Penetration Tester
ANALYGENCE Inc
Description Are you a problem solver? Do you like complex, challenging puzzles? This position involves a blending of several disciplines to include, but not limited, penetration testing, reverse engineering, and code/script development. In this role, you will apply your talents to reverse engineer executables to identify flaws and create and operationally test exploits to take advantage of an identified vulnerability or zero days. The Air Combat Command's 67th Cyberspace Wing (67 CW), 346th Cyber Test and Evaluation Squadron (346 CTES), executes, and contributes as both an operational and participating test organization in a full array of operational tests of various cyber weapons in coordination with the 318 Range Squadron (318RANS) who provides instrumented cyber range services, through both physical hardware and virtual systems. In support of this mission, Tharros is seeking a Penetration Tester (PT) to conduct assessments of threats and vulnerabilities; determine deviations from acceptable configurations, enterprise, or local policy; assess risk levels; and recommend/develop appropriate mitigation countermeasures in operational and nonoperational situations. The PT also performs assessments of systems and networks within the network environment or enclave and identifies where they deviate from acceptable configurations, enclave policy, or local policy and measures effectiveness of defense-in-depth architecture against known vulnerabilities. Responsibilities include: Analyze organization's cyber defense policies and configurations and evaluate compliance with regulations and organizational directives Analyze software applications to gain an understanding of the system, mission and or application vulnerabilities and exploits Develop exploits for exposed vulnerabilities with a focus on non-interference of mission partner systems and networks Conduct and/or support authorized penetration testing on enterprise network assets Maintain deployable cyber defense audit toolkit (e.g., specialized cyber defense software and hardware) to support cyber defense audit missions Maintain knowledge of applicable cyber defense policies, regulations, and compliance documents specifically related to cyber defense auditing Prepare audit reports that identify technical and procedural findings and provide recommended remediation strategies/solutions Conduct required reviews as appropriate within environment (e.g., Technical Surveillance, Countermeasure Reviews [TSCM], TEMPEST countermeasure reviews) Perform technical (evaluation of technology) and nontechnical (evaluation of people and operations) risk and vulnerability assessments of relevant technology focus areas (e.g., local computing environment, network and infrastructure, enclave boundary, supporting infrastructure, and applications) Make recommendations regarding the selection of cost-effective security controls to mitigate risk (e.g., protection of information, systems and processes) Position requires travel up to 25% supporting customer assessments up to 1-4 weeks in duration. Requirements Current Top Secret clearance with SCI eligibility. Bachelor's degree in a related field and a minimum of 8-12 years of experience providing related penetration testing services. IAT Level III certification required (CASP, CISSP+, CISA, etc.). Experience with computer networking concepts and protocols, and network security methodologies. Understanding risk management processes (e.g., methods for assessing and mitigating risk), laws, regulations, policies, and ethics as they relate to cybersecurity and privacy, cybersecurity and privacy principles, cyber threats and vulnerabilities, specific operational impacts of cybersecurity lapses and application vulnerabilities. Knowledge of cryptography and cryptographic key management concepts, data backup and recovery, host/network access control mechanisms (e.g., access control list, capabilities lists). Knowledge of cybersecurity and privacy principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation). Knowledge of network access, identity, and access management (e.g., public key infrastructure, Oauth, OpenID, SAML, SPML), how traffic flows across the network (e.g., Transmission Control Protocol [TCP] and Internet Protocol [IP], Open System Interconnection Model [OSI], Information Technology Infrastructure Library, current version [ITIL]). Knowledge of programming language structures and logic, system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, Procedural Language/Structured Query Language [PL/SQL] and injections, race conditions, covert channel, replay, return-oriented attacks, malicious code). Knowledge of systems diagnostic tools and fault identification techniques and what constitutes a network attack and a network attack's relationship to both threats and vulnerabilities. Knowledge of interpreted and compiled computer languages, different classes of attacks (e.g., passive, active, insider, close-in, distribution attacks). Knowledge of cyber attackers (e.g., script kiddies, insider threat, non-nation state sponsored, and nation sponsored), system administration, network, and operating system hardening techniques Knowledge of cyber-attack stages (e.g., reconnaissance, scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks). Knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth), security models (e.g., Bell-LaPadula model, Biba integrity model, Clark-Wilson integrity model). Knowledge of ethical hacking principles and techniques and data backup and restoration concepts, system administration concepts for operating systems such as but not limited to Unix/Linux, IOS, Android, and Windows operating systems and infrastructure supporting information technology (IT) for safety, performance, and reliability. Knowledge of an organization's information classification program and procedures for information compromise, packet-level analysis using appropriate tools (e.g., Wireshark, tcpdump). Knowledge of cryptology, network protocols such as TCP/IP, Dynamic Host Configuration, Domain Name System (DNS), and directory services. Knowledge of penetration testing principles, tools, and techniques and an organization's threat environment. Knowledge of Application Security Risks (e.g. Open Web Application Security Project Top 10 list). Skill in conducting vulnerability scans and recognizing vulnerabilities in security systems and assessing the robustness of security systems and designs. Detecting host and network-based intrusions via intrusion detection technologies (e.g., Snort). Experience in mimicking threat behaviors, the use of penetration testing tools and techniques and the use of social engineering techniques. (e.g., phishing, baiting, tailgating, etc.). Network analysis tools to identify vulnerabilities. (e.g., fuzzing, nmap, etc.), reviewing logs to identify evidence of past intrusions and conducting application vulnerability assessments. Perform impact/risk assessments and develop insights about the context of an organization's threat environment. Experience with cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation) and the ability to identify systemic security issues based on the analysis of vulnerability and configuration data. Programming language structures (e.g., source code review) and logic and the ability to share meaningful insights about the context of an organization's threat environment that improve its risk management posture. Understanding cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation). ANALYGENCE Inc
$500 per month
...Become a Professional Game Tester We're looking for passionate gamers to join our elite team of mobile game testers. Get paid to play and test the latest games before they launch. $500+ Avg Monthly Pay 5-10 Hours/Week 100% Remote Position Requirements:...SuggestedRemote work10 hours per week- Description Summary: The Clinical Informatics Systems Analyst Senior is primarily responsible for assisting in the operation and administration of clinical information systems, collaborating with clinical and technical associates to enhance workflow methodology and...SuggestedFull timeWork at officeMonday to Friday
$112k - $179k
Peraton is looking for a Digital Forensic Analyst to support the Air Force Office of Special Investigations in San Antonio, TX. The role requires acquiring and analyzing data from electronic devices and handling sensitive criminal investigations. The ideal candidate will...SuggestedWork at office$82.6k - $162.8k
Position Summary Consultant - Technology Resilience Accelerate your career as a Consultant, Technical Resilience, helping clients strengthen their ability to prepare for, respond to, and recover from disruption. In this role, you will support the design and delivery...SuggestedLocal areaVisa sponsorship- Job OverviewThe Rackspace Internal Audit team is looking for a Staff Technology Auditor with passion for the latest cloud technologies to develop their career at the #1 Managed Cloud Company. The Staff Technology Auditor will play a critical role in conducting global technology...SuggestedFull time
- ...experience is required Completion of formal offensive cyber operations training Experience conducting network exploitation, penetration testing, or red team operations Proficiency with UNIX/Linux and Windows operating systems Strong understanding of network...Work experience placementImmediate start
- ...DESIRED SKILLS Experience with cloud security models Knowledge of identity and access management (IAM) Familiarity with penetration testing tools Understanding of secure software development practices Proficiency in scripting for security automation (e.g....Temporary workFor contractorsImmediate startFlexible hours
- ...documentation and report-writing abilities DESIRED SKILLS Knowledge of cloud security practices (e.g., AWS, Azure) Familiarity with penetration testing results interpretation Experience in managing classified information systems Understanding of advanced threat...Temporary workFor contractorsImmediate startFlexible hours
- We are looking for a Systems Security Engineer to strengthen and secure enterprise infrastructure for a respected financial institution in San Antonio, Texas. This position blends hands-on systems administration with a strong security focus, making it well suited for someone...
- ...Application Firewalls (WAF), Endpoint Detection and Response (EDR), anti-virus tools, sandboxing, network- and host-based firewalls, penetration-testing tools, or technologies used to identify Advanced Persistent Threats (APTs) - Experience operationalizing threat...Local areaVisa sponsorship
- Position Summary Deloitte helps organizations protect and grow their business by delivering risk management solutions across critical domains, including cyber. Within that environment, this role leads the delivery, growth, and continuous improvement of large-scale...Contract workLocal areaVisa sponsorship
$134.5k - $265.1k
Position Summary Our Deloitte Cyber Defense & Resilience team recognizes that resilient organizations must protect not only data and technology, but also people, facilities, assets, and operations. Join our Physical Security consulting team to help clients address...Contract workLocal areaVisa sponsorship$163.4k - $322.1k
Position Summary Drive strategic consulting, advisory, and delivery efforts that help clients strengthen physical security programs, align security capabilities to enterprise priorities, and build resilience across people, facilities, assets, and operations. This...Local areaVisa sponsorship- ...Response/Extended Detection and Response (EDR/XDR), antivirus, sandboxing, network- and host-based firewalls, threat intelligence, and penetration testing - Bachelor’s degree in computer science, information systems, information security, mathematics, decision sciences, risk...Local areaVisa sponsorship
$161k - $207k
Watch Desk Systems Analyst - Texas Make an Impact Where It Matters Most At Intelliforce, we support mission systems that have to stay available, responsive, and understood around the clock. In this role, you will help support Watch Desk operations supporting complex...Full timeWork at officeImmediate startVisa sponsorshipShift workDay shift- POSITION SUMMARY/RESPONSIBILITIES The Senior Cyber Security Analyst must have a deep understanding of information security protocols and a passion for protecting Community First Health Plans Inc. (Community First) healthcare data. In this role, the Senior Analyst will...
$75k - $105k
Responsibilities & Qualifications RESPONSIBILITIES Assists with Certification & Accreditation (C&A), Authorization to Operate (ATO), and security authorization activities for DoW information systems. Provides administrative and technical support to the ISSM in...Full timeContract workTemporary workWork at officeLocal areaMonday to FridayWeekend workDay shiftAfternoon shift$82.6k - $162.8k
...endpoint detection and response (EDR), antivirus tools, sandboxing, network- and host-based firewalls, threat intelligence, and penetration testing.Documented coursework, training, certification, or experience identifying attack activity, including network probing and...Work at officeLocal areaVisa sponsorshipShift workRotating shift$39 - $43 per hour
DescriptionKforce is seeking a Cybersecurity Specialist in San Antonio, TX to support governance, risk, and compliance (GRC) initiatives within a growing cybersecurity program. This role will serve as a key liaison between technical teams and business stakeholders, helping...$82.6k - $162.8k
Position Summary Helping clients protect people, assets, and critical operations requires a practical approach to physical security and resilience. As a Physical Security Consultant, you will support clients in assessing risk, strengthening protective measures, and...Local areaVisa sponsorship$105.4k - $207.8k
...Firewall (WAF), Endpoint detection and response (EDR), Anti-Virus, Sandboxing, network- and host-based firewalls, Threat Intelligence, Penetration Testing, etc.Knowledge of Advanced Persistent Threats (APT) tactics, techniques, and procedures; understanding of possible attack...Work at officeLocal areaVisa sponsorshipShift workRotating shift- ...actions What You Bring: Requirements: DoDD 8570.01-M/8140.01 I AT Level III CND Active TS/SCI Five years' of penetration testing experience. BA/BS or MA/MS Five (5) years of penetration testing experience. Demonstrated advanced knowledge of...Temporary workFor contractorsFlexible hours
- Chief Information Security Officer (CISO), Information Security & Compliance About the Company Innovative artificial intelligence (AI) & marketing analytics platform Industry Information Technology and Services Type Public Company Founded 2014 ...
- Chief Information Security Officer (CISO) About the Company Innovative provider of data safety & recovery solutions Industry Information Technology and Services Type Privately Held Founded 2024 Employees 51-200 Specialties cloud backup ...
- ...Information Systems Security Managers (ISSMs), Information Systems Security Engineers (ISSEs), Cyber Operations Teams (COT), Cyber Penetration Teams (CPT), Product Owners, software developers, and DevSecOps engineers to maintain secure cloud-native capabilities while...Full timeTemporary workImmediate start
$171.6k - $338.3k
Position Summary Deloitte Cyber understands the unique challenges and opportunities businesses face in cybersecurity. Deloitte’s Cyber team helps our clients navigate the ever-changing threat landscape. We simplify complexity, and enable businesses to operate with...Local area- ...technologies Familiarity with regulatory compliance standards (e.g., NIST, HIPAA) Experience with vulnerability scanning and penetration testing Knowledge of identity and access management (IAM) practices Expertise in threat detection and mitigation strategies...Temporary workFor contractorsImmediate startFlexible hours
$142.32k - $273.93k
...using a variety of cyber defense tools to detect and respond to threats. Conducts vulnerability, security configuration, and/or penetration testing assessments of systems and networks. Identifies cyber threats, analyzes operational impacts, and communicates to appropriate...Full timeH1bWork at officeRemote workHome officeRelocation packageFlexible hours- ...ISSE will serve as an embedded cybersecurity engineer working alongside Government engineers, Cyber Operations Teams (COT), Cyber Penetration Teams (CPT), software developers, cloud engineers, and DevSecOps personnel to engineer, implement, automate, and continuously...Full timeContract workTemporary workImmediate start
- ...endpoint protection tools Familiarity with network protocols and security Ability to perform vulnerability assessments and penetration tests Expertise in implementing encryption and secure authentication methods DESIRED SKILLS Knowledge of cloud security...Temporary workFor contractorsImmediate startFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Penetration Tester. Be the first to apply!




