Senior Penetration Tester / Vulnerability Assessment Engineer

Analygence

• $120K — $145K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • BS degree in IT, Cybersecurity, Information Systems, or Computer Science, or 10 years of IT/cybersecurity experience.
  • 7+ years of experience in penetration testing or vulnerability assessment.
  • Active TS/SCI clearance and U.S. citizenship; willing to undergo a DHS polygraph.
  • Familiarity with penetration testing methodologies (MITRE ATT&CK, OWASP, PTES).
  • Knowledge of software assurance and secure code review practices.
  • Understanding of common attack vectors across network, application, and cloud layers.
  • Proficient in manual exploitation tools like Burp Suite and Metasploit.

Responsibilities

  • Perform penetration tests across the DHS IE portfolio using standard methodologies.
  • Utilize manual techniques to identify vulnerabilities missed by automated tools.
  • Validate SOC incident response procedures through controlled testing.
  • Conduct software assurance and compliance testing of software requests.
  • Perform source code reviews using both automated and manual processes.
  • Execute vulnerability assessments and supply chain risk management reviews.
  • Maintain and update the security posture of the penetration testing kit.

Benefits

  • On-site work in a secure Government SCIF environment.
  • Opportunity to work on critical national security projects.
  • Engagement with advanced penetration testing methodologies.
  • Collaboration with a skilled team in a high-stakes environment.
Full Job Description
Description

In support of this mission, we have an immediate opportunity for a Senior Penetration Tester / Vulnerability Assessment Engineer. In this role you will identify, assess, and validate vulnerabilities across DHS Intelligence Enterprise cloud and on-premise systems through penetration testing, software assurance, and vulnerability assessment. You will emphasize manual, expert-driven techniques to find what automated tools miss and validate SOC detection and response. This position is on-site in a Government SCIF in Washington, DC.

Duties include but not limited to:
  • Perform penetration tests across the DHS IE portfolio using standard methodologies (e.g., MITRE ATT&CK, OWASP), from rules of engagement through exploitation, post-exploitation, and reporting.
  • Use manual techniques to find vulnerabilities commonly missed by automated tools.
  • Validate SOC incident response procedures through controlled testing.
  • Perform software assurance through vulnerability and compliance testing of software requests; provide approval recommendations.
  • Conduct source code reviews using automated tools and manual processes.
  • Perform vulnerability assessments and supply chain risk management reviews.
  • Maintain the security posture of the penetration testing kit.
  • Update penetration testing, SCRM, and vulnerability assessment SOPs.


Requirements

  • BS degree in Information Technology, Cybersecurity, Information Systems, or Computer Science OR minimum of 10 years' experience in IT or cybersecurity.
  • Minimum of 7 years' experience in penetration testing or vulnerability assessment.
  • Active TS/SCI clearance and U.S. citizenship; willingness to undergo a DHS counterintelligence-scope polygraph.
  • Knowledge of penetration testing methodologies and frameworks (e.g., MITRE ATT&CK, OWASP, PTES).
  • Knowledge of software assurance and secure code review practices.
  • Knowledge of common attack vectors across network, application, and cloud layers.
  • Skill in manual exploitation using tools such as Burp Suite, Metasploit, or Core Impact.
  • Skill in static code analysis using tools such as SonarQube or Fortify.
  • Ability to write clear penetration test reports with recommended corrective actions.
  • Proficient in Microsoft Office Suite to include Teams or similar workplace chat and videoconferencing tools.
  • Excellent written and oral communications skills.

Desired
  • OSCP, GPEN, GWAPT, CEH, or CISSP certification.
  • Cloud (AWS, Azure) or Cross Domain Solution testing experience.

Similar Jobs

More Jobs at Analygence

More Information Technology Jobs

Find similar Senior Penetration Tester / Vulnerability Assessment Engineer jobs: