penetration testing professional

Eliassen Group
Alexandria, VA, United States
4 days ago
Apply on www.thejobnetwork.com
Prepare application

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$156,000.0 - $176,800.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Software System Penetration Testing Bash Shell Burp Suite Cyber Security Domain Name System (DNS) Hypertext Transfer Protocols (HTTP) Python (Programming Language) Nmap Open Web Application Security Windows PowerShell Comptia Pentest+ CE
+12 more
TCP/IP Scripting Computer Network Technologies Advanced Reports GWAPT Information Technology Metasploit Complex Event Processing Nessus Web Technologies Blue Team (Cyber Security) Vulnerability Analysis

Job description

Our client seeks an experienced penetration testing professional to plan and execute comprehensive security assessments across applications, systems, and infrastructure in alignment with federal standards and industry best practices. The role will coordinate assessment scoping, develop and maintain testing procedures, conduct multi-team exercises, and produce clear reporting with prioritized remediation guidance to strengthen defensive posture and SOC effectiveness., * Coordinate and conduct Agency penetration testing on systems operated by and on behalf of NCUA, ensuring access occurs only through specified authentication methods and is limited to vetted personnel.

  • Develop, maintain, and update the Penetration Testing CONOPS and SOPs aligned to NIST guidance, applicable Federal regulations, and industry best practices.
  • Coordinate prior to each assessment to determine the appropriate assessment model and identify the technology to be tested.
  • Draft Rules of Engagement and test-specific penetration testing documentation for each engagement.
  • Perform testing and detection activities including red teaming, blue teaming, penetration testing, adversary emulation, purple teaming, and breach and attack simulation to improve SOC operations and defensive posture.
  • Document findings and vulnerabilities with risk categorization, impact evaluation, and prioritized remediation, and provide regular status updates to stakeholders.
  • Simulate APT scenarios by emulating adversary TTPs to evaluate system resilience and inform enhanced protective measures.
  • Conduct red and blue team exercises with post-exercise reviews highlighting detections and areas for improvement.
  • Execute the full assessment lifecycle including onboarding, active assessment, findings development, triage, detailed reporting, and patch validation.
  • Draft and publish reports for each penetration test including results, findings, and proposed remediation.
  • Maintain tracking of penetration testing activities across engagements.
  • Integrate penetration testing with vulnerability assessments, threat modeling, event detection evaluation, continuous monitoring tool verification, incident response, and incident reporting compliance.

Requirements

  • US Citizenship required.
  • Minimum of 5 years of experience conducting, supporting, or leading penetration tests across enterprise environments.
  • Strong understanding of Windows and Linux/Unix operating systems and core networking protocols such as TCP/IP, DNS, HTTP/S, and SMB.
  • Ability to identify, validate, and exploit vulnerabilities across networks, systems, and applications.
  • Working knowledge of web technologies and common vulnerability classes including the OWASP Top 10.
  • Proficiency with tools such as Burp Suite, Metasploit, Nmap, Nessus, and Cobalt Strike or equivalents.
  • Scripting or automation ability in Python, Bash, or PowerShell.
  • Experience performing reconnaissance, vulnerability identification, exploitation, and post-exploitation per approved rules of engagement.
  • Capability to develop and deliver findings reports that translate technical issues into business risk with prioritized remediation.
  • Strong written communication skills for clear, organized findings reports for technical and non-technical stakeholders.
  • Strong verbal communication skills to brief findings, risk ratings, and recommendations to leads, system owners, or client stakeholders.
  • Problem-solving skills and ability to work independently or as part of a team under defined timelines.
  • Sound judgment and professionalism when operating within sensitive or production environments.
  • Desirable: Experience in regulated or federal environments aligned with NIST SP 800-53, SP 800-115, and RMF processes.
  • Desirable: Familiarity with wireless and social engineering testing methodologies.
  • Clearance: Ability to obtain and maintain a Public Trust.

Education Requirements:

  • Bachelor of Science in Computer Science, Information Technology, Information Security, Cybersecurity, or related field.
  • Must hold one or more certifications: OSCP, CEH, GPEN, GWAPT, PenTest+, or eCPPT.

Benefits & conditions

Due to federal security clearance requirements, applicant must be a United States Citizen. This is a contract to hire opportunity. Applicants must be willing and able to work on a w2 basis and convert to FTE following contract duration. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance.

Rate: $75.00 to $85.00/hr. w2, Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range.W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality.If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following

About the company

About Eliassen Group: Eliassen Group is a strategic consulting firm that helps organizations reach further and achieve more through our technology, business advisory, and life sciences solutions. For nearly 40 years, we have combined exceptional people, deep domain expertise, and intelligent capabilities to expand our clients’ capacity and accelerate meaningful outcomes. We are driven by a purpose to positively impact the lives of our employees, clients, consultants, and the communities we serve. Eliassen is committed to building a diverse and inclusive team from a variety of backgrounds, perspectives, and skills. We are an Equal Opportunity and Affirmative Action Employer and all employment decisions are based on merit, performance, and business needs. Eliassen does not discriminate on the basis of race, color, gender identity or expression, sexual preference or orientation, sex (including pregnancy, childbirth, and related medical conditions), marital status

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.thejobnetwork.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · World Congress 2023

7:01 min

Initial reconnaissance and port scanning execution

Antonio De Mello +1 · LIVE

6:24 min

Common information security tools and terminologies

Antonio De Mello +1 · LIVE

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher · LIVE

9:34 min

Tracing reconnaissance footprints and path traversal execution

Antonio De Mello +1 · LIVE

51 sec

Exploring offensive security with red team tooling

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all