Demo

Penetration Tester

Cyber Management International Corporation
Arlington, VA Full Time
POSTED ON 4/1/2025
AVAILABLE BEFORE 5/31/2025

Job Title: Penetration Tester(s)
Location: Arlington, VA
Terms: Full-time
Requirements: Must be a U.S. Citizen with Active Security Clearance

About the Role
Multiple junior to senior level roles available for Penetration Testers in the Red Cell Team. Red Cell is a penetration-testing program that conducts independent testing to ensure appropriate controls and safeguards are in place and function as intended for the Department’s networks, assets and data.

Responsibilities

  • Assess the current state of the customer’s system security by identifying all vulnerabilities and security measures.
  • Help customer perform analysis and mitigation of security vulnerabilities.
  • Perform and report on penetration testing of systems, including cloud, to satisfy the NIST 800-53 CA-8 security control and using methodologies that may include, NIST SP 800-115, Penetration Testing Execution Standard (PTES), and Information Systems Security Assessment Framework (ISSAF).
  • Stay abreast of current attack vectors and unique methods for exploitation of computer networks. Provide support to incident response teams through capability enhancement and reporting.
  • Assist in maintaining Red Cell infrastructure.
  • Develop or modify tools that automate discovery or exploitation (e.g. bash, Python, JavaScript, PowerShell).

Qualifications: Basic Requirements

  • Bachelor of Science and up to 5 years of relevant experience in Cyber/IT, or a Master's of Science and 3 years of relevant experience in Cyber/IT. In lieu of a degree, 4 years of additional IT security or penetration testing experience may be considered.
  • Possess one of the following certifications, OR be able to obtain before start date:
  • CCNA Cyber Ops, CCNA-Security, CEH, CFR, Cloud , CySA , GCIA, GCIH, GICSP, SCYBER, Security CE, SSCP
  • Demonstrated experience with Kali Linux.
  • Demonstrated penetration testing tools experience with Nmap, Burp Suite, Metasploit, etc.
  • Demonstrated ability in evaluating vulnerabilities, performing root cause analysis, and reporting findings utilizing assessment methodologies such as NIST SP 800-115, Penetration Testing Execution Standard (PTES), Information Systems Security Assessment Framework (ISSAF), OWASP Web Security Testing Guide (WTG), etc.
  • Demonstrated ability to lead a penetration test and guide Senior/Junior Penetration Testers.
  • U.S. citizenship required.
  • An active Secret security clearance.
  • Must have the ability to obtain a final Top Secret security clearance.

Preferred Requirements

  • One of the following certifications or an alternate, verifiable certification demonstrating IT security competence:
  • CompTIA CASP
  • ISC2 Certified Information Security Professional (CISSP)
  • ISC2 Certified Cloud Security Professional (CCSP)
  • ISC2 Information Systems Security Engineering Professional (ISSEP)
  • One of the following certifications or an alternate, verifiable certification demonstrating practical penetration testing competence:
  • Offensive Security Certified Professional (OSCP)
  • Offensive Security Certified Professional (OSCP)
  • Hack the Box Certified Penetration Testing Specialist (CPTS)
  • TCM Security Practical Network Penetration Tester (PNPT)
  • GIAC Exploit Researcher and Advanced Penetration Tester (GXPN)
  • Zero Point Security Red Team Ops II
  • Advanced understanding of the following:
  • NIST Risk Management Framework (RMF) and the Assessment and Authorization (A&A) process.
  • Security principles such as CIA, IAAAA, access control models, risk management, etc.
  • Networking principles and technologies such as IP routing, TCP/UDP, VPNs, firewalls, NAT, etc.
  • Common network protocols such as SSH, FTP, SMTP, SMB, HTTP, etc.
  • Operating system principles such as process management, device management, user management, file systems, etc.
  • Data processing principles such as encoding, hashing, encryption, etc.
  • Scripting and programming languages such as Bash, Python, PowerShell, JavaScript, etc.
  • Common application vulnerabilities and exploits such as outdated components,
  • permissions misconfigurations, lack of input validation, logging/monitoring failures, etc.
  • Common web application vulnerabilities and exploits such as XSS, SQLi, LFI, file uploads, broken authentication mechanisms, etc.
  • Active Directory (AD) enumeration and attacks such as kerberoasting, AS-REP roasting, abusing misconfigured privileges, crafting golden tickets, etc.
  • Public Key Infrastructure (PKI) and navigating IT environments implementing multifactor authentication.
  • Cloud technologies and platforms such as Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (GCP), etc.

About us

Cyber Management International Corporation is actively recruiting highly IT Security professionals looking for challenging, exciting work in support of the U.S. Department of State (DOS). Specifically, our customer is the Bureau of Diplomatic Security (DS), Directorate of Cyber and Technology Security (CTS). DS/CTS is a center of excellence that brings together cybersecurity, technology security, and investigative expertise as a unified security capability focused on solving critical and emerging issues enabling the State Department to fulfill its vital global mission.

Target Salary Range: $70,000 - $110,000

For more information about our company, please visit www.cybermgt.com or email us at recruiting@cybermgt.com

Job Type: Full-time

Pay: $70,000.00 - $110,000.00 per year

Benefits:

  • 401(k)
  • 401(k) matching
  • Dental insurance
  • Health insurance
  • Life insurance
  • Paid time off
  • Vision insurance

Schedule:

  • Day shift
  • Monday to Friday

Security clearance:

  • Secret (Required)

Ability to Commute:

  • Arlington, VA 22209 (Required)

Work Location: In person

Salary : $70,000 - $110,000

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Penetration Tester?

Sign up to receive alerts about other jobs on the Penetration Tester career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$92,729 - $118,963
Income Estimation: 
$118,965 - $150,754
Income Estimation: 
$92,729 - $118,963
Income Estimation: 
$118,965 - $150,754
Income Estimation: 
$157,357 - $212,690
Income Estimation: 
$196,356 - $280,529
Income Estimation: 
$76,865 - $99,440
Income Estimation: 
$92,729 - $118,963
Income Estimation: 
$118,965 - $150,754
Income Estimation: 
$141,372 - $178,696
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Cyber Management International Corporation

Cyber Management International Corporation
Hired Organization Address Arlington, VA Full Time
Job Title: Sr Policy Strategist/Architect and Cybersecurity Engineer Location: Arlington, VA Terms: Full-time Requiremen...

Not the job you're looking for? Here are some other Penetration Tester jobs in the Arlington, VA area that may be a better fit.

Penetration Tester

Cymertek, Tysons, VA

Penetration Tester

Cymertek, Chantilly, VA

AI Assistant is available now!

Feel free to start your new journey!