Jobs · Maryland

IT Security Specialist - Penetration Tester

Signal Corps Regimental Association · Silver Spring, MD · 1 wk ago
Full-time

About the Role

AttainX, Inc. is in search of a highly energetic Penetration Tester to join our team on a cyber security program supporting our US federal government client. We're looking for a highly skilled and experienced professional with a minimum of 5 years of proven expertise in penetration testing and ethical hacking. In this role, you'll take a hands-on approach to identify, exploit, and report security weaknesses across diverse environments, including AWS, Azure, and on-premises infrastructure. Your work will directly contribute to fortifying critical systems and protecting sensitive data from evolving cyber threats.

Responsibilities

  • Protocol analysis, vulnerability discovery and exploitation, post exploitation impact analysis, and physical security
  • Serve as highly technical problem-solver who understands software architectures, security, communication protocols, virtualization, and hardware, and work with other engineers to the resolution of problems in design, development, and operations
  • Perform manual and automated firmware analysis on target devices
  • Perform pen tests, fuzzing and custom exploit attacks against client systems
  • Review deployment architectures, topologies and conops for compliance regulatory security mandates
  • Produce security reports suitable for submission to regulatory bodies
  • Conduct hands-on technical testing beyond automated tool validation, including full exploitation and leveraging of access within multiple environments
  • Conduct scenario-based security testing, or red teaming to identify gaps in detection and response capabilities of client end systems
  • Conduct research and testing in support of client requirements
  • Design, implement, and integrate security solutions
  • Design, develop and support the company's line of technology products
  • Analyze information security systems and applications
  • Recommend and develop security measures to protect information against unauthorized modification or loss

Qualifications

  • A minimum of 5 years of proven penetration testing and ethical hacking experience
  • Hands-on experience in penetration testing across AWS, Azure, and On-Premise environments
  • At least 5 years of recent experience (within the last 6 years) in applying IT security concepts, methodologies, principles, procedures and using industry-standard IT security tools (e.g. Burp Suite, Metasploit, Wireshark)
  • At least 5 years of recent experience (within the last 6 years) with enterprise architecture methodologies, concepts, procedures, principles, and tools
  • At least 5 years of recent experience (within the last 6 years) in contingency planning and backup and recovery best practices and application of NIST guidance in this area
  • At least 5 years of recent experience (within the last 6 years) in using technical testing tools (Tenable Security Center, ArcSight, IBM Big Fix, etc.)
  • At least 5 years of recent experience (within the last 6 years) in conducting penetration testing or the ability to bring in a penetration tester when required
  • At least 5 years of performing assessments of Federal Information Systems using the Risk Management Framework
  • Possess at least one of the following certifications or be able to obtain within six (6) months of hire: Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), GIAC Certified Incident Handler (GCIH), GIAC Systems and Network Auditor (GSNA), Electronic Commerce Council Certified Ethical Hacker (CEH), ISC2 Certified in Governance, Risk and Compliance (CGRC), Security Certified Network Professional (SCNP), Security Certified Network Architect (SCNA)
  • Proficiency in handling multiple tasks concurrently
  • Proficiency in project and time management
  • Ability to adjust to changing priorities
  • Ability to work in a cohesive team-oriented environment
  • Must be a US Citizen able to obtain and maintain a Moderate Public Trust

Preferred Qualifications

  • Knowledge of DOC, NOAA, and NWS IT security policies and implementation standards or those of similar sized organizations AND comprehensive understanding of NIST guidance to include NIST Special Publications and Federal Information Processing Standards
  • Self-starter, highly motivated individual who adapts to a dynamic work environment
  • Strong attention to detail with an ability to operate effectively across multiple priorities

Benefits

  • Competitive compensation
  • Paid vacation
  • Medical, dental, and vision insurance
  • Matching 401K plan
  • Tuition/training reimbursement
  • Long & Short-Term Disability

Similar jobs