6 часов назад
Lead Penetration Tester (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Lead Penetration Tester (Cybersecurity): Leading operational security assessments and web application penetration tests across federal agencies, with an accent on FedRAMP, OWASP, NIST, and DISA STIG methodologies. Focus on developing test plans, prioritizing risks through criticality matrices, producing evidence-based reports, and presenting findings to CIO and CISO-level leadership.
Location: Fort Collins, Colorado; Kansas City, Missouri; or Washington, DC, United States. Travel to agency sites is required as needed.
Company
builds and delivers federal technology using a product-oriented approach focused on speed, ownership, and execution.
What you will do
- Lead approximately 6–7 operational security assessments annually across federal agencies.
- Conduct approximately 3–4 web application security assessments per year using OWASP methodology.
- Develop test plans, assessment objectives, scopes, timelines, and rules of engagement.
- Build criticality matrices, prioritize findings, and author evidence-based security assessment reports.
- Present technical findings and remediation guidance to agency CIO, CISO, and senior leadership audiences.
- Provide FedRAMP-qualified penetration testing support for cloud service authorization activities.
Requirements
- Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent experience.
- At least 5 years of hands-on penetration testing experience, including leadership of assessments in federal environments.
- Active Secret clearance required.
- CISA AES Assessment Lead or Technical Lead certification required, or actively in progress.
- FedRAMP penetration testing experience required.
- Experience with the ISC Security Assessment Methodology, OWASP, NIST SP 800 series, DISA STIG, federal rules of engagement, test plans, criticality matrices, reporting, and executive presentations.
Nice to have
- GPEN, GXPN, OSCP, GWAPT, or equivalent offensive security certifications.
- Experience leading CISA AES assessments across multiple federal civilian agencies.
- Familiarity with FedRAMP High, Moderate, and Low authorization boundaries.
- Red Team or adversary emulation experience.
- Cloud-native security assessment experience with AWS, Azure, GCP, or GovCloud, or an active TS/SCI clearance.
Culture & Benefits
- Flexible schedules and teleworking options.
- Medical insurance, including HSA-eligible plans.
- Employer-paid dental, vision, short-term disability, long-term disability, and life insurance options.
- 5% 401(k) company matching, paid holidays, PTO accrual, and paid parental leave.
- Professional development, career growth opportunities, and company events.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →