Vulnerability Assessment & Penetration Testing Specialist — Level III
About the role
RiVidium Inc. is seeking an experienced Vulnerability Assessment & Penetration Testing Specialist - Level III to serve the team for all Cybersecurity and Intelligence Enterprise Information Technology Services (CIEITS) program activities. The Vulnerability Assessment & Penetration Testing Specialist - Level III serves as the senior technical expert responsible for planning, executing, and leading advanced penetration testing, vulnerability assessments, software assurance, and cyber supply chain risk management activities across the Department of Homeland Security (DHS) Intelligence Enterprise (DHS IE).
Responsibilities
The specialist will perform comprehensive security assessments of enterprise networks, cloud environments, applications, operating systems, and Cross Domain Solutions (CDS) using industry-recognized methodologies and advanced manual testing techniques. The position also supports software assurance initiatives through secure code reviews, application security testing, and Supply Chain Risk Management (SCRM) activities to strengthen the cybersecurity posture of DHS IE systems.
- Lead and conduct comprehensive penetration testing engagements for DHS Intelligence Enterprise systems, networks, applications, cloud environments, and infrastructure.
- Perform penetration testing using industry-recognized methodologies, including MITRE ATT&CK Framework, OWASP Web Security Testing Guide, NIST penetration testing guidance, and PTES (Penetration Testing Execution Standard).
- Utilize advanced manual testing techniques to identify vulnerabilities that are not detectable through automated scanning tools.
- Validate Security Operations Center (SOC) detection and incident response capabilities through controlled adversary emulation and red team testing.
- Assess logging, monitoring, detection, and response mechanisms to identify gaps in defensive capabilities.
- Perform software assurance reviews by conducting security and compliance testing of software requests and applications prior to deployment.
- Conduct vulnerability assessments of enterprise systems and deliver comprehensive Security Assessment Reports (SARs) and Vulnerability Assessment Reports (VARs) within established service-level agreements.
- Perform Supply Chain Risk Management (SCRM) and Cyber Supply Chain Risk Management (C-SCRM) assessments for software, hardware, and third-party technologies supporting DHS IE.
Requirements
- Active Top Secret/Sensitive Compartmented Information (TS/SCI) security clearance.
- Minimum 7-10 years of experience performing penetration testing, vulnerability assessments, software assurance, and offensive cybersecurity activities within Federal Government or Intelligence Community environments.
- Current Certified Ethical Hacker (CEH) certification.
- Current Certified Information Systems Security Professional (CISSP) certification.
- Expert knowledge of MITRE ATT&CK Framework, OWASP Testing Methodology, OWASP Top 10, NIST Cybersecurity Framework, and Penetration Testing Execution Standard (PTES).
- Demonstrated experience with penetration testing and vulnerability assessment tools such as Burp Suite Professional, Nessus / ACAS, Nmap, Metasploit Framework, Wireshark, Kali Linux, WebInspect, and Nikto.
Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Software Engineering, Information Systems, or a related technical discipline.
- Minimum 2 years of experience in each of the following: Software Assurance, Penetration Testing, Vulnerability Assessment, Patch Management, Secure Cloud and Hybrid Cloud Security Engineering.
- Experience performing secure code reviews and identifying application security vulnerabilities.
Skills
- Offensive Security Certified Professional (OSCP) certification (preferred).
- GIAC Penetration Tester (GPEN) certification (preferred).
- Experience conducting penetration testing of Cross Domain Solutions (CDS) and classified information systems (preferred).
- Experience supporting DHS Intelligence & Analysis (I&A) or other Intelligence Community cybersecurity programs (preferred).
- Familiarity with DISA Security Technical Implementation Guides (STIGs), container security (Docker, Kubernetes), Kubernetes security, serverless application security, and secure DevSecOps pipelines (preferred).