> Markdown version of [/jobs/ext/2625136-senior-security-test-evaluation-analyst](https://www.wearedevelopers.com/jobs/ext/2625136-senior-security-test-evaluation-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Test & Evaluation Analyst - **Company:** Ampcus Inc - **Location:** Washington, DC, United States - **Experience:** Expert - **Salary:** $85,000.0 - $100,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Application Programming Interfaces (APIs), Data Analysis, Apple Mac Systems, Cloud Computing, Code Review, Cross-Site Request Forgery, Database Security, Linux, Networking Hardware, Network Security, Network Protocols, Web Application Security, SQL Injection, Systems Architecture, Web Applications, Network Routers, Firewalls (Computer Science), Cross Site Scripting, Vulnerability Analysis - **Published:** August 15, 2026 - **Apply:** https://www.careerjet.com/job/us06701d259bfee5f4a9bb10e563b4b94a/eaa ## About the Role * At least five years of experience performing the functions associated with this labor category., * Experience implementing comprehensive security tests that include all phases of the ethical hacking process (e.g., reconnaissance, foot printing, scanning, exploitation, and post-exploitation) and other security assessment activities (e.g., static or dynamic code review, system architecture diagram review, control evaluation) to demonstrate or emulate an adversary's ability to gain unauthorized access to sensitive data and systems that reside in either local (on-premises) or cloud computing solutions. * Experience analyzing data, identifying vulnerabilities, and developing corresponding mitigation strategies. * Experience conducting scenario-based and functional security testing during authenticated and unauthenticated testing. * Deep understanding of network protocols, configurations, security technologies, and security practices, including network security, operating system hardening, database security, and web application security for both local (on-premises) and cloud computing solutions. * Deep understanding of common vulnerabilities and attack vectors, including experience identifying and exploiting vulnerabilities in operating systems (e.g., Windows, Linux, and MacOS), network devices (e.g., firewalls, routers, and switches) and web applications and application program interfaces (e.g., SQL injection, cross-site scripting and cross-site request forgery). Certifications: * CISSP * Offensive Security Certified Professional (OSCP) * GIAC Penetration Tester (GPEN) * Equivalent ## Description * Implement comprehensive security testing to include all phases of the ethical hacking process (e.g., reconnaissance, foot printing, scanning, exploitation, and post-exploitation). * Conduct security assessment activities (e.g., static or dynamic code review, system architecture diagram review, control evaluation). * Analyze data, identify vulnerabilities, and develop corresponding mitigation strategies. * Conduct scenario-based and functional security testing during authenticated and unauthenticated testing. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Data Science in Retail](https://www.wearedevelopers.com/videos/586-data-science-in-retail) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [It's a (testing) trap! - Common testing pitfalls and how to solve them](https://www.wearedevelopers.com/videos/1193-it-s-a-testing-trap-common-testing-pitfalls-and-how-to-solve-them) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)