Senior Cybersecurity Penetration Tester
Listed on 2025-12-25
-
IT/Tech
Cybersecurity, Information Security, Data Security, IT Consultant
Senior Cybersecurity Penetration Tester – ASRC Federal
ASRC Federal is a leading government contractor furthering missions in space, public health and defense. As an Alaska Native owned corporation, our work helps secure an enduring future for our shareholders. We are a top veteran employer and Certified Great Place to Work™.
We actively hire a Senior Cybersecurity Penetration Tester for our Defense Counterintelligence Security Agency (DCSA) program based in Quantico, VA. Remote flexibility available – telework offered with a requirement to be onsite up to two days a week at Quantico Marine Corps Base VA.
Position DescriptionThe Cybersecurity Penetration Tester is a hands‑on technical role responsible for conducting simulated attacks on systems and networks to identify vulnerabilities and weaknesses that could be exploited by malicious actors. The role requires a deep understanding of security principles, hacking techniques, and attack methodologies. The Penetration Tester will plan, execute, and document penetration tests, provide recommendations for remediation, and contribute to the overall improvement of the organization’s security posture.
Minimum Requirements- 5–7 years of experience in security principles such as attack frameworks, threat landscapes, and attacker tactics, techniques and procedures.
- Proven experience conducting penetration tests of web applications, networks, and other systems.
- Experience with a variety of penetration testing tools and techniques (Rapid7 Nexpose, Appspider Pro, Metasploit, Cobalt Strike, Burp Suite, etc.).
- Active Top‑Secret Clearance REQUIRED, eligible to be upgraded to TS/SCI.
- Bachelor’s Degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- Must meet 8570 certification requirements at the time of hire. IAT II Information Assurance Baseline (e.g., CASP+ CE, CCMP Security, CISA, CISSP, GCED, GCIH, Security+ CE or CCSP). A CSSP Auditor cert is preferred (e.g., CEH, CySA+, CISA, GSNA, CFR or Pen Test).
- Penetration Testing:
- Conduct penetration tests of web applications, mobile applications, networks, cloud environments, and other systems.
- Utilize a variety of tools and techniques to identify vulnerabilities including SQL injection, cross‑site scripting (XSS), buffer overflows, and other common attack vectors.
- Perform reconnaissance to gather information about target systems and networks.
- Develop and execute exploit code to demonstrate the impact of identified vulnerabilities.
- Bypass security controls and evade detection.
- Vulnerability Assessment:
- Perform vulnerability assessments using automated scanning tools and manual techniques.
- Analyze scan results to identify false positives and prioritize vulnerabilities.
- Develop custom scripts and tools to automate vulnerability assessment tasks.
- Reporting and Documentation:
- Document all findings in detailed reports, including descriptions of vulnerabilities, methods used to exploit them, and recommendations for remediation.
- Present findings to stakeholders, including technical teams and management.
- Create and maintain documentation on penetration testing methodologies, tools, and techniques.
- Remediation Support:
- Provide guidance and technical assistance to system owners and developers on vulnerability remediation.
- Validate remediation efforts to ensure vulnerabilities have been properly addressed.
- Conduct retests to verify the effectiveness of implemented security controls.
- Research and Development:
- Stay up‑to‑date on the latest security threats, vulnerabilities, and attack techniques.
- Research and evaluate new penetration testing tools and methodologies.
- Develop custom tools and scripts to enhance penetration testing capabilities.
- Contribute to the development of security policies and procedures.
- Collaboration:
- Collaborate with other cybersecurity professionals, including security architects, incident responders, and security engineers.
- Share knowledge and expertise with team members.
- Participate in security training and awareness programs.
- Ethical Hacking:
- Conduct all penetration testing activities in a legal and ethical manner, adhering to established rules of engagement.
- Protect the confidentiality…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).