DataLock Consulting Group logo
DataLock Consulting GroupPosted 9 months ago

Security Penetration Tester

RemoteUnited States

Full TimeAssociates DegreeSmall

Job Summary

Develop, document, and review System Rules of Engagement, Security Assessment Plans, and Security Assessment Reports while performing security control assessments of information systems to determine control effectiveness and vulnerability states. Conduct audits of security controls using NIST 800-53A, analyze findings to convey weaknesses, and create SARs with remediation recommendations. Perform quality control on deliverables, participate in kickoff and briefing meetings, and conduct post-assessment meetings with customers to provide authorization recommendations based on risk determinations.

Required Qualifications

  • 2+ years' experience as a lead penetration tester
  • 4+ years' experience performing security testing and/or security control assessments
  • 4+ years' experience with developing and documenting the ROEs, SAPs, and SARs
  • 4+ years' experience and expert knowledge of the NIST Cybersecurity Framework, Risk Management Framework, FIPS, and other NIST A&A publications
  • 4+ years' of experience utilizing NIST 800-53 and 800-53A
  • Experience conducting Penetration Tests in a commercial and or federal environment
  • Experience assessing and providing recommendation on the following: Privacy Impact Assessment, Risk Assessment, System Security Plan, Disaster Recovery / Contingency Plan, and Incident Response Plan
  • Knowledge of the Systems Development Life Cycle (SDLC) and its application in the development of technology solutions
  • Knowledge and skills to perform and document the assessment
  • Experience with tools such as Nessus, Web Inspect, Db Protect and Splunk
  • Technical background with Windows, Unix, legacy systems, databases, web servers/applications, cloud and virtualization environments
  • Familiar with the cloud environments (services/security) and FedRAMP A&A process
  • Familiar with FedRAMP Penetration Testing Guidance
  • Effective verbal and written communication skills with ability to effectively communicate with all levels of users and teammates both written and verbally
  • Effective technical writing and documentation processing skills
  • BS/BA degree in Information Technology or related cyber/cyber-security field
  • Must possess one of the following certifications: Cisco Certified Network Professional CCNP / Security, CompTIA Advanced Security Practitioner (CASP+), Certified Information Systems Security Professional (CISSP), Certified Secure Software Lifecycle Professional (CSSLP), CISSP-Information Systems Security Engineering Professional (CISSP-ISSEP), SANS GIAC Penetration Tester (GPEN), Open Web Application Security Project Penetration Tester (OWASP), GIAC Certified Enterprise Defender (GCED), Certi...

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce