Cybersecurity Penetration Tester

2 weeks ago


Arlington, Virginia, United States Guidehouse Full time
Job Family:
Cyber Consulting

Travel Required:
Up to 10%

Clearance Required:
Active Secret

The Senior Consultant will be responsible for:
  • Designing and recommending solutions across all cyber areas.
  • Creating solutions that will protect proprietary and confidential data and systems.
  • Leveraging in-depth knowledge of cyber environment to investigate, mitigate, and implement processes and procedures to correct intrusions.
  • Conducting proactive cyber risk assessments to identify previously undetected vulnerabilities or intrusions.
  • Assisting clients to manage tasks associated with network permissions, system permissions, and application permissions.
  • Implementing processes for monitoring onboarding and terminations, rights to applications, and rights and permissions to file shares across multiple operating systems and platforms.
What You Will Do:

The Senior Consultant will provide penetration testing services using a variety of tactics, techniques, and procedures to identify exploitable vulnerabilities in networks and systems. They will also measure compliance with organizational security policies, test whether staff are aware of security issues, and ultimately determine the organization's risk to cybersecurity threats.

Other responsibilities will include:
  • Performing network mapping and reconnaissance, documenting Rules of Engagement to guide the scope, developing test plan, and assisting with acquiring management approval.
  • External Testing: Conducting a variety of penetration tests based on system's criticality, test objectives, and organization's requirements to include:
  • Working with IT personnel to define scope for targeted testing; and
  • Mimicking an outside attacker to gain access to system and what information can be accessed.
  • Internal Testing: Mimicking an outside an insider attack to determine risk employees with various access levels pose to the organization.
  • Red Team Testing: Focusing testing activity towards accessing specific target datasets. Testing methodology should include crafted e-mails, custom public websites, exploit code, and social engineering.
  • Analyzing test results, developing a report on discovered vulnerabilities, and providing risk-based recommendations to remediate those vulnerabilities.
What You Will Need:
  • A current and active TS clearance OR a current and active Secret clearance with the ability to obtain a TS clearance.
  • Bachelor's degree and minimum 3-5 years of prior cybersecurity penetration testing experience.
  • One of the following certifications: Offensive Security Certified Professional (OSCP) or GIAC Penetration Tester (GPEN) or Certified Ethical Hacker (CEH) Certification.
  • Previous passing of the CISA AES HVA Assessment or ability to pass the CISA AES HVA Assessment course.
What Would Be Nice To Have:
  • Qualified as CISA-AES HVA Operator.
  • Experience supporting US government cybersecurity programs.
  • CISSP or CISM.
  • Experience managing direct client engagement team to deliver impactful support to Federal clients.
  • Experience with managing/supporting and/or knowledge of cybersecurity or high value asset program.
  • Experience conducting HVA assessment or performing Risk and Vulnerability Assessments.
  • Knowledge of Cybersecurity Framework, Risk Management, NIST Rev 5.
  • Experience developing and maintaining working relationships while serving Federal clients onsite.
  • Ability to identify obstacles and opportunities that impact the success of plans or initiatives.
  • Excellent oral and written communication and presentation skills.
  • Ability to communicate effectively and demonstrate leadership when interacting with clients and fellow team members.
What We Offer:

Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.

Benefits include:
  • Medical, Rx, Dental & Vision Insurance
  • Personal and Family Sick Time & Company Paid Holidays
  • Position may be eligible for a discretionary variable incentive bonus
  • Parental Leave and Adoption Assistance
  • 401(k) Retirement Plan
  • Basic Life & Supplemental Life
  • Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts
  • Short-Term & Long-Term Disability
  • Student Loan PayDown
  • Tuition Reimbursement, Personal Development & Learning Opportunities
  • Skills Development & Certifications
  • Employee Referral Program
  • Corporate Sponsored Events & Community Outreach
  • Emergency Back-Up Childcare Program
  • Mobility Stipend
About Guidehouse
Guidehouse is an Equal Employment Opportunity / Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, national origin, ancestry, citizenship status, military status, protected veteran status, religion, creed, physical or mental disability, medical condition, marital status, sex, sexual orientation, gender, gender identity or expression, age, genetic information, or any other basis protected by law, ordinance, or regulation.

Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.

If you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at [redacted] or via email at RecruitingA[redacted]. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation.

Guidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.

  • Arlington, Virginia, United States Rollout Systems Full time

    JSF IT -Information Assurance/Security Specialist, IAM LEVEL III on F-35 JSF ITACTIVE SECRET CLEARANCE ON DAY ONE REQUIRED. Position Description: Determines enterprise information assurance and security standards. Develops and implements information assurance/security standards and procedures. Coordinates, develops, and evaluates security programs for an...


  • Arlington, Virginia, United States Ashoka Full time

    Position Summary Ashoka is looking to add an Security Administrator to our technology team supporting operations around the world. The Security Administrator is responsible for deploying, monitoring, and maintaining security infrastructure, analyzing and responding to threats, and ensuring that Ashoka is continually improving its security practice over...

  • Network Monitor

    2 weeks ago


    Arlington, Virginia, United States Arcfield Full time

    Overview:Responsibilities:In support of the Department of Homeland Security's Cyber Security Division under the newly created Cyber and Infrastructure Security Agency, Arcfield provides specialized security services to support the Department's critical cyber programs. The National Cybersecurity Protection System (NCPS), also known as the EINSTEIN set of...


  • Arlington, Virginia, United States Two Six Technologies Full time

    Two Six Technologies is seeking an Electronics Product Design Engineer to develop new electronics products. If you have a desire to perform cutting-edge research, hardware design, and engineering for advanced embedded applications, apply today Job Responsibilities:Collaborate with an interdisciplinary team to generate designs for RF, Network, Digital, Power,...

  • Senior App Sec

    1 month ago


    Arlington, Virginia, United States Motion Recruitment Full time

    Senior App SecThis company is the United States financial watchdog that use heavy amounts of data and analytics to track every transaction on the stock market.The company is located in the D.C. Metro area, and will remain 100% remote. Required Skills & Experience:Application Security (AppSec) domain knowledge/experience, including ALL of the following:...

  • Senior App Sec

    4 weeks ago


    Arlington, Virginia, United States Motion Recruitment Full time

    Senior App SecThis company is the United States financial watchdog that use heavy amounts of data and analytics to track every transaction on the stock market.The company is located in the D.C. Metro area, and will remain 100% remote. Required Skills & Experience:Application Security (AppSec) domain knowledge/experience, including ALL of the following:...


  • Arlington, Virginia, United States Gridiron IT Solutions Full time

    GridironIT is seeking a Security Engineer local to the Arlington, VA area.100% onsite.TS/SCI is requiredThe Challenge:Everyone knows security needs to be "baked in" to a system architecture, but you actually know how to bake it in. You can identify and implement ways to harden systems and reduce their attack surface. What if you could use your cyber...


  • Arlington, Virginia, United States Rapid7 Full time

    Detection & Response AnalystWe are looking for people with a passion for investigation and forensic analysis to join our MDR SOC team at Rapid7. As a Detection & Response Analyst, you will utilize Rapid7's advanced tools to investigate and triage security events and work side-by-side Rapid7's Incident Response Consultants to investigate incidents ranging...


  • Arlington, Virginia, United States Rapid7 Full time

    Detection & Response AnalystWe are looking for people with a passion for investigation and forensic analysis to join our MDR SOC team at Rapid7. As a Detection & Response Analyst, you will utilize Rapid7's advanced tools to investigate and triage security events and work side-by-side Rapid7's Incident Response Consultants to investigate incidents ranging...


  • Arlington, Virginia, United States NTT DATA Full time

    Req ID: NTT DATA Services strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now. We are currently seeking a Power BI Processor/Developer to join our team in Arlington, Virginia (US-VA), United States (US). Job Summary: We are...


  • Arlington, United States Guidehouse Full time

    Job Family: Cyber Consulting Travel Required: Up to 10% Clearance Required: Active Secret The Senior Consultant will be responsible for: Designing and recommending solutions across all cyber areas. Creating solutions that will protect proprietary and confidential data and systems. Leveraging in-depth knowledge of cyber environment to investigate, mitigate,...


  • Arlington, United States SkyePoint Decisions Full time

    Overview: SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure and Operations, and Applications Development and Maintenance IT service provider headquartered in Dulles, Virginia with operations across the U.S. We provide innovative enterprise-wide solutions as well as targeted services addressing the complex...


  • Arlington, United States Peraton Full time

    **About Peraton** **Responsibilities** Peraton is seeking an experienced **Cyber Penetration Tester** to become part of Peraton's Department of State (DoS) Diplomatic Security Cyber Mission (DSCM) program providing leading cyber and technology security experience to enable innovative, effective and secure business processes. **Location: Arlington, VA....

  • Software Tester

    3 weeks ago


    Arlington, United States RedMatter Solutions Full time

    RedMatter Solutions is currently seeking a Software Tester - responsible for providing testing support to verify that operational capabilities and requirements are met, and defects are not introduced into the production environment to the greatest extent possible. This position can be completed on a hybrid basis. Technical and Product Skills Required -...

  • IT Security Tester

    3 weeks ago


    Arlington, United States Zermount Inc Full time

    **IT SECURITY TESTER** **MILITARY FRIENDLY & PREFERRED - HOH SPONSOR** **ESSENTIAL FUNCTIONS** - Conduct vulnerability testing and security assessments within the client's environment as defined in their IT Security Technical Testing Standard Operating Procedure (SOP) and according to best practices. - Conducts Vulnerability/Security Assessments and Audits...

  • Incident Manager

    1 month ago


    Arlington, United States Ampcus Full time

    Incident Manager - III - IMG  Hybrid in Arlington, VA - Multi Year Salaried Contract Must Have TS Clearance  Our client is supporting a Government customer to provide cybersecurity vulnerability analysis support to reduce the prevalence and impact of vulnerabilities and exploitable conditions across Federal Civilian Executive Branch (FCEB) entities...

  • Incident Manager

    1 month ago


    Arlington, United States Ampcus Incorporated Full time

    Incident Manager - III - IMG03  Hybrid in Arlington, VA - Multi Year Salaried Contract Must Have TS Clearance  Our client is supporting a U.S. Government customer to provide cybersecurity vulnerability analysis support to reduce the prevalence and impact of vulnerabilities and exploitable conditions across Federal Civilian Executive Branch (FCEB)...

  • Incident Manager

    4 weeks ago


    Arlington, United States Ampcus Incorporated Full time

    Incident Manager - III - IMG03  Hybrid in Arlington, VA - Multi Year Salaried Contract Must Have TS Clearance  Our client is supporting a U.S. Government customer to provide cybersecurity vulnerability analysis support to reduce the prevalence and impact of vulnerabilities and exploitable conditions across Federal Civilian Executive Branch (FCEB)...

  • Red Team Operator

    1 month ago


    Arlington, United States TELOPHASE Full time

    Location: Fully Remote Job Description: Performs the daily operation and execution of offensive security-related tools, processes and controls related to offensive cyber initiatives. Performs a variety of ethical hacking activities against the technical security controls and systems. Serves as technical and function SME across multiple security domain areas,...

  • Red Team Operator

    4 weeks ago


    Arlington, United States TELOPHASE Full time

    Location: Fully Remote Job Description: Performs the daily operation and execution of offensive security-related tools, processes and controls related to offensive cyber initiatives. Performs a variety of ethical hacking activities against the technical security controls and systems. Serves as technical and function SME across multiple security domain areas,...

  • Red Team Operator

    7 hours ago


    Arlington, United States TELOPHASE Full time

    Location: Fully Remote Job Description: Performs the daily operation and execution of offensive security-related tools, processes and controls related to offensive cyber initiatives. Performs a variety of ethical hacking activities against the technical security controls and systems. Serves as technical and function SME across multiple security domain areas,...


  • Arlington, United States Rollout Systems Full time

     JSF IT -Information Assurance/Security Specialist, IAM LEVEL III on F-35 JSF ITACTIVE SECRET CLEARANCE ON DAY ONE REQUIRED.  Position Description: Determines enterprise information assurance and security standards. Develops and implements information assurance/security standards and procedures. Coordinates, develops, and evaluates security programs for...

  • Cyber Sme

    2 weeks ago


    Arlington, United States SAIC Full time

    Job ID: 2405782 **Location**:ARLINGTON, VA, US **Date Posted**:2024-04-23 **Category**:Cyber **Subcategory**:Cybersecurity Ops **Schedule**:Full-time **Shift**:Day Job **Travel**:Yes, 10 % of the Time **Minimum Clearance Required**:TS/SCI **Clearance Level Must Be Able to Obtain**:TS/SCI with Poly **Potential for Remote...


  • Arlington, United States Millennium Full time

    For nearly two decades, Millennium Corporation has been operating on the leading edge of cybersecurity. Our elite team of more than 400 experts has an unparalleled record of performance supporting Red Team Operations, Defensive Cyber Operations, Software Engineering, and Technical Engineering. With the largest contingent of contracted Red Team operators in...

  • Network Monitor

    2 weeks ago


    Arlington, United States Arcfield Full time

    Overview: **Responsibilities**: In support of the Department of Homeland Security’s Cyber Security Division under the newly created Cyber and Infrastructure Security Agency, Arcfield provides specialized security services to support the Department’s critical cyber programs. The National Cybersecurity Protection System (NCPS), also known as the EINSTEIN...


  • Arlington, United States Na Ali'i Consulting & Sales, LLC. Full time

    Overview: Nakupuna Consulting is seeking a PeopleSoft (PS) Application Administrator to provide PeopleSoft environment administration, code migration management between environments, and environment troubleshooting support for the execution of a large size, multi-year contract to the Integrated Personnel and Pay System - Army (IPPS-A) Army Military Payroll...


  • Arlington, United States Ashoka Full time

    Position Summary Ashoka is looking to add an Security Administrator to our technology team supporting operations around the world. The Security Administrator is responsible for deploying, monitoring, and maintaining security infrastructure, analyzing and responding to threats, and ensuring that Ashoka is continually improving its security practice...


  • Arlington, United States Ashoka Full time

    Position Summary Ashoka is looking to add an Security Administrator to our technology team supporting operations around the world. The Security Administrator is responsible for deploying, monitoring, and maintaining security infrastructure, analyzing and responding to threats, and ensuring that Ashoka is continually improving its security practice...


  • Arlington, United States Na Ali'i Consulting & Sales, LLC. Full time

    Overview Nakupuna Consulting is seeking a PeopleSoft (PS) Application Administrator to provide PeopleSoft environment administration, code migration management between environments, and environment troubleshooting support for the execution of a large size, multi-year contract to the Integrated Personnel and Pay System – Army (IPPS-A) Army Military Payroll...


  • Arlington, United States Na Ali'i Consulting & Sales, LLC. Full time

    Overview Nakupuna Consulting is seeking a PeopleSoft (PS) Application Administrator to provide PeopleSoft environment administration, code migration management between environments, and environment troubleshooting support for the execution of a large size, multi-year contract to the Integrated Personnel and Pay System – Army (IPPS-A) Army Military Payroll...