Penetration Tester

2 weeks ago


Washington, United States Booz Allen Hamilton Full time
Job Number: R0211100

Penetration Tester, Mid

Key Role:

Support remote testing efforts of a client‘s network to expose weaknesses in security. Maintain baseline system security according to organizational policies. Monitor and evaluate the effectiveness of the enterprise‘s cybersecurity safeguards to ensure that they provide the intended level of protection. Work with stakeholders to resolve computer security incidents and vulnerability compliance. Identify, assess, and recommend cybersecurity or cybersecurity-enabled products for use within a system and ensure that recommended products follow the organization‘s evaluation and validation requirements.

Basic Qualifications:

  • 2+ years of experience with penetration testing

  • Experience with security testing tools, such as Burp Suite, SQLMap, Nmap, Nessus, Metasploit, or Cobalt Strike

  • Experience with network, application, and external penetration testing

  • Experience creating Rules of Engagement (ROE), test plans, and scripts to aid in testing efforts

  • Experience creating Technical Assessment Reports which details findings and remediation efforts

  • Knowledge of penetration test methodology

  • Knowledge of network access, identity, and access management, such as public key infrastructure, Oauth, OpenID, SAML, and SPML

  • Ability to keep up with the latest vulnerability information sources, such as alerts, advisories, errata, and bulletins

  • Ability to obtain a Secret clearance

  • Bachelor‘s degree

Additional Qualifications:

  • Experience conducting or leading Red Team or Purple Team engagements

  • Experience conducting web application and API penetration testing

  • Experience with network hardware devices and functions, and network traffic analysis methods

  • Knowledge of defense evasion in enterprise environments and custom payload generation

  • Knowledge of incident categories, incident responses, and timelines for responses

  • Possession of excellent verbal communication and organization skills

  • GWAPT, GPEN, OSCP, CRTP, or CEH Certification

Clearance:

Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information.

Compensation

At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen‘s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.

Salary at Booz Allen is determined by various factors, including but not limited to location, the individual‘s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $60,400.00 to $137,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen‘s total compensation package for employees. This posting will close within 90 days from the Posting Date.

Identity Statement

As part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.

Work Model
Our people-first culture prioritizes the benefits of flexibility and collaboration, whether that happens in person or remotely.

  • If this position is listed as remote or hybrid, you‘ll periodically work from a Booz Allen or client site facility.
  • If this position is listed as onsite, you‘ll work with colleagues and clients in person, as needed for the specific role.

EEO Commitment

We‘re an equal employment opportunity/affirmative action employer that empowers our people to fearlessly drive change - no matter their race, color, ethnicity, religion, sex (including pregnancy, childbirth, lactation, or related medical conditions), national origin, ancestry, age, marital status, sexual orientation, gender identity and expression, disability, veteran status, military or uniformed service member status, genetic information, or any other status protected by applicable federal, state, local, or international law.



  • Washington, Washington, D.C., United States Diverse Lynx Full time

    Job Title: Cybersecurity Engineer - Penetration TesterThis role involves applying security testing methodologies to identify vulnerabilities in custom solutions, ERP integrations, and commercial off-the-shelf solutions. Key responsibilities include:• Practical working knowledge of penetration testing tools and frameworks like BurpSuite, Metasploit, and...


  • Washington, Washington, D.C., United States OneZero Solutions Full time

    About Our TeamOneZero Solutions, LLC is an employee-centric company that values team members and supports customers and missions. We pride ourselves on forward-thinking and technically proficient teams across cyber mission areas.Job ResponsibilitiesWe are seeking a Cloud Penetration Tester to perform cloud pentests and serve as the cloud pentesting SME for...

  • Penetration Tester

    4 weeks ago


    Washington, United States Editech Staffing Full time

    Job OverviewOur client is looking for an experienced Application Penetration Tester to assess the security of a cloud-native, microservices-based architecture. You will focus on web and mobile applications, cloud security testing, adversary emulation, and continuous security improvement.Key responsibilities include static and dynamic source code reviews...


  • Washington, United States Editech Staffing Full time

    Lead Application Penetration TesterOnsite / Washington, DCJob Overview Our client is seeking a highly skilled and experienced Lead Application Penetration Tester to join their dynamic team. This role is ideal for someone with a passion for cybersecurity, a deep understanding of application security, and the ability to identify and mitigate vulnerabilities....

  • Penetration Tester

    2 months ago


    washington, United States Editech Staffing Full time

    Job OverviewOur client is looking for an experienced Application Penetration Tester to assess the security of a cloud-native, microservices-based architecture. You will focus on web and mobile applications, cloud security testing, adversary emulation, and continuous security improvement.Key responsibilities include static and dynamic source code reviews...

  • Penetration Tester

    3 months ago


    Washington, United States Editech Staffing Full time

    Job OverviewOur client is looking for an experienced Application Penetration Tester to assess the security of a cloud-native, microservices-based architecture. You will focus on web and mobile applications, cloud security testing, adversary emulation, and continuous security improvement.Key responsibilities include static and dynamic source code reviews...


  • Washington, DC, United States Chenega Corporation Full time

    Intermediate Penetration Tester Hybrid Schedule: In person, in the Washington, DC office twice per week Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you looking for a career where professional development is embedded in your employer’s core culture? If so, Chenega Military, Intelligence &...


  • Washington, United States Kavaliro Full time

    Kavaliro is seeking an experienced Lead Application Penetration Tester to join our cyber security client. This role is perfect for someone passionate about cybersecurity and skilled in identifying and mitigating vulnerabilities in application security. As the lead, you'll be responsible for the security of cloud-native, microservices-based applications,...

  • QA Tester

    3 weeks ago


    Washington, United States TWO95 International Full time

    Title: QA Tester Location: Washington, DC Position: Contract Rate: $/Open Description: Test web services, web applications, APIs, mobile applications for potential vulnerabilities, Wireless penetration testing, and POS device security assessments. Run patch/configuration audit scans and create scan reports. Periodically run Host Discovery Scans, web searches...

  • QA Tester

    6 months ago


    Washington, United States TWO95 International Full time

    Title: QA Tester Location: Washington, DC Position: Contract Rate: $/OpenDescription:- • Test web services, web application, API, mobile application for potential vulnerabilities, Wireless penetration testing and POS device security assessments • Run patch / configuration audit scans, create scan report • Periodically run Host Discovery Scans, web...


  • Washington, United States Palo Alto Networks Full time

    Palo Alto Networks is seeking a seasoned cybersecurity consultant to join our team as a Principal Consultant in Offensive Security. This role offers the opportunity to work on challenging security projects, collaborate with experienced professionals, and contribute to the company's mission of creating a safer digital world.Job DescriptionWe are looking for a...


  • Washington, United States Aon Full time

    Job SummaryAs a Principal Security Penetration Tester at Aon, you will serve as a senior member of our penetration testing team. We are looking for motivated individuals to add to our team, providing a challenging and exciting work environment with a healthy combination of autonomy and senior-level support. Our team publishes books and security blogs,...


  • Washington, United States JPMorgan Chase & Co. Full time

    Assessments & Exercises Senior Associate - Red Team OperatorContribute to leading-edge security and resilience efforts, advancing protective strategies and propelling continuous improvement.As an Assessments & Exercises Senior Associate in the Cybersecurity and Technology Controls line of business, you will contribute significantly to enhancing the firm's...


  • washington, United States Editech Staffing Full time

    We are seeking a Lead Mobile Security Engineer to join a growing team! In this role, you'll lead security testing projects, conduct in-depth code reviews, and ensure mobile applications and developer workflows are secure.Benefits IncludeHealth, Vision and Dental InsuranceGenerous Paid Time Off401K MatchingCompletion of I-9, verifying US work authorization...


  • Washington, United States Editech Staffing Full time

    We are seeking a Lead Mobile Security Engineer to join a growing team! In this role, you'll lead security testing projects, conduct in-depth code reviews, and ensure mobile applications and developer workflows are secure.Benefits IncludeHealth, Vision and Dental InsuranceGenerous Paid Time Off401K MatchingCompletion of I-9, verifying US work authorization...


  • Washington, United States Tad PGS Full time

    About the RoleWe have an exceptional opportunity for a seasoned CyberArk Senior Systems Engineer to contribute to the success of the Department of Transportation (DOT). This Contract to Hire position offers an estimated salary range of $134,000 - $143,500 per year and comes with a wide range of benefits, including free career counseling services, 401(k), and...


  • Washington, United States JPMorgan Chase Full time $204,250 - $325,000

    Spearhead cutting-edge security strategies and resilience initiatives, shaping the future of cybersecurity. As an Assessments & Exercises Director in the Cyber and Tech Controls line of business, you will lead key efforts to enhance the firm's cybersecurity or resiliency posture. Plan and implement testing engagement to proactively identify risks and...


  • Washington, United States JPMorgan Chase Full time $204,250 - $325,000

    Spearhead cutting-edge security strategies and resilience initiatives, shaping the future of cybersecurity. As an Assessments & Exercises Director in the Cyber and Tech Controls line of business, you will lead key efforts to enhance the firm's cybersecurity or resiliency posture. Plan and implement testing engagement to proactively identify risks and...


  • Washington, DC, United States JPMorgan Chase & Co. Full time

    Spearhead cutting-edge security strategies and resilience initiatives, shaping the future of cybersecurity. As an Assessments & Exercises Director in the Cyber and Tech Controls line of business, you will lead key efforts to enhance the firm's cybersecurity or resiliency posture. Plan and implement testing engagement to proactively identify risks and...


  • Washington, United States JPMorgan Chase Full time $152,000 - $260,000

    Contribute to leading-edge security and resilience efforts, advancing protective strategies and propelling continuous improvement. As an Assessments & Exercises Vice President in the Cybersecurity and Tech Controls line of business, you will contribute significantly to enhancing the firm's cybersecurity or resiliency posture by using industry-standard...