Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Vulnerability Assessment & Penetration Testing Specialist Level III

Rividium Inc

Description The Vulnerability Assessment & Penetration Testing Specialist - Level III serves as the senior technical expert responsible for planning, executing, and leading advanced penetration testing, vulnerability assessments, software assurance, and cyber supply chain risk management activities across the Department of Homeland Security (DHS) Intelligence Enterprise (DHS IE). This role performs comprehensive security assessments of enterprise networks, cloud environments, applications, operating systems, and Cross Domain Solutions (CDS) using industry-recognized methodologies and advanced manual testing techniques. The specialist leverages frameworks such as MITRE ATT&CK, OWASP, NIST, and industry best practices to identify vulnerabilities that may not be detected by automated tools. The position also supports software assurance initiatives through secure code reviews, application security testing, and Supply Chain Risk Management (SCRM) activities to strengthen the cybersecurity posture of DHS IE systems. Working closely with Security Operations Center (SOC) personnel, Cybersecurity Engineers, Information System Security Officers (ISSOs), Information System Security Managers (ISSMs), developers, and Government stakeholders, the Vulnerability Assessment & Penetration Testing Specialist provides expert recommendations to reduce enterprise cyber risk while ensuring compliance with Federal, DHS, and Intelligence Community (IC) cybersecurity requirements. Key Responsibilities Lead and conduct comprehensive penetration testing engagements for DHS Intelligence Enterprise systems, networks, applications, cloud environments, and infrastructure. Perform penetration testing using industry-recognized methodologies, including: MITRE ATT&CK Framework OWASP Web Security Testing Guide NIST penetration testing guidance PTES (Penetration Testing Execution Standard) Plan and execute all phases of penetration testing, including: Pre-engagement planning Rules of Engagement (ROE) Threat intelligence gathering Threat modeling Vulnerability identification Exploitation Post-exploitation analysis Reporting and remediation recommendations Utilize advanced manual testing techniques to identify vulnerabilities that are not detectable through automated scanning tools. Perform network, web application, wireless, cloud, and infrastructure penetration testing using ethical hacking techniques while ensuring no disruption to production environments. Validate Security Operations Center (SOC) detection and incident response capabilities through controlled adversary emulation and red team testing. Assess logging, monitoring, detection, and response mechanisms to identify gaps in defensive capabilities. Perform software assurance reviews by conducting security and compliance testing of software requests and applications prior to deployment. Review Software Assurance Request Forms and provide technical adjudication and security recommendations. Conduct vulnerability assessments of enterprise systems and deliver comprehensive Security Assessment Reports (SARs) and Vulnerability Assessment Reports (VARs) within established service-level agreements. Perform Supply Chain Risk Management (SCRM) and Cyber Supply Chain Risk Management (C-SCRM) assessments for software, hardware, and third‑party technologies supporting DHS IE. Conduct secure source code reviews using both automated and manual analysis techniques to identify software vulnerabilities and coding weaknesses. Utilize static application security testing (SAST), dynamic application security testing (DAST), and software composition analysis (SCA) tools to evaluate software security. Maintain the penetration testing toolkit, ensuring monthly software updates, quarterly configuration reviews, and compliance with approved security baselines. Develop comprehensive penetration testing reports documenting: Testing methodology Attack paths Exploited vulnerabilities MITRE ATT&CK mappings Risk ratings Technical findings Executive summaries Remediation recommendations Develop and maintain Standard Operating Procedures (SOPs) supporting penetration testing, software assurance, vulnerability assessment, and SCRM activities. Collaborate with cybersecurity engineering, DevSecOps, cloud engineering, and system administration teams to remediate identified vulnerabilities. Support cybersecurity audits, security assessments, authorization activities, and continuous monitoring initiatives. Participate in cybersecurity working groups and provide technical guidance on emerging threats, offensive security techniques, and vulnerability management best practices. Minimum Qualifications Active Top Secret/Sensitive Compartmented Information (TS/SCI) security clearance. Minimum 7-10 years of experience performing penetration testing, vulnerability assessments, software assurance, and offensive cybersecurity activities within Federal Government or Intelligence Community environments. Current Certified Ethical Hacker (CEH) certification. Current Certified Information Systems Security Professional (CISSP) certification. Expert knowledge of: MITRE ATT&CK Framework OWASP Testing Methodology OWASP Top 10 NIST Cybersecurity Framework Penetration Testing Execution Standard (PTES) Demonstrated experience with penetration testing and vulnerability assessment tools such as: Burp Suite Professional Nessus / ACAS Nmap Metasploit Framework Wireshark Kali Linux WebInspect Nikto Other industry-standard offensive security tools Experience performing software assurance using: SonarQube GitLab Security Static Application Security Testing (SAST) Dynamic Application Security Testing (DAST) Software Composition Analysis (SCA) Minimum 2 years of experience in each of the following: Software Assurance Penetration Testing Vulnerability Assessment Patch Management Secure Cloud and Hybrid Cloud Security Engineering Experience performing secure code reviews and identifying application security vulnerabilities. Bachelor's degree in Cybersecurity, Computer Science, Software Engineering, Information Systems, or a related technical discipline. Preferred Qualifications Offensive Security Certified Professional (OSCP) certification. GIAC Penetration Tester (GPEN) certification. Experience conducting penetration testing of Cross Domain Solutions (CDS) and classified information systems. Experience supporting DHS Intelligence & Analysis (I&A) or other Intelligence Community cybersecurity programs. Familiarity with: DISA Security Technical Implementation Guides (STIGs) Container security (Docker, Kubernetes) Kubernetes security Serverless application security Secure DevSecOps pipelines Experience supporting Cloud Service Provider (AWS, Azure, or Google Cloud) penetration testing and cloud-native security assessments. Experience performing adversary emulation, purple team, or red team exercises. Familiarity with NIST SP 800-161 Cyber Supply Chain Risk Management (C-SCRM) guidance. Required Certifications The following current certifications are required: Certified Ethical Hacker (CEH) Certified Information Systems Security Professional (CISSP) Preferred Certifications Include Offensive Security Certified Professional (OSCP) GIAC Penetration Tester (GPEN) Clearance Requirement Active Top Secret/Sensitive Compartmented Information (TS/SCI) Clearance Required About the Organization Established in 2008, RiVidium, Inc. (dba TripleCyber) is a VA-Verified SDVOSB and an SBA-Certified 8(a) company. To prepare our clients for the future, RiVidium has balanced all parts of our organization to attract the finest employees in order to 'Strive to be the missing element defining tomorrow's technology'. RiVidium keeps pace and surpasses its competitors by meeting challenges of advancements in Logistics, Human Capital, Cyber, Intelligence & Technology. EOE Statement We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status or any other characteristic protected by law. If you need a reasonable accommodation for any part of the employment process, please contact Human Resources (HR) at View email address on click.appcast.io. #J-18808-Ljbffr Rividium Inc

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Vulnerability Assessment & Penetration Testing Specialist Level III in Washington DC vacancy
  •  ...tailored solutions, tested leadership, and trusted...  ...is seeking a Penetration Tester III to support proactive...  ...red team activities, assessing security posture across...  ...validation, and reporting of vulnerabilities to improve cyber...  ...: OtherExperience level: Mid-Senior... 
    Suggested
    Contract work
    Work at office
    Worldwide
    Monday to Friday
    Weekend work
    Afternoon shift

    SOSi

    Washington DC
    2 days ago
  • $130k - $190k

     ...currently seeking a Penetration Tester. This position...  ..., development, test, and evaluation of security...  ..., cybersecurity assessment, technical analysis,...  ...cybersecurity assessments, vulnerability assessments, and...  ...(DAU) T&E Level I, II, and/or III certification or equivalentExperience... 
    Suggested
    Full time
    Work experience placement
    Work at office
    Local area
    Remote work
    Worldwide
    Flexible hours

    Battelle Memorial Institute

    Washington DC
    2 days ago
  • Cybersecurity Vulnerability Analyst (Incident Manager III) Description Supporting our prime contractor and their...  ...creativity and divergent thinking to assess and explain the impact of...  ...cybersecurity analyst (i.e. SOC Analyst or Penetration Tester) is required Experience... 
    Suggested
    For contractors

    kozmetickesluzby.vecnakraska.sk - Jobboard

    Arlington, VA
    4 days ago
  •  ...DescriptionProSidian Seeks a Cyber Security Penetration Testing Specialist (SCA Code: -) in CONUS -...  ...engagement for a cabinet-level department of the US Govt...  ...’s Office of Enterprise Assessment (EA) provides leadership...  ...to prevent exploitable vulnerabilities (including human factor... 
    Suggested
    Full time
    Temporary work
    For contractors
    Work at office
    Flexible hours

    Prosidian Consultng

    Washington DC
    3 days ago
  •  ...seeking a highly motivated Penetration Tester. The...  ...provide support for HVA Assessments using methodology by...  ...tactics and procedures to test preventative,...  ...remediate cybersecurity --vulnerabilities across the State Department...  ...policy; assess the level of risk; and develop... 
    Suggested
    Work at office
    Local area
    Shift work
    3 days per week

    Science Applications International Corporation

    Beltsville, MD
    3 days ago
  • $95k - $112k

     ...Decisions is seeking a Penetration Tester to support...  ...leading penetration tests to assess the security of customer...  .... Identify vulnerabilities and develop recommended...  ...Penetration Testing Specialist (CPTS) TCM...  ...and appraised at CMMI Level 3 for Services and Development... 
    Contract work
    Remote work

    SkyePoint Decisions

    Arlington, VA
    5 days ago
  • $115k - $203k

     ...Senior Penetration Tester Job Description Overview...  ...pentesting capabilities to test our internal and...  ...to validate identified vulnerabilities and demonstrate the exploitation...  ...the exploit to senior level management is key to...  ...risks, and MCP server assessment. Hands-on... 
    Hourly pay
    Full time
    Work at office
    Work from home
    Monday to Thursday

    CoStar Group

    Arlington, VA
    1 day ago
  •  ...Job Title: Senior Penetration Tester Pay Type : SALARIED...  ...& Compliance, Vulnerability Management, Continuous...  ...methods, scripts, and tests for the team, with a focus...  ...Web Applications Assess and test the security...  ...issues and associated risk levels Present findings,... 
    Full time
    Work experience placement
    Remote work
    Monday to Friday
    Shift work
    Night shift

    Quzara LLC

    Washington DC
    4 days ago
  • The Opportunity:Tetra Tech is adding an Analyst (Level I,II,III,IV,V) to our Tetra Tech team based in Courthouse, Virginia. Why Tetra Tech...  ...services.The Analyst (Levels I-V) conducts organizational assessments, evaluations, and technical analyses to improve management... 
    Contract work
    For contractors
    Work at office
    Worldwide

    Tetra Tech

    Arlington, VA
    3 days ago
  •  ...Vulnerability Management Analyst Location- Joint Base Andrews, MD...  ...charities. We are proud of our CMMI Level 3 for Services and...  ...by performing vulnerability assessments, reviewing DISA STIG compliance...  ...identify CAT I, CAT II, and CAT III vulnerabilities, validate findings... 
    Temporary work
    Local area
    Flexible hours

    TIME Systems

    Andrews Air Force Base, MD
    4 days ago
  • $104k - $166k

     ...seeking to hire an experienced Penetration Tester for its Federal...  ...security missions by identifying vulnerabilities, emulating real‑world...  ...full‑spectrum penetration testing across enterprise, cloud, mobile...  ..., CPT, or LPTCISA AES HVA Assessment Lead or Technical Lead... 
    Contract work
    Currently hiring
    Shift work

    Peraton Corporation

    Washington DC
    3 days ago
  • $86k - $138k

     ...seeking an experienced Cyber Penetration Tester to become part of...  ...performing and leading penetration tests to assess the security of customer systems.Identify vulnerabilities and develop recommended...  ...Certified Penetration Testing Specialist (CPTS)TCM Security Practical... 
    Contract work
    Flexible hours
    Shift work

    Peraton Corporation

    Arlington, VA
    3 days ago
  • $124.54k - $180k

     ...clearance to support DHS onsite in Washington, DC.ResponsibilitiesThe Senior Penetration Tester serves as Key Personnel responsible for leading advanced penetration testing and vulnerability assessment activities within a TS/SCI environment. This role ensures mission‑... 
    Currently hiring

    Govcio

    Washington DC
    2 days ago
  • $90k - $130k

     ...seeking a highly motivated Penetration Tester to join our cybersecurity...  ...comprehensive penetration tests across applications,...  ...identifying and exploiting vulnerabilities to validate and strengthen the...  ...application, and social engineering assessments. Use a combination of... 
    Full time
    Work at office

    Praescient Analytics

    Arlington, VA
    1 day ago
  •  ...Solutions is seeking an experienced Penetration Testerto lead advanced security assessments and contribute to the...  ...development and execution of penetration testing strategies. This role combines...  ...and applications.Identify vulnerabilities, assess risks, and deliver clear... 
    3 days per week

    ASRC Federal Holding Company

    Washington DC
    14 hours ago
  •  ...We deliver tailored solutions, tested leadership, and trusted results...  ...Overview SOSi is seeking a Risk and Vulnerability Analyst II to support vulnerability assessment and risk analysis activities in...  ...-timeFunction: OtherExperience level: Mid-Senior LevelIndustry: Information... 
    Contract work
    Work at office
    Worldwide
    Monday to Friday
    Weekend work
    Afternoon shift

    SOSi

    Washington DC
    3 days ago
  •  ...Penetration Tester Locations: Los Angeles (CA), Dallas (TX), Washington...  ...teaming and penetration testing Perform penetration...  ...more to identify exploits and vulnerabilities Create and deliver...  ...vulnerability testing, web application assessments, social engineering, and... 
    Work experience placement

    WATI

    Washington DC
    2 days ago
  •  ...Description Tharros is seeking a Senior Penetration Testing, Software Assurance and Vulnerability Assessment Engineer to support a DHS Intelligence and Analysis cybersecurity program in the National Capital Region. This role will support advanced penetration... 

    ANALYGENCE Inc

    Washington DC
    1 day ago
  •  ...Cybersecurity Assessments And Exercises Vice President Drive the...  ...through hands-on offensive testing. As an Assessments &...  ...plan, execute, and report on penetration tests targeting high-impact...  ...will proactively identify vulnerabilities, collaborate with application... 

    Chase

    Washington DC
    5 days ago
  •  ...Job Summary: The Penetration Testing Specialist / Information Security Analyst Journeyman is responsible for conducting thorough penetration tests and vulnerability assessments to identify and exploit security weaknesses. This role involves hands-on testing, validating... 
    Flexible hours

    vTech Solution

    Washington DC
    4 days ago
  •  ...Penetration Tester Alexandria, VA Type: Contract-to-Hire...  ...an experienced penetration testing professional to plan and execute...  ...comprehensive security assessments across applications, systems...  .... Document findings and vulnerabilities with risk categorization, impact... 
    Hourly pay
    Full time
    Contract work
    Local area
    2 days per week
    3 days per week

    Eliassen Group

    Alexandria, VA
    3 days ago
  • $106.3k - $221.1k

     ...Senior Penetration Tester At Accenture Federal Services, nothing matters more than helping...  ...will conduct comprehensive penetration tests on applications, networks, and systems. Identify and exploit security vulnerabilities to assess risk, developing detailed reports on... 
    Local area

    Accenture Federal Services

    Arlington, VA
    2 days ago
  • $90k - $155k

     ...our team. ABSC is seeking a Vulnerability Management Analyst to join our...  ...vulnerability detection, assessment, analysis, remediation, and...  ...Support periodic reviews and testing of RMF security controls. Configure...  ...DoD 8570/8140 IAT Level II certification. Option 2 –... 
    Contract work
    Remote work
    Flexible hours

    Absolute Business Solutions Corp

    Arlington, VA
    14 hours ago
  • $71.6k - $119.4k

     ...215 Are you a collaborative Penetration Tester looking to work for a mission...  ...perform hands-on security testing and peer review activities, validate vulnerabilities and security controls, and...  ...triaging findings from third-party assessments, ensuring timely follow-up and... 
    Full time
    Local area
    Work from home

    RELX

    Alexandria, VA
    2 days ago
  • $66k - $106k

     ...Jr Cyber Penetration Tester Job Locations US-VA-Arlington Requisition...  ...: Support the Penetration Testing (Red Cell) Team. Assess the current state of the customer'...  ...security by identifying all vulnerabilities and security measures. Help customer... 
    Contract work
    Local area
    Remote work
    Shift work

    Peraton

    Arlington, VA
    3 days ago
  • $104.8k - $192.2k

     ...Sector - Cybersecurity - Penetration Tester - Senior...  ...managing engagements to assess, improve, build, and in...  ...discovering the newest security vulnerabilities, attending and...  ...of our Penetration Testing team, you'll identify...  ...and mentoring to staff-level penetration testers during... 
    For contractors
    Summer holiday
    Work at office
    Local area
    Flexible hours

    EY (Ernst & Young)

    McLean, VA
    4 days ago
  •  ...Senior Vulnerability Analyst This position supports the Information Risk Strategy Management (IRSM) Vulnerability Management...  ...identified through vulnerability scanning and assessments/penetration tests along with any emergency concerns are assigned to owners... 

    Software Technology Inc

    Washington DC
    2 days ago
  •  ...Job Title : Senior Penetration Tester / Red Team Consultant Client...  ...of hands-on penetration testing/offensive security experience...  ...and Microsoft 365 security assessments Network, web application...  ...escalation and lateral movement Vulnerability validation, exploitation and... 
    Temporary work
    Remote work

    Inabia Software & Consulting Inc.

    Washington DC
    8 days ago
  •  ...offers integrated CMMI Level 3 processes, tools, and...  ...Responsibilities : Lead SBA’s penetration, offensive, and adversarial testing services, including gray...  ...actor attacks, and assess SOC detection...  ...Provide source code analysis, vulnerability scanning, phishing simulations... 
    Local area
    Remote work

    eTelligent Group LLC

    Washington DC
    more than 2 months ago
  • $110k - $150k

     ...over bureaucracy. Lead Penetration Tester Location:...  ...leads operational security assessments and penetration testing across a portfolio of federal...  ...reach agency CIO and CISO-level leadership. The program also...  ...upon Stay current on vulnerability research, offensive... 
    Full time
    Work experience placement
    Flexible hours

    Revolutional, LLC

    Washington DC
    15 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Vulnerability Assessment & Penetration Testing Specialist Level III. Be the first to apply!