Penetration Tester - TS/SCI with Polygraph
General Dynamics Information Technology · Bethesda, MD · Yesterday
Information Technology$172k–$233k/yrFull-time
About the role
Join GDIT as an Ethical Hacker/Penetration Tester Sr Principal and build an impactful career in enterprise IT, collaborating with people who are driven and resourceful like you.
Responsibilities
- Conduct internal penetration testing and vulnerability assessment of servers, web applications, web services, and databases
- Manually exploit and compromise operating systems, web applications, and databases
- Examine results of web/OS scanners, scans and static source code analysis
- Identify vulnerabilities, misconfigurations, and compliance issues
- Write final reports, defend all findings to include the risk or vulnerability, mitigation strategies, and references
- Ability to meet and coordinate with various audiences to include developers, system administrators, project managers, and senior government stakeholders
- Provide security recommendations for developers, system administrators, project managers, and senior government stakeholders
- Report vulnerabilities identified during security assessments
- Write penetration testing Rules of Engagements (RoE), Test Plans, and Standard Operating Procedures (SOP)
- Conduct security reviews, technical research, and provided reporting to increase security defense mechanisms
- Make recommendations to the IC CISO or designee for improving TTPS for better cyber threat protection
Qualifications
- Education: Bachelor's degree in computer engineering, Computer Science, Electrical Engineering, Information systems, Information Technology, Cybersecurity, or a closely related discipline. A Master's degree in an applicable discipline may be substituted for three years of demonstrated work experience
- Experience: 8+ years of related experience
- Security clearance level: TS/SCI with Polygraph
- US citizenship required
Desired skills
- Certifications: CEH – Certified Ethical Hacker Certification, CPT – Certified Penetration Tester
- Strong writing skills
- Experience with NIST 800-53 and Risk Management Framework
- Knowledge of system and application security threats and vulnerabilities
- Knowledge of network access, identity, and access management e.g. public key infrastructure (PKI)
- Knowledge of network protocols such as Transition Control Protocol/Internet Protocol (TCP/IP), Dynamic Host Configuration, Domain Name System (DNS), and directory Services
- Ability to assess the robustness of security systems and designs
- Knowledge of cybersecurity principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation)
- Write final reports and defend all findings, including risk or vulnerability, mitigation strategies, and references
- Report vulnerabilities identified during security assessments
- Conducted security reviews, technical research and provided reporting to increase security defense mechanisms
Pay
The likely salary range for this position is $172,144 - $232,900. Salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
Schedule
Scheduled Weekly Hours: 40. Travel Required: Less than 10%. Telecommuting Options: Onsite. Work Location: USA MD Bethesda.
This response is AI-generated, for reference only.