Back to the board

Security Penetration Tester

100% remote Flexible hours Hiring now

Job Description:

  • Conduct security control assessments of the security and privacy controls implemented by an information system to determine the overall effectiveness of the controls and the vulnerability state of components, applications and databases residing within the system boundary.
  • Perform appropriate assessments on any new system developed or deployed by the customer, and conduct audits of security controls to ensure continuous monitoring of systems assigned.
  • Assess systems that have previously been assessed and received an ATO and systems that have not yet been assessed and do not have an ATO.
  • Develop, document and review System Rules of Engagement (ROE), Security Assessment Plans (SAPs) and Security Assessment Reports (SARs).
  • Have a working knowledge of the FedRAMP Penetration Guidance and Requirements.
  • Develop associated schedules and resource plans to complete the assessments.
  • Perform quality control on the assessment and associated deliverables.
  • Participate as an individual contributor for complex system assessments.
  • Develop practical and risk-based approaches for security control implementation and vulnerability remediation.
  • Work closely with ISSOs (contractors and Government) and the technical team and ensure all appropriate A&A supporting documentation is provided prior to conducting the assessment.
  • Review and provide feedback system boundaries, common controls, the security categorization of information systems, applicable security control baseline based on system categorization.
  • Conduct/participate in Security Assessment Kickoff briefings and SAR briefings.
  • Review cyber/system/network security body of evidence and documentation for accuracy and completeness.
  • Conduct security controls assessment of applicable security controls and privacy controls; assess implemented security controls and provide assurance that they are operating as intended.
  • Analyze security control findings for information systems and applications to convey weaknesses.
  • Document security assessment results accurately; read, understand, and convey vulnerabilities found during the assessments.
  • Create security assessment results and document recommendations in a SAR for remediations and security control measures.
  • Perform audits of each system and provide an authorization recommendation based on determination of risk to the customer.
  • Conduct Post Assessment Meetings with the customer.
  • Develop and maintain a schedule for conducting reoccurring Continuous Monitoring and ongoing CDM efforts once the initial assessments are complete.

Requirements:

  • 2+ years’ experience as a lead penetration tester
  • 4+ years’ experience performing security testing and/or security control assessments.
  • 4+ years’ experience with developing and documenting the ROEs, SAPs, and SARs.
  • 4+ years’ experience and expert knowledge of the NIST Cybersecurity Framework, Risk Management Framework, FIPS, and other NIST A&A publications.
  • 4+ years' of experience utilizing NIST 800-53 and 800-53A.
  • Experience conducting Penetration Tests in a commercial and or federal environment.
  • Experience assessing and providing recommendation on the following: Privacy Impact Assessment, Risk Assessment, System Security Plan, Disaster Recovery / Contingency Plan, and Incident Response Plan.
  • Knowledge of the Systems Development Life Cycle (SDLC) and its application in the development of technology solutions.
  • Knowledge and skills to perform and document the assessment.
  • Experience with tools such as Nessus, Web Inspect, Db Protect and Splunk.
  • Technical background with Windows, Unix, legacy systems, databases, web servers/applications, cloud and virtualization environments.
  • Familiar with the cloud environments (services/security) and FedRAMP A&A process.
  • Familiar with FedRAMP Penetration Testing Guidance.
  • Effective verbal and written communication skills with ability to effectively communicate with all levels of users and teammates both written and verbally.
  • Effective technical writing and documentation processing skills.

Benefits:

  • No benefits mentioned

Apply tot his job Apply To this Job

Keep exploring

Sr. Security Engineer (Penetration Testing)

100% remote Flexible hours

Information Security Analyst (Remote)

100% remote Flexible hours

Manager, Cyber Threat Intelligence Remote / Telecommute Jobs

100% remote Flexible hours

(Contractor) Senior Penetration Tester – QA Automation & Security

100% remote Flexible hours

Computer Security Specialist | Upto $90/hr

100% remote Flexible hours

Mid-Level QA Engineer- Remote

100% remote Flexible hours

Chief Threat Intelligence Officer

100% remote Flexible hours

Senior Threat Intelligence Analyst (Iran APT Focus)

100% remote Flexible hours

Remote Cyber Threat Intelligence Analyst – Entry Level Opportunity with blithequark

100% remote Flexible hours

QA Engineer - Complaint Investigation

100% remote Flexible hours

Home Infusion / IVIG RN

100% remote Flexible hours

Construction Project Manager, 2 Hour Learning (Remote) - $100,000/year USD

100% remote Flexible hours

Operations Property & Lease Compliance Coordinator, NA

100% remote Flexible hours

Experienced Data Entry Assistant - Remote / Entry Level Position at arenaflex

100% remote Flexible hours

Experienced Business Analyst – Entry-Level Business Analyst & Scrum Master Training Program

100% remote Flexible hours

Senior Treasury Specialist

100% remote Flexible hours

Experienced Part-Time Remote Data Entry Clerk – Urgent Hire at arenaflex

100% remote Flexible hours

Treasury Analyst | Remote

100% remote Flexible hours

Experienced Medical Assistant – Remote Customer Service Representative for arenaflex

100% remote Flexible hours

Experienced Live Chat Support Assistant – Remote Customer Service Representative

100% remote Flexible hours