Penetration Tester (hybrid)
Posted Updated
Overview
- Tier One Technologies is seeking a Penetration Tester to support our US Government client.
- This hybrid contract-to-hire position can be originated in Falls Church, VA; Raleigh, NC or Eagan, MN.
- SELECTED CANDIDATES WITHOUT REQUIRED CLEARANCE WILL BE SUBJECT TO A FEDERAL GOVERNMENT BACKGROUND INVESTIGATION TO RECEIVE IT.
Responsibilities
- Monitor and optimize network performance to ensure reliability and efficiency.
- Develop and maintain accurate network documentation, diagrams, and configurations.
- Identify and mitigate vulnerabilities affecting network switches.
- Provide support for firewall and load-balancing technologies.
- Collaborate with other IT teams to develop and implement integrated system solutions.
- Prepare regular progress reports documenting project status, milestones, and key updates.
Qualifications
- A degree from an accredited College/University in the applicable field of services is required. If the individual's degree is not in the applicable field, then 4 additional years of related experience is required.
- 8+ years of IT-related work experience.
- Highly skilled in web application testing, API testing, and network testing.
- Prior experience with Burp Suite Professional, or other similar DAST tools.
- Experience with AI and penetration testing AI.
- Experience with Kali Linux and most of the tools available in the distro for penetration testing.
- Experience with tools such as Metasploit Pro and Cobalt Strike for red team operations.
- Experience with Red Team engagements from planning to execution.
- Experience with phishing network users to gain access for lateral movement on the network.
- Experience with Purple Team engagements to test monitoring controls in coordination with engineering teams and CSOC teams.
- Proficiency in scripting, such as Python and/or PowerShell.
- Experience with penetration testing supporting PCI-DSS.
- Technical writing skills, along with ease in communicating concepts related to security vulnerabilities and attack path scenarios.
- Familiar with OWASP Application Security Verification Standard (ASVS) and MITRE ATT&CK framework.
- Penetration testing certification recommended. Acceptable certifications: Offensive Security Certified Professional (OCSP), Global Information Assurance Certification (GIAC) Certifications (e.g., GIAC Certified Penetration Tester (GPEN), GIAC Web Application Penetration Tester (GWAPT), or GIAC Exploit Researcher and Advanced Penetration Tester (GXPN)).
- Exceptional communication skills.
- Ability to obtain Public Trust Clearance.
- Must be a US Citizen or Permanent Status Green Card holder.
- Must have lived in the US for the past 5 years.
- Cannot have more than 6 months travel outside the United States within the last five years. Military Service excluded. (Exception does not include military family members.)