Pen Tester, SME/Level 4

Arcfield, Inc.
Chantilly, VA, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Working hours
Regular working hours

Tech stack

Software System Penetration Testing Cyber Security Information Systems Networking Basics Network Protocols Comptia Pentest+ CE Scripting SARS Software Products Software Security Information Technology Vulnerability Analysis

Job description

Arcfield’s Cyber programs are expanding and currently in need of Penetration Tester (Pen Tester), Level 4 (SME) professionals to review and evaluate NRO Information Systems (IS) and recommend changes to the Government that can improve information confidentiality, integrity, and availability. Note: An offer for this position is contingent upon contract award., * Conduct basic reconnaissance and vulnerability scanning using established methodologies

  • Identify, document, and report common vulnerabilities that could be exploited
  • Perform security-focused services to improve the security posture of NRO Information Systems
  • Execute active and passive penetration testing capabilities on NRO IT assets, as per government policy and direction
  • Document findings in detailed reports for inclusion in Security Assessment Reports (SARs)
  • Support Risk Management Framework (RMF) Steps 4 and 6 processes
  • Review and write Information System Accreditation Packages (ISAPs) and Technical Information System Security Requirements (TISSRs)
  • Conduct approved testing as well as writing reports following government-approved templates
  • Complete ISAP/TISSR reports within 30 calendar days of on-site assessment completion
  • Maintain and update report templates with government approval
  • Demonstrate basic scripting abilities and understanding of network fundamentals
  • Proficiently use vulnerability scanning tools
  • Adhere to rules of engagement agreements between COMM Pen Testers and NRO Program ISO
  • Collaborate with Program Offices to determine the scope and depth of Information System testing

Requirements

  • Must be able to possess and maintain a TS/SCI clearance with Poly
  • BS 10-12 Years, MS 8-10 Years, Phd 5-7 Years
  • Bachelor/STEM with 7+yrs Relevant Experience
  • Certifications (One or more):
  • GCIH
  • GPEN
  • PenTest+
  • Basic scripting abilities
  • Basic understanding of network fundamentals
  • Basic understanding of vulnerability scanning tools
  • Expertise in:
  • Network protocols
  • Application security
  • Social engineering
  • Advanced scripting
  • Extensive knowledge of:
  • Cybersecurity frameworks
  • Industry standards
  • Advanced security tools
  • 6+ yrs-Pen Testing experience
  • Strong leadership and project management abilities
  • Excellent communication skills (both written and verbal)
  • Ability to work with both technical and non-technical stakeholders
  • Problem-solving and analytical thinking skills
  • Ability to work under pressure and manage multiple priorities

Desired

  • BS/STEM degree(s) in Computer Science, Information Technology, Cybersecurity, or a related field
  • Experience with government and military IT systems, particularly in the IC and DoD environments
  • Understanding of IC and DoD organizational structures and processes
  • Familiarity with government reporting requirements and procedures
  • Demonstrated ability to develop innovative solutions for complex technical problems
  • Recognition as an authority in information security within previous roles
  • Experience in developing and implementing security policies and procedures

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

3:45 min

Familiarizing with machine learning and neural network basics

Tillman Radmer +2 · WWC 2021

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · WWC 2023

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

2:39 min

Shifting security testing focus toward critical application logic problems

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · WWC Europe 2026

Videos

See all

Related articles

See all