Job Requirements
Remote
Public Trust Polygraph not specified
Early Career (2+ yrs experience)
$65,000 - $70,000
Job Description
Remote
Our client seeks a Junior Penetration Tester to support security assessments across web applications, infrastructure, cloud environments, and related technologies connected to the client network. The role will develop test plans, perform vulnerability and risk analyses, automate testing processes, and map findings to NIST SP 800-53 controls to support compliance and strengthen security posture.
Due to federal security clearance requirements, applicant must be a United States Citizen or Permanent Resident with ability to obtain Public Trust clearance. Applicants must be willing and able to work on a w2 basis. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance.
Responsibilities
Conduct security testing of IT assets, web applications, infrastructure, mobile applications, custom software, virtual technologies, COTS products, cloud implementations, common application platforms, and other technologies connecting to or interacting with the Judiciary network.
Develop and maintain a repeatable methodology for performing security testing, including threat modeling, mapping business requirements to applicable security requirements, determining appropriate security controls, and defining test scenarios and test cases.
Develop Security Test Plans.
Perform security testing, vulnerability analysis, and risk analysis using an industry-proven, repeatable methodology.
Evaluate the effectiveness of security controls for the systems tested.
Relate test results to controls in NIST SP 800-53, as reflected in the JISF.
Develop, maintain, and use customized testing scripts to support testing automation.
Develop and deliver required reports.
Experience Requirements
Knowledge and experience with manual host testing per CIS benchmarks.
Strong knowledge of and experience with Burp Suite.
Strong knowledge of and experience with Qualys.
3+ years of experience in the information technology field.
Knowledge of and experience with Nessus.
Knowledge of OWASP Top 10.
Some penetration testing experience.
Preferred tools: Acunetix, AppDetective, DbVisualizer.
Knowledge of NIST Special Publications and NIST Risk Management Framework.
Knowledge of computer networking concepts, protocols, and network security methodologies.
Strong attention to detail.
Education Requirements
Education: Bachelor's Degree in a STEM field preferred. Certification: Industry standard certification (e.g., Security+) strongly preferred. Clearance: Ability to obtain and maintain a Public Trust required.
Our client seeks a Junior Penetration Tester to support security assessments across web applications, infrastructure, cloud environments, and related technologies connected to the client network. The role will develop test plans, perform vulnerability and risk analyses, automate testing processes, and map findings to NIST SP 800-53 controls to support compliance and strengthen security posture.
Due to federal security clearance requirements, applicant must be a United States Citizen or Permanent Resident with ability to obtain Public Trust clearance. Applicants must be willing and able to work on a w2 basis. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance.
Responsibilities
Conduct security testing of IT assets, web applications, infrastructure, mobile applications, custom software, virtual technologies, COTS products, cloud implementations, common application platforms, and other technologies connecting to or interacting with the Judiciary network.
Develop and maintain a repeatable methodology for performing security testing, including threat modeling, mapping business requirements to applicable security requirements, determining appropriate security controls, and defining test scenarios and test cases.
Develop Security Test Plans.
Perform security testing, vulnerability analysis, and risk analysis using an industry-proven, repeatable methodology.
Evaluate the effectiveness of security controls for the systems tested.
Relate test results to controls in NIST SP 800-53, as reflected in the JISF.
Develop, maintain, and use customized testing scripts to support testing automation.
Develop and deliver required reports.
Experience Requirements
Knowledge and experience with manual host testing per CIS benchmarks.
Strong knowledge of and experience with Burp Suite.
Strong knowledge of and experience with Qualys.
3+ years of experience in the information technology field.
Knowledge of and experience with Nessus.
Knowledge of OWASP Top 10.
Some penetration testing experience.
Preferred tools: Acunetix, AppDetective, DbVisualizer.
Knowledge of NIST Special Publications and NIST Risk Management Framework.
Knowledge of computer networking concepts, protocols, and network security methodologies.
Strong attention to detail.
Education Requirements
Education: Bachelor's Degree in a STEM field preferred. Certification: Industry standard certification (e.g., Security+) strongly preferred. Clearance: Ability to obtain and maintain a Public Trust required.
group id: 10106647