Demo

IT Security Tester - SR

Zermount, Inc
Zermount, Inc Salary
Arlington, VA Full Time
POSTED ON 3/3/2025
AVAILABLE BEFORE 5/27/2025

Job Description

Job Description

IT Security Tester - SR

MILITARY FRIENDLY & PREFERRED - HOH SPONSOR

SUMMARY

The IT Security Tester - SR is responsible for identifying, assessing, and mitigating information security risks, with a particular emphasis on conducting comprehensive IT Security testing activities across the enterprise including assets, IT systems, networks, and applications. This role includes conducting vulnerability, compliance, security control, applications, and code assessments. The professional will also be responsible for the review of scan results, vulnerabilities and risks and providing mitigations and recommendations. Required to continuously update tools as needed and required. The professional is responsible for the research of risks, vulnerabilities, and new threats to keep the client updated with the latest threats. The IT Security professional is responsible for the development, updating, and automating of IT Security Hardening Guides. The IT Security professional is responsible for developing and updating documentation such as SOP.

ESSENTIAL FUNCTIONS

  • Conduct IT Security Testing within the client's environment as captured in the client's IT Security Technical Testing Standard Operating Procedure (SOP) and according to best practices.
  • The types of IT Security Testing which is expected is :

Monthly vulnerability and compliance scanning of all operating systems on servers and workstations to support Continuous Monitoring

  • Security Control Assessments (SCA) utilizing NIST SP 800-53a for systems developed and requesting production deployment
  • Ad-hoc vulnerability and compliance scanning of operating systems on servers and workstations, and databases to support Plan of Action and Milestone (POA&M) closure
  • Application Security Assessment (ASA)
  • Web Application
  • Quarterly Database scanning to support Continuous Monitoring
  • Cloud Security Testing
  • Software code analysis
  • Perform in-depth analysis on testing and assessment results, provide solutions and recommendations for remediation efforts, develop reports and conduct briefings on results.
  • Utilize scanning tools may be identified during the period of performance to support cloud-based systems or transition to other scanning tools.
  • Conduct Risk and Vulnerability Assessments, to include but not limited to :
  • Utilize a variety of toolsets with the intention of discovering, analyzing, and reporting on security flaws and vulnerabilities.

  • Conduct detailed risk assessments of the organization's IT infrastructure, systems, applications, and data.
  • Identify vulnerabilities, threats, and potential attack vectors, evaluating their impact on business operations and assets.
  • Perform assessments of the client's ability to protect its information and information systems from cyber threats by identifying, assessing, and prioritizing risks to information and information systems.
  • Supply Chain Risk Management Services
  • Development and implement strategies to manage both every day and exceptional risks along the supply chain, based on continuous risk assessment with the objective of reducing vulnerability and ensuring continuity.

  • Vulnerability Testing :
  • Perform systematic vulnerability assessments on networks, systems, and applications.

  • Utilize a range of tools and techniques to identify and analyze security weaknesses.
  • Collaborate with IT teams to remediate vulnerabilities and enhance security measures.
  • Hardening Guides (HGs) / Secure Configuration Baselines (SCBs) :
  • Develop, document, and test hardening guides for various systems and applications.

  • Ensure that HG / SCB measures align with industry best practices (e.g., CIS Benchmarks), and client specific and compliance requirements.
  • Continuously update and improve hardening guides based on new threats and vulnerabilities.
  • Update automated scanning configuration files, to automate the system and application compliance with the client's security policies.
  • Ensure compliance with relevant security standards and regulations.
  • Recommend and assist in the implementation of security improvements and best practices.
  • Continuous Monitoring :
  • Prepare detailed reports and documentation on risk assessments, vulnerability tests, and hardening strategies.

  • Monitor IT environments continuously for new threats and vulnerabilities, updating assessments and security measures as needed.
  • Engage with internal and external stakeholders, including IT teams, management, and team members.
  • QUALIFICATIONS

    Required Skill and Experience :

  • 5 years' experience in working experience in IT Security, preferably with conducting vulnerability, security control and application security testing.
  • Experience with vulnerability scanning tools and technologies.
  • Working knowledge of Security principles, techniques and technologies.
  • Strong analytical skills and efficient problem solving.
  • Working technical knowledge of IT systems, applications, services, and protocol.
  • A strong understanding of the vulnerabilities associated with network and application protocols and vulnerabilities effecting the Microsoft Windows operating system.
  • Displays technical experience with conducting research and providing review recommendations on software and technologies for vulnerabilities.
  • Experience with NIST Special Publications and guidance.
  • Self-motivated, and able to work and communicate in a team environment.
  • Excellent communication (written and verbal) skills.
  • Experience with a depth and breadth of IT Security tools and technologies, examples of technologies used are as follows :
  • Tenable, AWS Inspector, RSA Archer, Fortify, Burp Suite, Splunk, NMAP, and Core

    Education :

  • Bachelor's degree or higher in computer science, Information Technology, Information Security, or similar fields.
  • Experience maybe used in place of a degree based on approval by the PgM and client.

    Certifications :

  • At least one of the following certifications, or one equal based on DOD 8570, is required :
  • Certified Information Systems Security Professional (CISSP);

  • GIAC security certification (e.g. GCIH, GWAPT, GPEN, GSLC, etc.)
  • Work Location and Business / Core Hours :

  • Location : LOC HQ, Washington DC with remote work authorized by the COR.
  • Business : 7 : 00 am - 7 : 00 pm EST / Core Hours : 8 : 00 am - 4 : 00 pm EST
  • Ability to pass a minimum background investigation.
  • If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
    Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

    What is the career path for a IT Security Tester - SR?

    Sign up to receive alerts about other jobs on the IT Security Tester - SR career path by checking the boxes next to the positions that interest you.
    Income Estimation: 
    $65,140 - $82,070
    Income Estimation: 
    $83,010 - $104,507
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $164,835 - $201,088
    Income Estimation: 
    $135,994 - $168,063
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $77,991 - $108,747
    Income Estimation: 
    $111,725 - $147,313
    Income Estimation: 
    $112,673 - $137,290
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $70,462 - $84,818
    Income Estimation: 
    $77,991 - $108,747
    Income Estimation: 
    $87,093 - $107,335
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $111,725 - $147,313
    Income Estimation: 
    $139,945 - $168,577
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $161,209 - $233,553
    View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

    Job openings at Zermount, Inc

    Zermount, Inc
    Hired Organization Address Arlington, VA Full Time
    Job Description Job Description BUSINESS DEVELOPMENT LEAD MILITARY FRIENDLY & SKILLBRIDGE SPONSOR Zermount Inc. is seeki...
    Zermount, Inc
    Hired Organization Address Arlington, VA Full Time
    Senior Executive Assistant / Project Coordinator MILITARY FRIENDLY & PREFERRED - HOH SPONSOR Provide support for the two...
    Zermount, Inc
    Hired Organization Address Arlington, VA Full Time
    Job Description Job Description BUSINESS DEVELOPMENT SPECIALIST / CAPTURE SPECIALIST MILITARY FRIENDLY & - SKILLBRIDGE S...
    Zermount, Inc
    Hired Organization Address Arlington, VA Full Time
    BUSINESS DEVELOPMENT (BD) PROPOSAL WRITER / CYBERSECURITY ANALYST MILITARY FRIENDLY & SKILLBRIDGE SPONSOR Zermount Inc. ...

    Not the job you're looking for? Here are some other IT Security Tester - SR jobs in the Arlington, VA area that may be a better fit.

    Penetration Tester

    Gridiron IT, Fort Belvoir, VA

    AI Assistant is available now!

    Feel free to start your new journey!