> Markdown version of [/jobs/ext/552149-cyber-security-analyst](https://www.wearedevelopers.com/jobs/ext/552149-cyber-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Analyst - **Company:** Ampcus Inc - **Location:** Fairfax County, VA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Bash Shell, Burp Suite, Cloud Engineering, Cyber Security, Information Systems, Computer Networks, Computer Forensics, Cross-Site Request Forgery, Linux, Perl (Programming Language), VMware ESX Servers, Fuzz Testing, Python (Programming Language), Kali Linux, Network Security, Open Source Technology, Open Web Application Security, Windows PowerShell, Phishing, Ruby, Single Sign-On, SQL Injection, System Programming, TCP/IP, Virtualization Technology, Web Applications, Scripting, Computer Networking Systems, Cloud Platform System, Malware, Cross-Site Scripting (XSS), Metasploit, Nessus - **Published:** June 15, 2026 - **Apply:** https://diversityjobs.com/career/9021598/Cyber-Security-Analyst-Virginia-Chantilly ## About the Role * 4-5 years of experience in related field * Demonstrated real-world experience performing grey and black box penetration testing. * Must be proficient in exploiting common web application vulnerabilities like XSS, CSRF, Command Injection, SQLi, single sign-on bypass, etc. * Must be proficient in any of the following: PowerShell Empire, Metasploit Framework, Cobalt Strike, Burp Suite, Canvas, Kali Linux, A/V evasion methodologies, Exploit Dev. * Must have solid working experience and knowledge of Windows operating systems (incl. Active Directory), Linux operating systems; VMware ESXi or similar; mobile platforms are a plus. * Solid understanding of networking, TCP/IP, virtualization and cloud architecture. * Strong familiarity with some of the following: OWASP top 10, DoD and NSA Vulnerability and Penetration Testing Standards. * Knowledge of exploitation concepts including phishing and social engineering tactics, buffer overflows, fuzzing, SQLi, MiTM, covert channels, secure tunneling and open-source exfiltration techniques. * Experience with Linux, Windows, wireless, and virtual platforms * Knowledge of information security policies and guidance * Proactive interest in emerging technologies and techniques related to penetration testing Preferred Skills and Qualifications * Experience with IOT device is a plus * Certifications such as CEH or OSCP * Malware analysis or digital computer forensics experience is a plus * Scripting (Windows/*nix), Bash, Python, Perl or Ruby, Systems Programming is a plus ## Description * Perform recon on applications and networks * Perform penetration testing and system exploitation against desktops, servers, applications, operating systems, and security systems to gain root and administrator access for highly specialized network systems * Perform internal and external pentest against systems to determine vulnerabilities and offer mitigation strategies * Perform reconnaissance, privilege escalation persistence, lateral movement, and payload generation against information systems * Analyze vulnerabilities, delivering clear and coherent written reporting, identifying network risks, and providing mitigation recommendations * Conduct penetration and malicious user testing in Cloud environments, including Amazon Web Services (AWS), Azure, and on-premise systems * Translate systems and applications into security test plans, performing hands-on security testing and leveraging adversarial tactics * Must be able to use at least two of the following proficiently and instruct others on them: Nessus, Burp, Metasploit, and the Social Engineering Toolkit. * Researches and maintains proficiency in tools, techniques, countermeasures, and trends in computer network vulnerabilities, data hiding and network security and encryption * Ability to assist with researching and evaluating security policies and guidance * Ability to train other team members on security concepts * Excellent communication skills ## Related Videos - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)