Senior Penetration Testing, Software Assurance and Vulnerability Assessment Engineer
Listed on 2026-08-22
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Network Security, Security Management & Operations
Senior Penetration Testing, Software Assurance and Vulnerability Assessment Engineer
Dexian Government Solutions is recruiting for a Senior Penetration Testing, Software Assurance and Vulnerability Assessment Engineer to support our proposal at the DHS CIETS in DC Metro area.
Position OverviewServes as DHS I&A's senior offensive security and technical assessment specialist. This position is responsible for identifying vulnerabilities, assessing system security posture, validating security control effectiveness, conducting penetration testing activities, evaluating software assurance risks, and providing actionable remediation recommendations across classified and unclassified environments.
Job DutiesThe Senior Penetration Testing, Software Assurance and Vulnerability Assessment Engineer provides expert support for:
- Penetration testing
- Vulnerability assessments
- Security testing and evaluation
- Software assurance analysis
- Security control validation
- Technical risk identification
- Security architecture assessment
- Remediation planning
- The position functions as the Government's senior technical assessor responsible for independently identifying weaknesses before adversaries do.
- Conduct penetration testing of DHS I&A systems and environments.
- Evaluate system resistance to cyber-attacks.
- Assess network, application, operating system, and infrastructure security.
- Perform adversarial testing activities to identify exploitable weaknesses.
- Validate effectiveness of implemented security controls.
- Document findings and recommend corrective actions.
- Conduct comprehensive vulnerability assessments.
- Analyze vulnerability scan results.
- Identify security weaknesses and misconfigurations.
- Assess severity and operational impact of vulnerabilities.
- Provide technical recommendations to reduce risk.
- Evaluate software security posture.
- Assess application security controls.
- Review software development and deployment risks.
- Identify coding and implementation weaknesses.
- Analyze software assurance findings and recommend mitigation strategies.
- Perform security testing supporting RMF activities.
- Validate implementation of technical security controls.
- Support Security Control Assessments (SCAs).
- Evaluate effectiveness of security safeguards.
- Verify compliance with security requirements.
- Assist authorization teams in assessing residual risk.
- Conduct technical security reviews of systems and architectures.
- Evaluate proposed technologies and security implementations.
- Identify engineering weaknesses affecting system security.
- Support architecture and design reviews.
- Recommend technical improvements.
- Support ongoing vulnerability management activities.
- Assess emerging risks and threat exposure.
- Review remediation progress.
- Monitor recurring findings and risk trends.
- Support continuous authorization activities.
- Analyze risks associated with identified vulnerabilities.
- Recommend risk mitigation strategies.
- Evaluate compensating controls.
- Prioritize remediation activities.
- Brief Government leadership on technical findings and risk implications.
- Coordinate with ISSOs and ISSMs regarding findings.
- Support Security Control Assessors during assessments.
- Work with system administrators and engineers to resolve vulnerabilities.
- Provide technical recommendations to system owners.
- Support Government cybersecurity leadership during audits and inspections.
- ISSOs
- ISSMs
- Security Control Assessors
- Security Risk Management Engineers
- Cybersecurity Engineers
- System Administrators
- Application Development Teams
- System Owners
The Senior Penetration Testing, Software Assurance and Vulnerability Assessment Engineer must have at least 2 years of recent experience in each of the following technical areas: software assurance, penetration testing with a range of automated tools, vulnerability assessment, security patch management, secure cloud and hybrid engineering, and CDS, for a total of at least 10 years.
Certification Requirements- Certified Ethical Hacker (CEH)
- CISSP or comparable demonstrable experience
TS/SCI with CI Polygraph
BenefitsOpen Paid Time Off, 11 Federal Paid Holidays & 5 Paid Sick Days, Company-paid Life/AD&D, Company-paid Short Term and Long-Term Disability, Health Insurance with Company Contribution, 401k Plan with Company Match, Employee Recognition Program, opportunity for Employee Referral Bonus, opportunity for annual Performance Bonus and much more!
EEO StatementDexian Government Solutions is proud to be an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All employment is decided based on qualifications, merit, and business need.
All applicants will be considered for employment without attention to race, religion, color, national…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).