user avatar

Penetration Tester

CyberCore Technologies

Today
Top Secret/SCI
$90,000 - $150,000
Polygraph
IT - QA and Test
Annapolis Junction, MD (On-Site/Office)

A Lead Penetration Tester is needed to join a high performing agile team using the Scaled Agile Framework (SAFe) methodology on a large, complex program that provides system engineering, development, test, integration and operational support. The selected individual will work on a team of cyber Subject Matter Experts (SMEs) who are providing support to a large, complex technical program for preventing, identifying, containing and eradicating cyber threats to networks through monitoring, intrusion detection, and protective security services on information systems including local area networks/wide area networks (LAN/WAN), commercial Internet connections, public facing websites, security devices, servers and workstations. She/he will be responsible for the overall security of Enterprise-wide information systems, and will collect, investigate, and report any suspected and confirmed security violations.

Primary Responsibilities
  • Perform internal and external pentests against systems to determine vulnerabilities and develop mitigation strategies.
  • Perform web app pentests.
  • Perform vulnerability risk assessments.
  • Perform physical pentests and social engineering analysis.
  • Perform cyber incident response as needed.
  • Evaluate the impact of new development on the operational security posture of IT systems.
  • Evaluate, review, and test critical software.
  • Formulate security compliance requirements for new system features.
  • Identify and remediate security issues throughout the system.
  • Audit and assess system security configuration settings using common methodologies and tools.
  • Work with development teams to enrich team-wide understanding of different types of vulnerabilities, attack vectors, and remediation approaches.
  • Work closely with System Engineering, Test Engineering, and Integration teams to ensure hardware and software architecture and implementations meet strict security requirements.
  • Propose, assess, coordinate, implement, and enforce information systems security policies, standards, and methodologies.
  • Serve as a Subject Matter Expert in security architecture, to include providing advice to Program Managers, Customer technical experts, and internal program teams.


Required Skills

  • Must have experience with penetration testing tools.
  • Must have experience in web development and programming languages such as Java, XML, Perl and HTML.
  • Must have experience with programming/scripting in Python, Powershell, C, JavaScript, etc.
  • Must have extensive experience performing IT security risk assessments.
  • Must have experience performing web app and physical pentests.
  • Must have experience with or strong familiarity of the following Web Application tools; Burp Suite, Web Inspect, Appdetective.
  • Must have experience with or strong familiarity of Kali.
  • Must have experience with or strong familiarity of IPS/IDS solutions.
  • Must have a strong understanding of the Cyber Kill Chain methodology.
  • Must have experience applying Risk Management Framework.
  • Must have experience with secure configurations of commonly used desktop and server operating systems.
  • Must have the ability to effectively collaborate with technical staff and customers to form mitigation strategies and plan for continuous modernization and legacy integration.
  • Must have experience managing multiple projects simultaneously and quickly and effectively adjusting to shifting priorities in resolving issues.
  • Active TS/SCI security clearance with a current polygraph is required


Desired Skills

  • Bachelor's degree in a technical/information assurance field and at least 12 years of relevant experience.
  • Certifications in one or more of the following areas strongly preferred:
    • GIAC Web Applications Penetration Tester (GWAPT)
    • GIAC Penetration Tester (GPEN)
    • Certified Ethical Hacker (CEH)
    • Certified Information Security Manager (CISM)
    • Certified Web Application Defender (GWEB)
    • Certified Information System Security Professional (CISSP)
  • Extensive experience developing/implementing integrated security services management processes, such as assessing and auditing network penetration testing, anti-virus planning assistance, risk analysis, and incident response.
  • Extensive experience providing information assurance support for application development that includes system security certifications and project evaluations for firewalls that encompass development, design, and implementation.


Additional Details

Published Additional Details

At CyberCore, we believe in taking care of our employees both inside and outside the workplace. Our comprehensive benefits package includes:

  • Health Insurance to ensure you and your family stay healthy and well.
  • Dental and Vision Insurance for preventive and routine care.
  • Basic Life Insurance and Disability Insurance to provide peace of mind for you and your loved ones.
  • Paid Holidays and Paid Time Off (PTO) to help you relax, recharge, and enjoy life.
  • Paid Parental Leave for new parents to focus on family.
  • Tuition Reimbursement to support your professional growth and education.
  • A 401(k) plan with a company match to help you plan for your future.


At CyberCore, we are committed to fostering a supportive and enriching environment where you can thrive both personally and professionally.

The salary range for this role is $90,000 - $150,000. This range is a good faith estimate that reflects various experience levels. At CyberCore, we consider multiple factors when determining compensation, including the specific role and its responsibilities, the candidate's professional experience, geographic location, education, and relevant skills. This range is not a guarantee of salary, as final compensation may also be influenced by contractual requirements and other considerations.

Equal Employment and Diversity

CyberCore has, on many occasions, expressed support and commitment to the principles of diversity and equal employment opportunity. It is CyberCore's policy to recruit, hire, train, and promote individuals, as well as administer all personnel actions, without regard to race, color, national or ethnic origin, pregnancy, age, religion, disability status, sex, sexual orientation, gender identity and expression, veteran status, genetic information or any other characteristic protected under applicable federal or state law. CyberCore will not tolerate unlawful discrimination, and any such conduct is prohibited. CyberCore is committed to ensuring that CyberCore's workforce and volunteers reflect America's diverse population. CyberCore knows that such diversity will enrich the company with the talent, energy, perspective, and inspiration we need to achieve our mission.
group id: 10117368
Find CyberCore Technologies on Social Media
Network Employers
user avatar
About Us
CyberCore Technologies maintains a global presence through our locally owned and operated organizations. We support the Department of Defense (DoD) in many long-term engagements throughout DoD, IC, DHS and commercial organizations for planning and successfully implementing technology projects. Our core competencies are in Value Added Reseller (VAR), Systems Integration, Professional Services and Managed Services. We deliver mission critical solutions that make a difference, by starting with our clients’ needs, collaborating closely and then creating a solution that works best for the client. Our advanced methodology safeguards our clients supply chain processes in five steps; Asset Verification, Vulnerability Identification, Risk Analysis, Mitigation and Documentation & Reporting.

CyberCore Technologies Jobs


Job Category
IT - QA and Test
Clearance Level
Top Secret/SCI