Cloud Penetration Tester
Role details
Job location
Tech stack
Job description
Department of Homeland Security (DHS), Customs and Border Protection (CBP) Security Operations Center (SOC) is a US Government program responsible to prevent, identify, contain and eradicate cyber threats to CBP networks through monitoring, intrusion detection and protective security services to CBP information systems including local area networks/wide area networks (LAN/WAN), commercial Internet connection, public facing websites, wireless, mobile/cellular, cloud, security devices, servers and workstations. The CBP SOCis responsible fortheoverall security of CBP Enterprise-wide information systems, and collects, investigates, and reports any suspected and confirmed securityviolations., * Conduct penetration testing activities aligned withCBPand industry best practices.
- Performinternal and externalweb application, network, and infrastructurepentestassessments using commercial and open-source tools.
- Execute testing operations safely andin accordance withdefined operational guidelines.
- Produce detailed reports outlining findings and actionable remediation recommendations.
- Partner with SOC, engineering, and security teams tovalidateand remediate vulnerabilities.
- Support tool development,methodologyimprovements, and team-wide knowledge sharing.
- Assistin verifying Bug Bounty findings and remediations, Must have the following experience with1-3 of the tools listed below:
- Kali Linux
- Metaspoilt
- Burp suite pro
- Cobalt Strike /Sliver
- Tenable Nessus
- Tenable Security Center
- Bloodhound
- BladeRF/HakRF
- Hak5 equipment
- Wireshark /tcpdump
- Prowler
- Scoutsuite
Requirements
Weareseekinga highly skilled and experienced Penetration Tester to join our team supportingtheCBP SOC. Thiscandidate willbe responsible forconducting comprehensive security assessmentsofCBPFISMAsystems with the purpose ofidentifyingvulnerabilities and providing actionable recommendations to enhance the security posture of CBP's critical systems and networks. This role requires a deep understanding of offensive cybersecurity techniques, strong analytical capabilities,detailed report writing skillsand the ability to workas part of a team., * Bachelors' degree from an accredited college in a related discipline, or equivalent experience/combined education, with4years of professional experience; or 2 years of professional experience with a Masters' degree.
- 3 years in Pen Testing and Vulnerability Assessment, with specific emphasis on web application and enterprise network environments.
- 3 years of professional experience in incident detection and response, malware analysis, or cyber forensics.
- Must be able to work in the office in Ashburn, VA 2-5 days per week as required by the customer.
- Must have a US Citizenship to be considered for this position due to the customer clearance required.
- Must be able to obtain and maintain a CBP BI Public Trust clearance prior to start.
Must have the specific experience1-3 yearsin at least 1of the following specialties:
- Networkpentesting
- Web applicationpentesting
- Active directorypentesting
- Mobile applicationpentesting
- Cloud infrastructurepentesting
- RFpentesting, * OSCP
- GPEN
- CRTO
- OSWP
- GWAPT
- AWS Solutions Architect Associate
Clearance: In addition to specific security clearance requirements all CBP SOC employeesare required tosuccessfully complete a CBP Background Investigation to support this program
Preferred Qualifications:
- CISSP
- GISF
- GXPN
- OSCE
- OSEE
- AWS Certified Security - Specialty
- Certified Kubernetes Administrator (CKA)
- Ability to brief seniorgovernment leadershiponpentestingrequirements and results
- Red Team operator experience
- Experience creating and updating SOPs
- Analytical and Problem-Solving Skills
- Communication Skills
Benefits & conditions
Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits .