IT Security Specialist - Penetration Tester

ATTAINX INC
Birmingham, AL, United States
3 days ago
Apply on www.jofdav.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$125,000.0
Working hours
Regular working hours
Job source

Tech stack

Adobe InDesign Amazon Web Services Software System Penetration Testing Microsoft Azure Burp Suite Communications Protocols Cyber Security Information Systems Federal Information Processing Standards (FIPS) Firmware Information Systems Security Architecture Professional Software Architecture
+6 more
ArcSight SIEM Tool Wireshark Virtualization Technology Metasploit Cybercrime Hardware Infrastructure

Job description

We are searching for Penetration Tester to support Security Assessment and Authorization initiatives for our Government client. Job duties include:

  • Protocol analysis, vulnerability discovery and exploitation, post exploitation impact analysis, and physical security.
  • Highly technical problem-solver who understands software architectures, security, communication protocols, virtualization, and hardware, and work with other engineers to the resolution of problems in design, development, and operations.
  • Perform manual and automated firmware analysis on target devices.
  • Perform pen tests, fuzzing and custom exploit attacks against client systems.
  • Review deployment architectures, topologies and conops for compliance regulatory security mandates.
  • Produce security reports suitable for submission to regulatory bodies.
  • Conduct hands-on technical testing beyond automated tool validation, including full exploitation and leveraging of access within multiple environments.
  • Conduct scenario-based security testing, or red teaming to identify gaps in detection and response capabilities of client end systems.
  • Conducting research and testing in support of client requirements.
  • Designing, implementation, and integration of security solutions.
  • Designing, development and support of the company’s line of technology products.
  • Analyzes information security systems and applications.
  • Recommends and develops security measures to protect information against unauthorized modification or loss.
  • Familiar with a variety of the field’s concepts, practices, and procedures.
  • Relies on experience and judgment to plan and accomplish goals.
  • Performs a variety of complicated tasks.

Requirements

Are you a seasoned penetration tester with a passion for uncovering vulnerabilities and securing complex systems? We’re looking for a highly skilled and experienced professional with a minimum of 5 years of proven expertise in penetration testing and ethical hacking to join our team. In this role, you’ll take a hands-on approach to identify, exploit, and report security weaknesses across diverse environments, including AWS, Azure, and on-premises infrastructure. Your work will directly contribute to fortifying critical systems and protecting sensitive data from evolving cyber threats.

If you thrive in dynamic, high-stakes environments and excel at devising creative solutions to complex security challenges, we want to hear from you. Join us in our mission to build a safer digital future., * A minimum of 5 years of proven penetration testing and ethical hacking experience.

  • Hands-on experience in penetration testing across AWS, Azure, and On-Premise environments.
  • At least 5 years of recent experience (within the last 6 years) in applying IT security concepts, methodologies, principles, procedures and using industry-standard IT security tools (e.g. Burp Suite, Metasploit, Wireshark).
  • At least 5 years of recent experience (within the last 6 years) with enterprise architecture methodologies, concepts, procedures, principles, and tools.
  • At least 5 years of recent experience (within the last 6 years) in contingency planning and backup and recovery best practices and application of NIST guidance in this area.
  • At least 5 years of recent experience (within the last 6 years) in using technical testing tools (Tenable Security Center, ArcSight, IBM Big Fix, etc.).
  • At least 5 years of recent experience (within the last 6 years) in conducting penetration testing or the ability to bring in a penetration tester when required.
  • At least 5 years of performing assessments of Federal Information Systems using the Risk Management Framework.
  • Possess at least one of the following Certifications or be able to Obtain within six (6) months of hire:
  1. Certified Information Systems Security Professional (CISSP).
  2. Certified Information Systems Auditor (CISA).
  3. GIAC Certified Incident Handler (GCIH).
  4. GIAC Systems and Network Auditor (GSNA).
  5. Electronic Commerce Council Certified Ethical Hacker (CEH).
  6. ISC2 Certified in Governance, Risk and Compliance (CGRC).
  7. Security Certified Network Professional (SCNP).
  8. Security Certified Network Architect (SCNA).
  • Proficiency in handling multiple tasks concurrently.
  • Proficiency in project and time management.
  • Ability to adjust to changing priorities.
  • Ability to work in a cohesive team-oriented environment.
  • Must be a US Citizen able to obtain and maintain a Moderate Public Trust., * Knowledge of DOC, NOAA, and NWS IT security policies and implementation standards or those of similar sized organizations AND comprehensive understanding of NIST guidance toinclude NIST Special Publications and Federal Information Processing Standards.
  • Self-starter, highly motivated individual who adapts to a dynamic work environment.
  • Strong attention to detail with an ability to operate effectively across multiple priorities.

Education / Experience:

Ideal for candidates with 5-7 years of hands-on penetration testing experience who are looking to advance into intermediate-level roles.

Benefits & conditions

We are proud to offer competitive compensation and benefits packages to include paid vacation, medical, dental, vision, matching 401K plan, tuition/training reimbursement, and Long & Short-Term Disability., $125,000.00

About the company

AttainX Inc. is SBA Certified 8(a), Women Owned Small Business (WOSB), Economically Disadvantaged WOSB (EDWOSB), CMMI Level 3, ISO 9001:2015 certified QMS and Silver Level SaFe Partner. For more than 12 years, AttainX, Inc. has delivered emergent technologies, software products, and high-quality services that meet the needs of our Federal Government customers.

The last 4 years have shown significant company growth as we have increased our contracts portfolio and hold the “Best in Class” contract vehicles, GSA MAS and OASIS Small Business and 8(a) Pools 1, 2 and 3. In addition, we are prime on several Agency Specific IDIQ’s and BPA’s with the National Oceanic and Atmospheric Administration, Department of Energy, Navy, Health and Human Service and the Defense Intelligence Agency.

AttainX is dedicated to quality and best practices for the services we provide. We understand our people are the key ingredient to ensuring our customers Mission and Goals are met with excellence.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.jofdav.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

3:19 min

Setting up a vulnerable test application and monitoring environment

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2024

2:19 min

Orchestrating over-the-air firmware updates for vehicle modules

Denis Grahovac · World Congress 2021

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · World Congress 2023

2:20 min

Utilizing custom firmware for variable torque manipulation

Daniel Meilak Daniel Meilak +1 · World Congress 2026 Europe

2:39 min

Shifting security testing focus toward critical application logic problems

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

Videos

See all

Related articles

See all