Vulnerability Assessment & Penetration Testing Specialist - Level III
Listed on 2026-08-08
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Network Security
Vulnerability Assessment & Penetration Testing Specialist Level III
Full-Time/Part-Time Full-Time
Description
The Vulnerability Assessment & Penetration Testing Specialist - Level III serves as the senior technical expert responsible for planning, executing, and leading advanced penetration testing, vulnerability assessments, software assurance, and cyber supply chain risk management activities across the Department of Homeland Security (DHS) Intelligence Enterprise (DHS IE). This role performs comprehensive security assessments of enterprise networks, cloud environments, applications, operating systems, and Cross Domain Solutions (CDS) using industry-recognized methodologies and advanced manual testing techniques.
The specialist leverages frameworks such as MITRE ATT&CK, OWASP, NIST, and industry best practices to identify vulnerabilities that may not be detected by automated tools. The position also supports software assurance initiatives through secure code reviews, application security testing, and Supply Chain Risk Management (SCRM) activities to strengthen the cybersecurity posture of DHS IE systems.
Working closely with Security Operations Center (SOC) personnel, Cybersecurity Engineers, Information System Security Officers (ISSOs), Information System Security Managers (ISSMs), developers, and Government stakeholders, the Vulnerability Assessment & Penetration Testing Specialist provides expert recommendations to reduce enterprise cyber risk while ensuring compliance with Federal, DHS, and Intelligence Community (IC) cybersecurity requirements.
Key Responsibilities
- Lead and conduct comprehensive penetration testing engagements for DHS Intelligence Enterprise systems, networks, applications, cloud environments, and infrastructure.
- Perform penetration testing using industry-recognized methodologies, including:
- MITRE ATT&CK Framework
- OWASP Web Security Testing Guide
- NIST penetration testing guidance
- PTES (Penetration Testing Execution Standard)
- Plan and execute all phases of penetration testing, including:
- Pre-engagement planning
- Rules of Engagement (ROE)
- Threat intelligence gathering
- Threat modeling
- Vulnerability identification
- Exploitation
- Post-exploitation analysis
- Reporting and remediation recommendations
- Utilize advanced manual testing techniques to identify vulnerabilities that are not detectable through automated scanning tools.
- Perform network, web application, wireless, cloud, and infrastructure penetration testing using ethical hacking techniques while ensuring no disruption to production environments.
- Validate Security Operations Center (SOC) detection and incident response capabilities through controlled adversary emulation and red team testing.
- Assess logging, monitoring, detection, and response mechanisms to identify gaps in defensive capabilities.
- Perform software assurance reviews by conducting security and compliance testing of software requests and applications prior to deployment.
- Review Software Assurance Request Forms and provide technical adjudication and security recommendations.
- Conduct vulnerability assessments of enterprise systems and deliver comprehensive Security Assessment Reports (SARs) and Vulnerability Assessment Reports (VARs) within established service-level agreements.
- Perform Supply Chain Risk Management (SCRM) and Cyber Supply Chain Risk Management (C-SCRM) assessments for software, hardware, and third‑party technologies supporting DHS IE.
- Conduct secure source code reviews using both automated and manual analysis techniques to identify software vulnerabilities and coding weaknesses.
- Utilize static application security testing (SAST), dynamic application security testing (DAST), and software composition analysis (SCA) tools to evaluate software security.
- Maintain the penetration testing toolkit, ensuring monthly software updates, quarterly configuration reviews, and compliance with approved security baselines.
- Develop comprehensive penetration testing reports documenting:
- Testing methodology
- Attack paths
- Exploited vulnerabilities
- MITRE ATT&CK mappings
- Risk ratings
- Technical findings
- Executive summaries
- Remediation recommendations
- Develop and maintain Standard Operating Procedures (SOPs) supporting penetration testing, software assurance, vulnerability assessment, and SCRM activities.
- Collaborate with cybersecurity engineering, Dev Sec Ops , cloud engineering, and system administration teams to remediate identified vulnerabilities.
- Support cybersecurity audits, security assessments, authorization activities, and continuous monitoring initiatives.
- Participate in cybersecurity working groups and provide technical guidance on emerging threats, offensive security techniques, and vulnerability management best practices.
Minimum Qualifications
- Active Top Secret/Sensitive Compartmented Information (TS/SCI) security clearance.
- Minimum 7-10 years of experience performing penetration testing, vulnerability assessments, software assurance, and offensive cybersecurity activities within Federal Government or Intelligence…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).