Job Requirements
Washington, DC
Public Trust Polygraph
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries
Job Description
Job Description
Tharros supports the Department of Homeland Security (DHS) with cybersecurity services across its Intelligence Enterprise.
In support of this mission, we have an immediate opportunity for a Senior Penetration Tester / Vulnerability Assessment Engineer. In this role you will identify, assess, and validate vulnerabilities across DHS Intelligence Enterprise cloud and on-premise systems through penetration testing, software assurance, and vulnerability assessment. You will emphasize manual, expert-driven techniques to find what automated tools miss and validate SOC detection and response. This position is on-site in a Government SCIF in Washington, DC.
Duties include but not limited to:
Requirements
Desired
Summary
Tharros combines extensive cyber defense knowledge with the world's preeminent vulnerability expertise to identify and defend against attacks before they become problems. Working at mission speed, we harden mission systems faster and secure them for longer, so agencies never lose the mission edge. Tharros lifts the veil of enterprise cybersecurity to detect zero days before they affect you, enabling mission maneuverability and the confidence to move missions forward.
In the ever-evolving realm of cyberspace, we are dedicated to becoming the paramount defender in the 5th warfighting domain. By pioneering innovative security solutions and fostering an environment of continuous learning and vigilance, we aim to protect the interests of our nation's security. Our commitment to excellence in cybersecurity will establish new benchmarks, transforming the digital landscape into a secure and thriving frontier for future generations.
Tharros. See Everything. Secure Anything.
Tharros is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Opportunity/Affirmative Action Employer and make employment decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected status.
Tharros supports the Department of Homeland Security (DHS) with cybersecurity services across its Intelligence Enterprise.
In support of this mission, we have an immediate opportunity for a Senior Penetration Tester / Vulnerability Assessment Engineer. In this role you will identify, assess, and validate vulnerabilities across DHS Intelligence Enterprise cloud and on-premise systems through penetration testing, software assurance, and vulnerability assessment. You will emphasize manual, expert-driven techniques to find what automated tools miss and validate SOC detection and response. This position is on-site in a Government SCIF in Washington, DC.
Duties include but not limited to:
- Perform penetration tests across the DHS IE portfolio using standard methodologies (e.g., MITRE ATT&CK, OWASP), from rules of engagement through exploitation, post-exploitation, and reporting.
- Use manual techniques to find vulnerabilities commonly missed by automated tools.
- Validate SOC incident response procedures through controlled testing.
- Perform software assurance through vulnerability and compliance testing of software requests; provide approval recommendations.
- Conduct source code reviews using automated tools and manual processes.
- Perform vulnerability assessments and supply chain risk management reviews.
- Maintain the security posture of the penetration testing kit.
- Update penetration testing, SCRM, and vulnerability assessment SOPs.
Requirements
- BS degree in Information Technology, Cybersecurity, Information Systems, or Computer Science OR minimum of 10 years' experience in IT or cybersecurity.
- Minimum of 7 years' experience in penetration testing or vulnerability assessment.
- Active TS/SCI clearance and U.S. citizenship; willingness to undergo a DHS counterintelligence-scope polygraph.
- Knowledge of penetration testing methodologies and frameworks (e.g., MITRE ATT&CK, OWASP, PTES).
- Knowledge of software assurance and secure code review practices.
- Knowledge of common attack vectors across network, application, and cloud layers.
- Skill in manual exploitation using tools such as Burp Suite, Metasploit, or Core Impact.
- Skill in static code analysis using tools such as SonarQube or Fortify.
- Ability to write clear penetration test reports with recommended corrective actions.
- Proficient in Microsoft Office Suite to include Teams or similar workplace chat and videoconferencing tools.
- Excellent written and oral communications skills.
Desired
- OSCP, GPEN, GWAPT, CEH, or CISSP certification.
- Cloud (AWS, Azure) or Cross Domain Solution testing experience.
Summary
Tharros combines extensive cyber defense knowledge with the world's preeminent vulnerability expertise to identify and defend against attacks before they become problems. Working at mission speed, we harden mission systems faster and secure them for longer, so agencies never lose the mission edge. Tharros lifts the veil of enterprise cybersecurity to detect zero days before they affect you, enabling mission maneuverability and the confidence to move missions forward.
In the ever-evolving realm of cyberspace, we are dedicated to becoming the paramount defender in the 5th warfighting domain. By pioneering innovative security solutions and fostering an environment of continuous learning and vigilance, we aim to protect the interests of our nation's security. Our commitment to excellence in cybersecurity will establish new benchmarks, transforming the digital landscape into a secure and thriving frontier for future generations.
Tharros. See Everything. Secure Anything.
Tharros is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Opportunity/Affirmative Action Employer and make employment decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected status.
group id: 10518809