Назад
Company hidden
2 часа назад

Senior Penetration Tester (Cybersecurity)

Формат работы
remote (только USA)/hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Senior Penetration Tester (Cybersecurity): Conducting enterprise-level penetration testing and threat emulation for a government agency with an accent on web application and API security. Focus on identifying business logic flaws, developing advanced analytics, and strengthening the overall enterprise security posture.

Location: Remote, but must be able to work onsite in Alexandria, VA when directed by the customer. Must have the ability to obtain a Public Trust clearance.

Company

hirify.global provides advanced cyber network defense operations and penetration testing support to protect critical government assets from hostile adversaries.

What you will do

  • Conduct penetration testing on web applications and API databases, analyzing endpoints and authentication mechanisms.
  • Identify security weaknesses and business logic flaws in application workflows.
  • Coordinate with system owners and developers to communicate findings and support remediation efforts.
  • Draft and review technical analysis reports resulting from penetration testing.
  • Develop automated testing programs to increase efficiency of security assessments.
  • Stay current with emerging security threats, attack techniques, and mitigation strategies.

Requirements

  • Must be based in the US and have the ability to obtain a Public Trust clearance.
  • Minimum 3 years of experience in Penetration Testing, Vulnerability Management, and APT threat assessment.
  • Proficiency with Kali Linux, Metasploit, Burp Suite, and post-exploitation frameworks.
  • Strong understanding of OWASP Top 10, API Security Top 10, and common web attack vectors.
  • Familiarity with NIST and FISMA compliance standards.
  • Working knowledge of Windows Active Directory and network protocols (TCP, UDP, ICMP, BGP, MPLS).

Nice to have

  • Industry certifications such as OSCP, OSEE, CISSP, GPEN, GWAPT, or CEH.
  • Experience developing custom exploits and exploitation tools.
  • Experience with deceptive technologies like honeynets.
  • Expertise in Advanced Persistent Threat (APT) or emerging threat research.

Culture & Benefits

  • Culture driven by core values: Happiness, Helpfulness, Honesty, Humility, Hunger for excellence, and Hustle.
  • Collaborative environment focusing on mutual respect and continuous improvement.
  • Opportunity to work on high-impact national security missions.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →