
Penetration Tester
Posted 16 hours ago

Posted 16 hours ago
This is a fully remote position, open to applicants in Texas.
• Conduct penetration testing across client environments utilizing black box, white box, web application, and mobile methodologies in accordance with NIST standards.
• Independently oversee engagements from initial scoping through final reporting while ensuring quality standards are met.
• Generate technical reports detailing findings, risk context, and actionable remediation recommendations for both technical and executive audiences.
• Assist in mobile application security evaluations for iOS and Android platforms, employing OWASP MASVS/MSTG guidelines.
• Engage in strategic planning and management within the domains of cybersecurity and digital forensics in line with the NICE Framework.
• Address security challenges related to architectures, firewalls, electronic data traffic, and network access.
• Investigate, assess, and recommend security tools, techniques, and technologies.
• Utilize COTS/GOTS and custom tools to scan, identify, contain, mitigate, and rectify vulnerabilities and intrusions.
• Design, develop, and implement security solutions across enterprise engagements.
• Present technical findings and associated business risks to developers, CISOs, and various clients.
• Serve as a spokesperson and advisor on advanced technical projects and research initiatives.
• Collaborate with senior management to formulate strategic plans and objectives.
• Share expertise, enhance internal tools and methodologies, and help address practice skill gaps.
• Monitor emerging vulnerabilities, attack techniques, and developments within the industry.
• Bachelor’s degree with nine (9) or more years of experience; Master’s degree with seven (7) or more years of experience; PhD or JD with four (4) or more years of relevant experience.
• Additional experience may be considered in lieu of a degree.
• Must be a US Citizen.
• Capable of passing a CJIS Criminal Justice background investigation and maintaining CJIS clearance throughout employment.
• Advanced technical proficiency in cybersecurity and digital forensics.
• Strong working knowledge of OWASP WSTG and OWASP Top 10, including vulnerability detection and exploitation.
• Proficient with Burp Suite Pro, FFUF, SQLMap, and Nuclei.
• Familiarity with mobile application testing concepts and tools, such as Frida, Objection, MobSF, and ADB.
• Demonstrated experience in red-teaming, ethical hacking, and cloud security architecture.
• Proficiency in malware reverse engineering and enterprise cyber architecture.
• Strong background in security concerns involving architectures, firewalls, electronic data traffic, and network access.
• Experience in researching, evaluating, and recommending security tools and technologies.
• Proficient in using COTS/GOTS and custom tools for vulnerability management.
• Ability to produce professional, client-ready penetration test reports with minimal revisions required.
• GWAPT certification is required or strongly preferred; OSCP, OSWE, or GWEB certifications will also be considered.
• Preferred: hands-on experience with iOS and/or Android application assessments.
• Preferred: understanding of API security testing with REST, GraphQL, and SOAP.
• Preferred: exposure to source code review in white box engagements.
• Preferred: experience presenting findings to client stakeholders and senior leadership.
• Preferred: experience in strategic planning, addressing complex technical challenges, providing consultative direction, managing advanced technical projects, and facilitating organizational decision-making.
• Equal Opportunity Employer.
• Intentional growth opportunities.
• Chance to make a visible impact on client and team outcomes.
• Opportunities for knowledge-sharing and improvement of internal tools and methodologies.
QTS Data Centers
SAIC
High 5 Games
Venbrook
Get handpicked remote jobs straight to your inbox weekly.