - $163k
...IT Cyber Security Travel Required: Up to 10% Clearance Required: Active Public Trust What You Will Do: Lead the design, deployment, and maintenance of Trellix security architecture. Monitor, analyze, and respond to security events and threats across...Temporary workFlexible hours- ...Senior Security Engineer CoStar Group (NASDAQ: CSGP) is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces. Included in the S&P 500 Index and the NASDAQ 100, CoStar Group is on a mission to digitize the...Full timeWork at officeWork from homeMonday to Thursday
$150k - $250k
...and your family. World-class facilities and the technology you need to thrive - in our offices or yours. Job Summary The Security Engineer - Google collaborates with account and specialty teams to assess customer cybersecurity needs. They will be a customer-facing...Work experience placementWork at officeRemote workWorldwideFlexible hours$127k - $155k
...Enforces application security in all phases of the software development life cycle. Works closely with team members to define application security best practices, performs software architecture and design reviews, and supports the identification, interpretation, and remediation...Contract workWork at office- ...Penetration Tester Marathon TS is looking for a Penetration Tester to support our government client. The Penetration Tester will: Conduct highly complex offensive security operations testing consistent with known adversary tactics techniques and procedures and...Local area
$218.03k - $256.5k
...underpins our position as the world's most trusted crypto platform. The Identity and Access Management (IAM) program, housed within Security, is a cross-functional team that designs, builds, and governs workforce identity services, privileged access controls, and...For contractorsLocal area$115k - $135k
...think global but act local – come join our team! This role will support the design, implementation, and continuous improvement of security architecture across AWS and Microsoft Azure environments, enterprise applications, and infrastructure platforms. This role will focus...Full timeLocal areaRemote work$184k - $230k
...Datavant is the data collaboration platform trusted for healthcare. Guided by our mission to make the world's health data secure, accessible and actionable, we provide critical data solutions for organizations across the healthcare ecosystem - including providers, health...Remote work- ...Platform Security Architect Duties/Responsibilities: • As part of a team, ensure the adoption of security architecture and engineering initiatives in order to effectively and securely support the organization in meeting specific business technology needs....
- ...technologies. EDB delivers the confidence of up to 99.999% high availability with mission critical capabilities built in such as security, compliance controls, and observability. For more information, visit Job Summary As a Staff Security Engineer at EDB, you will...Remote work
- ...approach and unwavering dedication to excellence. Job Responsibilities This role will design, implement, and strengthen technical security capabilities that support RMF execution, FISMA requirements, and secure enterprise operations. This position calls for a senior...
- ...Ensono is looking for a Security Senior Solution Architect, preferably remote within Central or Eastern time zones, to enhance client security solutions. This role involves working with senior executives to identify technology gaps, present solutions, and lead implementation...Remote work
$218.03k - $256.5k
...annually to foster collaboration, connection, and alignment. Attendance is expected and fully supported. Coinbase Infrastructure Security (InfraSec) is at the forefront of protecting the foundation of Coinbase’s infrastructure and platform services. This role partners...Local area- ...SENIOR DIRECTOR, INFORMATION SECURITY CISO WHO WE ARE Everforth Apex Systems is a leading global technology and digital engineering firm dedicated to helping organizations adapt, innovate, and thrive in a world of constant change. Leveraging deep industry...Temporary workRemote workFlexible hours
$118.72k - $190.04k
...implementation services. Red Hat is a rapidly growing company supporting more than 90% of Fortune 500 companies. The Red Hat Product Security Compliance team is seeking a knowledgeable and proactive Product Security Engineer to achieve our security and compliance...Permanent employmentFull timeContract workWork experience placementWork at officeRemote workWork from homeWorldwideFlexible hours- ...Network Security Engineering Professional This position may be offered to a candidate authorized to work in the US for his/her/their stated employer, without any restrictions which would prevent the candidate from working on the proposed assignment for the duration...Remote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Penetration Tester / Security Assessor. Be the first to apply!

