Senior Penetration Tester

Iron Vine Security
Suitland, MD
Full-time

Job Requirements :

Strong written and verbal communication skills.

Knowledge of capabilities and requirements analysis, cyber defense and vulnerability assessment tools and their capabilities, complex data structures, computer algorithms, programming principles, concepts and practices of processing digital forensic data.

Knowledge of vulnerability information dissemination sources (e.g., alerts, advisories, errata, and bulletins).

Plan and create penetration methods, scripts and tests

Understanding of incident categories, incident responses, and timelines for responses.

Experience with incident response and handling methodologies.

Carry out remote testing of a client's network or onsite testing of their infrastructure to expose weaknesses in security

Network access, identity, and access management experience (e.g., public key infrastructure, Oauth, OpenID, SAML, SPML).

Indepth understanding of network hardware devices and functions and network traffic analysis methods.

Knowledge of server diagnostic tools and fault identification techniques.

Simulate security breaches to test a system's relative security

Certifications / Licenses :

Bachelors degree or higher

10+ years’ penetration testing experience as well as additional experience in network security, reverse engineering, programming, databases, mainframes, web applications

One or more of the following certifications preferred :

Offensive Security Certified Professional (OSCP)

Certified Ethical Hacker (CEH) Certification

GIAC Penetration Tester (GPEN) Certification

Active TS / SCI clearance

Additional Experience Preferred :

Experience conducting vulnerability scans and recognizing vulnerabilities in security systems.

Skill in detecting host and network based intrusions via intrusion detection technologies (e.g., Snort).

Skill in determining an appropriate level of test rigor for a given system.

Skill in determining how a security system should work (including its resilience and dependability capabilities) and how changes in conditions, operations, or the environment will affect these outcomes.

Developing data dictionaries, data models, operations-based testing scenarios, security system access controls.

Skill in mimicking threat behaviors, optimizing database performance, and performing packet-level analysis using appropriate tools (e.

g., Wireshark, tcpdump).

Experience identifying, modifying, and manipulating applicable system components within Windows, Unix, or Linux (e.g., passwords, user accounts, files).

Collecting, processing, packaging, transporting, and storing electronic evidence to avoid alteration, loss, physical damage, or destruction of data.

Setting up a forensic workstation and forensic tool suites (e.g., EnCase, Sleuthkit, FTK).

Analyzing anomalous code as malicious or benign, volatile data.

Interpreting results of debugger to ascertain tactics, techniques, and procedures.

Skill in Regression Analysis (e.g., Hierarchical Stepwise, Generalized Linear Model, Ordinary Least Squares, Tree-Based Methods, Logistic).

Position Responsibilities :

Identify threat tactics, methodologies, gaps, and shortfalls.

Identify and direct the remediation of technical problems encountered during testing and implementation of new systems (e.

g., identify and find work-arounds for communication protocols that are not interoperable).

Identify security implications and apply methodologies within centralized and decentralized environments across the enterprise’s computer systems in software development.

Identify security issues around steady state operation and management of software and incorporate security measures that must be taken when a product reaches its end of life.

Identify, assess, and recommend cybersecurity or cybersecurity-enabled products for use within a system and ensure that recommended products are in compliance with organization's evaluation and validation requirements.

Identify, collect, and seize documentary or physical evidence, to include digital media and logs associated with cyber intrusion incidents, investigations, and operations.

Maintain baseline system security according to organizational policies.

Maintain database management systems software.

Maintain deployable cyber defense audit toolkit (e.g., specialized cyber defense software and hardware) to support cyber defense audit missions.

Manage threat or target analysis of cyber defense information and production of threat information within the enterprise.

Monitor and evaluate a system's compliance with information technology (IT) security, resilience, and dependability requirements.

Monitor and evaluate the effectiveness of the enterprise's cybersecurity safeguards to ensure that they provide the intended level of protection.

Verify stability, interoperability, portability, and / or scalability of system architecture.

Work with stakeholders to resolve computer security incidents and vulnerability compliance.

30+ days ago
Related jobs
Iron Vine Security
Suitland-Silver Hill, Maryland

GIAC Penetration Tester (GPEN) Certification . Plan and create penetration methods, scripts and tests . ...

Promoted
Intuit
Silver Spring, Maryland
Remote

As part of this position, you have the opportunity to work 100% remotely, collaborating with an exceptional team from the comfort of your home or office. By providing tax advice, full service return preparation, tax calculations, and managing product/software inquiries, you will be working toward ad...

Promoted
Online Consumer Panels America
Maryland

Product Testers are wanted to work from home nationwide in the US to fulfill upcoming contracts with national and international companies. Online Consumer Panels America is a consulting firm that specializes in product testing and product development work. We design and conduct In-Home Usage Testing...

Promoted
Tata Consumer Products - USA
Greater Landover, Maryland

Tata Consumer products is on a journey to become a multi category Premier FMCG company, and this role plays a key part in driving our Landover plant performance and our people development program underpinning products that are manufactured to the right cost & quality standards. At Tata Consumer ...

Promoted
Zen Strategics LLC
Silver Spring, Maryland

At least 5 years of recent experience (within the last 6 years) in conducting penetration testing or the ability to bring in a penetration tester when required. Seize your opportunity to make a personal impact as a Penetration Tester. As a Penetration Tester, you will be responsible for ensuring the...

Promoted
ARES Corporation
Greenbelt, Maryland

The Product Owner Applications, and Platform Services will serve as the Product Owner within the Custom Web, Agile Release Train (ART) throughout all stages of the product life cycle; Introduction, Growth, Maturity, and Decline. Working closely with Product Management, collaborate with business owne...

Promoted
AccelerEd
Hyattsville, Maryland

The Workday Human Capital Product Owner works in the Department of Information Technology Solutions (ITS). Drive Workday application roadmap at an enterprise level in collaboration with cross-functional stakeholders to achieve the product vision and strategically aligned prioritization. ...

Promoted
Computercraft Corporation
Bethesda, Maryland

Senior-level experience in Product Owner or Product Manager positions bringing public-facing web, data, or cloud products to market (e. The dbGap Product Owner will help develop and manage data-access-related products, tools, and protocols for the database of Genotypes and Phenotypes (dbGaP), a uniq...

Promoted
MATRIX SYSTEMS & TECHNOLOGIES INC
Bowie, Maryland

Experience with performance strategy and modeling. Experience with TOAD Rational CLM tools (Quality Manager, Team Concert, Doors Next Generation) Microsoft (MS) Office Excel, MS Word, MS Project, MS Visio CTRL-M (server) Adobe Pro SecureCRT, SecureFx IBM Mainframe (TSO and JCL) Java Batch (SpringBat...

Promoted
OCPA
Maryland
Remote

Product Testers are wanted to work from home nationwide in the US to fulfill upcoming contracts with national and international companies. A paid Product Tester position is perfect for those looking for an entry-level opportunity, flexible or seasonal work, temporary work or part-time work. Telecomm...