Penetration Tester
Marathon TS
Penetration Tester
Marathon TS is looking for a Penetration Tester to support our government client. The Penetration Tester will:
- Conduct highly complex offensive security operations testing consistent with known adversary tactics techniques and procedures and contribute to the development of objectives and approaches taken to remediate risk.
- Apply sound technical and management principles to identify and remediate cybersecurity vulnerabilities across the State Department global IT enterprise infrastructure
- Apply organizational and process change principals
- Evaluate system performance results, perform risk assessments, and evaluate performance metrics.
- Responsibilities include:
- Provide ad-hoc penetration testing and assessment services on Department of State systems identified by the leadership.
- Develop, identify and resolve security vulnerabilities related to deployment and testing processes
- Streamline and optimize processes and procedures in order to rapidly remediate vulnerabilities from cybersecurity threats
- Collaborate with Department and external cyber stakeholders on cybersecurity technology implementations to meet specific operational needs.
- Perform technical evaluations of recommended vulnerability mitigation actions and make recommendations based on impact and/or other countermeasures.
- Develop strategies for CIC cyber defense technologies, ensuring integration and alignment for continued operation.
- Conduct assessments of threats and vulnerabilities; determine deviations from acceptable configurations, enterprise, or local policy; assess the level of risk; and develop and/or recommend appropriate mitigation countermeasures in operational and non-operational situations
- Network Mapping include but are not limited to a network map of the organization's system that includes a visual representation of the organization's physical devices and digital network.
- Perform operation and maintenance activities in support of existing CIC cyber tools and technologies (MSV, Qualys, Tenable Nessus and others).
- Identify, diagnose, and prioritize anomalies in cyber defense infrastructure and resources.
- Perform cybersecurity testing of developed applications and/or systems. Identify and direct the remediation of technical problems encountered during testing and implementation of new systems.
- Document security issues and impacts identified through offensive operations in a clear and concise manner to facilitate reporting to impacted stakeholders.
Required Qualifications:
- 4 years Microsoft Operating Systems (OS) engineering and support experience focusing on Active Directory (AD), System Center Configuration Manager (SCCM), System Center Operations Manager (SCOM)
- 4-6 years Network penetration testing experience
- In-depth experience in planning, implementing, and managing large/global enterprise infrastructures
- Familiarity of various analytical tools (Splunk, USBDeview, Netwitness, MimiKatz)
- Understanding of Security Information and Event Management (SIEM) tools (Splunk, McAfee)
- Familiarity of Cobalt Strike, Nessus, Kali Linux, Burp Suite, Nmap and OpenVAS for databases
- Knowledge of general attack stages
- Skill in the use of social engineering techniques and using penetration testing tools
- Familiarity with OMB, NIST, Client, and related security guidelines and directives
- Interpersonal skills including the ability to collaborate effectively, and excellent written and oral communications
- Network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
- Server/endpoint OS (Microsoft, Linux, IOS) along with mobile and cloud technologies.
- Cloud application security, Vulnerability Management and Security Information, and Event Management capabilities.
- Knowledge of identity and access management solutions (MFA, PKI, SAML, etc.)
- Countermeasures / mitigations to identified cybersecurity risks.
- Knowledge of network protocols such as TCP/IP, Dynamic Host Configuration Protocol (DHCP), domain name system, and directory services
- Ability to generate and implement capabilities to monitor organization's network in real-time
- Ability to provide Vulnerability Scanning Risk Assessment
- Information protection technologies (e.g., firewalls, antivirus, threat protection, servers, routers, and others as appropriate).
- Ability to identify and exploit web vulnerabilities (XSS, CSRF, SQLi, SSRF, arbitrary file upload, etc.)
- Ability to identify and exploit mobile vulnerabilities (API issues, insecure storage, memory corruption, deep links, etc.)
Marathon TS is committed to the development of a creative, diverse and inclusive work environment. In order to provide equal employment and advancement opportunities to all individuals, employment decisions at Marathon TS will be based on merit, qualifications, and abilities. Marathon TS does not discriminate against any person because of race, color, creed, religion, sex, national origin, disability, age or any other characteristic protected by law (referred to as "protected status").
- ...Senior Web Application Penetration Tester Annapolis, Maryland SIXGEN's mission is to deliver agile, mission-ready cybersecurity solutions that empower government and critical infrastructure organizations to stay ahead of advanced cyber threats. We combine innovation...SuggestedFull timeTemporary workRemote workFlexible hours
- ...leaders to help them find the best cybersecurity talent, and right now, we are hiring for multiple companies looking for skilled Penetration Testers to enhance their security teams. Job Description We are looking for talented and experienced Penetration Testers to take...SuggestedImmediate startRemote work
- ...companies to meet regulatory requirements and enhance their cybersecurity posture from day one. The Opportunity We are seeking a Penetration Tester to join our growing cybersecurity team. In this role, you will assess the security of applications, networks, and systems...SuggestedRemote workHome office
$100k - $160k
...experience/expertise Key Responsibilities Conduct manual penetration testing across internal, external, and wireless networks, web... ...occasion These are not tool-heavy, checkbox pentests. Our testers think and act like adversaries - endpoint evasion, privilege escalation...SuggestedFull timeRemote work- ...Penetration Tester / Offensive Security Consultant Location : Remote (US or Canada) Company : Control Gap, a CyberGuard Advantage company About Us CyberGuard Advantage is a modern cybersecurity compliance and risk advisory firm backed by Atlantic Street Capital. We help...SuggestedRemote work
$40 per hour
...directly shapes the next generation of AI security models Qualifications 2+ years of hands‑on experience in cybersecurity (e.g., penetration testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat intelligence, or similar) Some coding...Hourly payFull timePart timeRemote work$75k - $135k
...to make our clients successful. Recruiting for the following levels: Junior - $75-90k Mid - $90-135k The primary role of this Penetration Tester is to perform multidisciplinary assessment services as needed. Examples include Application Security Assessments against web...Full timeRemote work- ...our clients, integrity and employees and believe a single person can make a difference! Clearfocus Technologies is seeking a Penetration Tester/Exploit Developer for a Remote Opportunity. All applicants must be willing to work on a 1099 basis and open to short-term assignments...Temporary workRemote work
- ...A fast-growing cybersecurity startup is seeking a Penetration Tester to enhance security for clients. You will conduct penetration tests, assess vulnerabilities in cloud and MacOS applications, and collaborate with teams to document recommendations and improve security...Remote work
- ...A leading cybersecurity platform is hiring talented Penetration Testers to identify vulnerabilities in innovative companies systems. Youll conduct penetration tests on various infrastructures and collaborate with teams to provide actionable security solutions. Ideal candidates...Flexible hours
- ...0 enterprises. We are looking for a talented and motivated Junior Security Consultant who will join our security team to work on penetration testing and vulnerability/cloud security assessment projects. We are ready to consider interns/junior specialists given that they...Remote workWork from homeWorldwideFlexible hours
$76.4k - $138.6k
At EY, we’re all in to shape your future with confidence. We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. Today’s world is fueled by vast amounts...Summer holidayLocal areaFlexible hours$500 per month
...Become a Professional Game Tester We're looking for passionate gamers to join our elite team of mobile game testers. Get paid to play and test the latest games before they launch. $500+ Avg Monthly Pay 5-10 Hours/Week 100% Remote Position Requirements:...Remote work10 hours per week- ...Community Game Tester (Paid, On-Call) - US Get AI-powered advice on this job and more exclusive features. About GBTN GBTN is a community of gamers who help shape the future of video games. We partner with developers to test unreleased and in-development titles...Extra incomeFull timePart timeImmediate startRemote workFlexible hours
- ...infrastructure architectural teams to create code that is secure by design and default. Triage programmatic source code findings and automate penetration testing to reduce the potential introduction of vulnerabilities. Lead and collaborate with developers on secure coding techniques...
- A leading cybersecurity firm is seeking a Cyber Security Consultant in the United States. The role involves managing client relationships, resolving cybersecurity-related issues, and providing strategic guidance across the region. Ideal candidates will have at least 3 ...Flexible hours
- OpenAI is looking for a Principal Software Engineer to join the Infrastructure Security team. This role involves designing and implementing high-scale security systems critical to safeguarding OpenAIs technology and user data. Candidates should possess strong software ...
$35 per hour
...Have you ever wondered what it’s like to dive into the world of mobile game discovery? Becoming a Freelance Software Tester offers the exciting opportunity to explore and analyze a wide array of mobile apps and games. This entry-level role is perfect for those eager to...Hourly payContract workFixed term contractFreelanceRemote workWorldwide- Security Engineer (Infrastructure Security) About 1mind 1mind is a platform that deploys multimodal Superhumans for revenue teams. These Superhumans combine a face, a voice, and a GTM brain equipped with deep technical and product knowledge. They can lead unlimited ...Full timeRemote workShift work
$89.74 per hour
Insight Global is looking for a Vulnerability Management Analyst to join one of our customers in Richmond VA. The Vulnerability Management Analyst is responsible for overseeing the quality, accuracy, and usability of technical documentation within the ServiceNow Knowledge...$92.21k - $125.15k
ISSO Employment Type: Full-Time, Experienced Department: Information Technology CGS is seeking an Information Systems Security Officer (ISSO) with DIACAP and/or RMF experience who has deep expertise in security assessment documentation to support Dept. of Commerce...Full timeLocal areaFlexible hours- Overview Bellese is a mission-driven Digital Services Company committed to pioneering innovative technology solutions in civic healthcare. Our dedication lies in making a meaningful impact on public health outcomes. Driven by service design, we strive to know the “Why”...Temporary workWork at officeRemote workWork from homeFlexible hours
$224k - $260k
...for a primarily AWS-based environment. Lead application security programs, including secure SDLC, dependency scanning, SAST/DAST, penetration testing, and vulnerability management. Own identity and access management strategy with Okta as the backbone. Ensure strong...Remote workFlexible hours- Title: Information Security Officer State Role Title: Salary Non-Specified Hiring Range: Commensurate with experience Location: OES Agency Website: Recruitment Type: General Public - G Additional Detail Job Duties The Department of Judicial...Contract workWork experience placementWork at office
- Chief Information Security Officer (CISO) About the Company Independent state agency responsible for public sector employee benefits Industry Government Administration Type Government Agency Founded 1942 Employees 201-500 Categories Financial...
- Who We Are: Exiger transforms supply chains into a strategic advantage-advancing our mission to make the world a safer and more transparent place to succeed. OurAI platform, 1Exiger, delivers instant visibility into complex supplier ecosystems, leveraging proprietary...
- ...the open source software program, including license compliance, vulnerability tracking, and remediation. Manage the external penetration testing program, from scoping and vendor selection through findings triage and remediation verification. Set and evolve standards...Contract workRemote workWorldwide
- Information System Security Officer Marathon TS is looking for an Information System Security Officer to support our efforts at DISA. Key Responsibilities: Verify data security access controls based on the Joint Special Access Program Implementation Guide (...Contract workWork experience placement
- ...Cyber Security Penetration Testing Specialist ProSidian Seeks a Cyber Security Penetration Testing Specialist in CONUS - Mid Atlantic Washington Metropolitan Area (Northern Virginia | Washington DC | Maryland) to support an engagement for a cabinet-level department...For contractorsWork at office
- A cybersecurity firm is seeking a Senior Virtual Information Security Officer to provide CISO-level advisory services. In this non-implementational role, youll guide strategy, mentor Virtual ISOs, oversee deliverables, and communicate effectively with client executives...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Penetration Tester. Be the first to apply!

