Назад
Company hidden
3 дня назад

Vulnerability Assessment Analyst and Penetration Tester (CA)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Vulnerability Assessment Analyst and Penetration Tester (CA) (Cybersecurity): Delivering continuous cyber assessments, penetration tests, security tools, and threat mitigation plans with an accent on manual assessment of systems, services, software, applications, and network infrastructure. Focus on automating repetitive testing tasks, identifying vulnerabilities beyond static analysis, improving penetration testing capabilities, and mentoring engineers on complex assessments.

Location: Camp Pendleton, California, in the San Diego area; onsite

Company

Federal contractor supporting a newly awarded Department of Defense program.

What you will do

  • Perform manual security assessments of systems, services, software, operating systems, web applications, and network infrastructure.
  • Conduct application and hardware penetration testing beyond vulnerabilities identified by static analysis tools.
  • Help ensure services, applications, and websites meet high security standards.
  • Automate repetitive testing tasks and build tools to improve penetration testing efficiency.
  • Create threat mitigation plans and help influence responses to identified threats.
  • Mentor and lead engineers delivering complex penetration tests and vulnerability assessments.

Requirements

  • Must be a US citizen due to government requirements.
  • Must hold an active DoD Secret clearance.
  • Five years of hands-on penetration testing experience across operating systems, web applications, and network infrastructure.
  • Experience with operating system security and knowledge of Windows and Linux Server administration.
  • Competence with testing frameworks and tools including Burp Suite, Metasploit, Cobalt Strike, Kali Linux, Nessus, and PowerShell Empire.
  • Knowledge of network defense technologies, including ACLs, firewalls, IDS/IPS, antivirus/EDR, and web content filtering, plus strong written and verbal communication skills.

Nice to have

  • Administrator-level knowledge of Windows and Linux Server operating systems.

Culture & Benefits

  • Opportunity to support a newly awarded DoD program.
  • Role includes mentoring and technical leadership responsibilities.

Hiring process

  • Possess OSCP, OSWA, GWAPT, or GPEN certification upon onboarding.
  • Obtain GXPN, OSEP, OSWE, or another listed advanced penetration testing certification within nine months of onboarding.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →