Penetration Tester Job at Shedd RS, Washington DC

d1ZtRnJGOG40S005SnBwQjlQblozUUd3T0E9PQ==
  • Shedd RS
  • Washington DC

Job Description

We are looking for a Penetration Tester to join our client’s team on an upcoming Security and Privacy Assessment project in the non-profit telecommunications industry. The Pen Tester will complement risk assessments as ongoing defense against technical security threats of weakness exploitation for the same systems.

This role is hybrid remote with some in-person support required at the customer's location in Washington, DC. This is a direct hire position with a salary range of $120-150k.

Responsibilities Include:
  • Penetration Testing:
    • Conduct annual penetration testing of IT Systems.
    • Ad hoc penetration testing as assigned for targeted applications, subsystems, or in response to emerging threats.
    • Penetration testing for ATO-oriented assessments and ISPCM-oriented assessments.
    • Conduct additional penetration tests as requested to accommodate schedules or ongoing authorization status for an authorized system, as required.
  • Vulnerability Assessment:
    • Analyze and assess potential security risks and vulnerabilities.
    • Conduct vulnerability scans and risk assessments on a variety of platforms.
  • Reporting and Documentation:
    • Document and report findings with clear and actionable recommendations.
    • Prepare detailed penetration testing reports and executive summaries.
  • Security Recommendations:
    • Provide expert guidance on remediation strategies to mitigate identified vulnerabilities.
    • Collaborate with IT and development teams to implement security improvements.
  • Security Research:
    • Stay updated with the latest security trends, threats, and technology developments.
    • Research new attack vectors and develop new testing methodologies.
  • Compliance and Best Practices:
    • Ensure compliance with industry standards and regulations (e.g., PCI-DSS, GDPR, HIPAA).
    • Advocate for security best practices across the organization.
    • Perform testing for OWASP Top Ten
  • Training and Mentorship:
    • Mentor junior penetration testers and provide training to staff on security awareness.
    • Conduct workshops and training sessions to promote security knowledge.
Required Skills, Qualifications, and Experience:
  • Certifications:
    • Must have and maintain at least one of the following current certifications: GIAC Penetration Tester ("GPEN"), Certified Ethical Hacker ("CEH"), CompTIA PenTest+, or Licensed Penetration Tester Master ("LPT").
  • Experience:
    • Minimum of 5 years of professional experience in penetration testing and ethical hacking.
    • Proven track record of conducting successful penetration tests.
  • Technical Skills:
    • Proficiency in using penetration testing tools (e.g., Burp Suite, Metasploit, Nmap).
    • Strong understanding of network protocols, operating systems, and web application security.
    • Experience with scripting languages (e.g., Python, Bash) for automation of tasks.
    • Knowledge of various security frameworks and standards (e.g., OWASP, NIST).
  • Soft Skills:
    • Excellent problem-solving skills and analytical thinking.
    • Strong communication skills, both written and verbal.
    • Ability to work independently and as part of a team.
Preferred Qualifications:
  • Experience in a similar role within a large enterprise or consulting environment.
  • Familiarity with cloud security testing (e.g., AWS, Azure).
  • Experience with mobile application security testing.
  • Advanced knowledge of social engineering techniques.
  • Experience developing Penetration Testing documents, such as scoping documents, ROE and reports.
  • Proficiency in Python programming.
  • Experience in leading internal and external pen tests.
  • Experience in all phases of the Penetration Testing Process.
  • Experience with numerous pen testing tools (Nmap, Burp, curl, wget, Nessus, Nikto, SQLMAP etc.).
  • Experience with database scanning tools.
  • Experience with web application scanning tools.
  • Experience with phishing tools.
  • The ability to write compelling documentation.

Job Tags

Remote job,

Similar Jobs

Vets Hired

Front Desk Grad School Receptionist Job at Vets Hired

 ...Description A regionally accredited private nonprofit career university provides educational programs at the undergraduate and graduate levels for a diverse student body. The main campus is in Fort Lauderdale with campuses located throughout the State of Florida and... 

Healthcare Recruitment Counselors

Physical Medicine and Rehab / Sports Med Physician Salisbury MD Job at Healthcare Recruitment Counselors

Physical Medicine and Rehab / Sports Med Physician Salisbury MD We are seeking a compassionate Physical Medicine and Rehab OR Sports Medicine Physician to join our medical practice in the Salisbury and Cambridge, MD area. We value our patients and truly want to listen... 

Integrity Locums

Physician / Pain Management / Ohio / Locum tenens / Neurology Locums Need in Ohio Job Job at Integrity Locums

 ...Friday ~8a-5p ~ days of week will vary ~ Possible tele-medicine hybrid in office Clinical Details Record a patients medical...  .../Neck Pain/Back Pain/ Musculoskeletal Injuries/ Joint Pain/ Sports-Related Injuries/ Movement Disorders/Nerve Pain/Facial Pain/... 

Gecko Hospitality

Assistant General Manager - Hotel Job at Gecko Hospitality

 ...Job Title: Hotel Assistant General Manager Position Overview: Take on an exciting leadership role where youll drive exceptional guest experiences, support daily operations, and collaborate closely with the General Manager. This role is critical in ensuring operational... 

Excellence Community Schools

Certified Classroom Teacher -Elementary (NY)-SY 24-25 Job at Excellence Community Schools

 ...educating our scholars is implemented by a collaborative team of teachers. Who We Need: We are seeking individuals who are...  ...qualifications. Health Insurance, dental, vision & 403b Retirement Plan Paid Time Off/Paid Sick Leave/Parental Leave/FMLA...