Penetration Tester with Security Clearance

Found in: Dice One Red US C2 - 6 days ago


Beltsville, United States SAIC Full time

Description SAIC is seeking a highly motivated Penetration Tester. The successful candidate will provide support to the Cybersecurity Integrity Center (CIC) in the Department of State Bureau of Information Resource Management (IRM). Duties are in the Washington, D.C. metropolitan area (30% in downtown D.C; 70% in Beltsville, MD. The CIC supports cybersecurity monitoring, threat analysis, incident response, and infrastructure remediation within and across all of the State Department's information technology (IT) infrastructure. The CIC coordinates and collaborates with other State Department bureaus as well as other organizations within the Federal Government, and commercial partners. The position allows hybrid remote work. Team is currently reporting onsite 3 days per week or more as needed. Description of Duties The Penetration Tester will provide support for HVA Assessments using methodology by Cybersecurity and Infrastructure Security Agency (CISA) Assessment Evaluation and Standardization (AES) program with broad and in-depth knowledge to conduct offensive cyber operations across the organization globally. In this role, you will conduct offensive security operations to emulate adversary tactics and procedures to test preventative, detective, and response controls across the global technology landscape. The Penetration Tester will: * Conduct highly complex offensive security operations testing consistent with known adversary tactics techniques and procedures and contribute to the development of objectives and approaches taken to remediate risk. * Apply sound technical and management principles to identify and remediate cybersecurity --vulnerabilities across the State Department global IT enterprise infrastructure. * Apply organizational and process change principals. * Evaluate system performance results, perform risk assessments, and evaluate performance metrics. Responsibilities include: * Provide ad-hoc penetration testing and assessment services on Department of State systems identified by the leadership. * Develop, Identify and resolve security vulnerabilities related to deployment and testing processes. * Streamline and optimize processes and procedures in order to rapidly remediate vulnerabilities from cybersecurity threats. * Collaborate with Department and external cyber stakeholders on cybersecurity technology implementations to meet specific operational needs. * Perform technical evaluations of recommended vulnerability mitigation actions and make recommendations based on impact and/or other countermeasures. * Develop strategies for CIC cyber defense technologies, ensuring integration and alignment for continued operation. * Conduct assessments of threats and vulnerabilities; determine deviations from acceptable configurations, enterprise, or local policy; assess the level of risk; and develop and/or recommend appropriate mitigation countermeasures in operational and non-operational situations. * Network Mapping include but are not limited to a network map of the organization's system that includes a visual representation of the organization's physical devices and digital network. * Perform operation and maintenance activities in support of existing CIC cyber tools and technologies (MSV, Qualys, Tenable Nessus and others). * Identify, diagnose, and prioritize anomalies in cyber defense infrastructure and resources. * Perform cybersecurity testing of developed applications and/or systems. * Identify and direct the remediation of technical problems encountered during testing and implementation of new systems. * Document security issues and impacts identified through offensive operations in a clear and concise manner to facilitate reporting to impacted stakeholders. * Provide guidance and recommendations to stakeholders responsible for security remediation actions to close identified gaps and remediation validation testing. * Independently handle complex issues with minimal supervision, while escalating only the most complex issues to appropriate staff. Qualifications Required Education & Experience * Bachelor's and five (5) years or more experience; Master's and three (3) years or more experience. * A degree in Cybersecurity or related field. * 4-6+ years penetration testing experience. * Web application penetration testing, LPT, Source code vulnerability analysis, serious problem-solving skills experience. * All penetration testers/operators must be DHS/CISA AES qualified within 90 days of onboarding. Required Clearance * US Citizenship. * Active Top Secret Clearance Desired * 4 years Microsoft Operating Systems (OS) engineering and support experience focusing on Active Directory (AD), System Center Configuration Manager (SCCM), System Center Operations Manager (SCOM). * 4-6 years Network penetration testing experience. * In-depth experience in planning, implementing, and managing large/global enterprise infrastructures. * Familiarity of various analytical tools (Splunk, USBDeview, Netwitness, MimiKatz). * Understanding of Security Information and Event Management (SIEM) tools (Splunk, McAfee). * Familiarity of Cobalt Strike, Nessus, Kali Linux, Burp Suite, Nmap and OpenVAS for databases. * Knowledge of general attack stages. * Skill in the use of social engineering techniques and using penetration testing tools. * Familiarity with OMB, NIST, DHS, and related security guidelines and directives. * Interpersonal skills including the ability to collaborate effectively, and excellent written and oral communications. * Network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth). * Server/endpoint OS (Microsoft, Linux, IOS) along with mobile and cloud technologies. * Cloud application security, Vulnerability Management and Security Information, and Event Management capabilities. * Countermeasures / mitigations to identified cybersecurity risks. * Knowledge of network protocols such as TCP/IP, Dynamic Host Configuration Protocol (DHCP), domain name system, and directory services. * Certifications: LPT (Licensed Penetration Testers, Microsoft Certifications (MCSE, MCSA, MCSD),OSCP (Offensive Security Certification Professional), ISACA Certified Information Systems Auditor (CISA), SCP Security Certified Network Architect (SCNA), ISACA Certified Information Security Manager (CISM) SAIC accepts applications on an ongoing basis and there is no deadline. Covid Policy: SAIC does not require COVID-19 vaccinations or boosters. Customer site vaccination requirements must be followed when work is performed at a customer site.



  • Beltsville, United States CareerBuilder Full time

    You will need to login before you can apply for a job. Cyber Security Engineer with Security Clearance Cyber Security Engineer Technical Skills with 7 Years of experience Cribl Splunk Enterprise Azure We are looking for a certified Cribl resource with a Splunk Enterprise and Splunk Enterprise Security background. Azure experience is a bonus. The candidate...

  • Network Technician with Security Clearance

    Found in: Dice One Red US C2 - 6 days ago


    Beltsville, United States SAIC Full time

    Description SAIC has an opportunity for a hybrid Network Technician in Beltsville, MD! The team currently reports onsite 3 days/week. The current shifts available are: * Nights: Tuesday-Saturday 10:30pm-7:00am * Days: Sunday-Thursday 6:30am-3:00pm Description of Duties * Responsible for installing, monitoring, operating, managing, troubleshooting and...

  • Cyber Engineer Senior with Security Clearance

    Found in: Dice One Red US C2 - 6 days ago


    Beltsville, United States SAIC Full time

    Description SAIC is seeking a highly motivated Senior Cyber Engineer. The successful candidate will provide support to the Cybersecurity Integrity Center (CIC) in the Department of State Bureau of Information Resource Management (IRM). Duties are in the Washington, D.C. metropolitan area (30% in downtown D.C; 70% in Beltsville, MD). The CIC supports...

  • Windows Service Desk Technician with Security Clearance

    Found in: Dice One Red US C2 - 2 weeks ago


    Beltsville, United States TENAX Technologies Full time

    TENAX Technologies is currently seeking a Windows-based Service Desk Technician to provide Tier 2 technical support in Beltsville, MD. The IT Service Desk Technician will provide high-level service to end-users while troubleshooting advanced hardware, software, and network issues. The ideal candidate must possess excellent customer service skills and the...

  • Windows Service Desk Technician with Security Clearance

    Found in: Dice One Red US C2 - 4 days ago


    Beltsville, United States TENAX Technologies Full time

    TENAX Technologies is currently seeking a Windows-based Service Desk Technician to provide Tier 2 technical support. The IT Service Desk Technician will provide high-level service to end-users while troubleshooting advanced hardware, software, and network issues. The ideal candidate must possess excellent customer service skills and the ability to...

  • Network Operations Engineer with Security Clearance

    Found in: Dice One Red US C2 - 6 days ago


    Beltsville, United States SAIC Full time

    Description This is an opening for a Network Operations Engineer to support a Department of State (DoS) Bureau of Information Resource Management (IRM) Operation Division. This program provides transparent, interconnected systems and security supporting the DoS in successfully carrying out its U.S. foreign policy mission. The Operations Division provides...

  • Network Operations Engineer Senior with Security Clearance

    Found in: Dice One Red US C2 - 6 days ago


    Beltsville, United States SAIC Full time

    Description This is an opening for a Network Operations Engineer to support a Department of State (DoS) Bureau of Information Resource Management (IRM) Operation Division. This program provides transparent, interconnected systems and security supporting the DoS in successfully carrying out its U.S. foreign policy mission. The Operations Division provides...

  • Cybersecurity Project Manager with Security Clearance

    Found in: Dice One Red US C2 - 3 days ago


    Beltsville, United States SAIC Full time

    Description This is a Project Manager position in support of the Cybersecurity Integrity Center (CIC) in the Department of State Bureau of Information Resource Management (IRM). Duties are in the Washington, D.C. metropolitan area (30% in downtown D.C; 70% in Beltsville, MD). This project management position plans, manages, and executes IT projects for the...

  • Cyber IT Specialist

    Found in: Dice One Red US C2 - 7 days ago


    Beltsville, United States Peraton Full time

    About Peraton Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our...

  • Cybersecurity Watch Officer

    Found in: Dice One Red US C2 - 7 days ago


    Beltsville, United States Peraton Full time

    About Peraton Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our...

  • Senior Information Technology Network Security Engineer

    Found in: Dice One Red US C2 - 6 days ago


    Beltsville, United States Peraton Full time

    About Peraton Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our...

  • Data Architect

    Found in: Dice One Red US C2 - 2 weeks ago


    Beltsville, United States Peraton Full time

    About Peraton Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our...

  • Cyber Incident Handler

    Found in: Dice One Red US C2 - 2 weeks ago


    Beltsville, United States Peraton Full time

    About Peraton Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our...

  • Cyber Security Engineer with Security Clearance

    Found in: Dice One Red US C2 - 6 days ago


    Beltsville, United States Catapult Staffing Full time

    Cyber Security Engineer Technical Skills with 7 Years of experience • Cribl• Splunk Enterprise • Azure We are looking for a certified Cribl resource with a Splunk Enterprise and Splunk Enterprise Security background. Azure experience is a bonus. The candidate will be supporting the deployment of (3) worker nodes.


  • Beltsville, United States Peraton Full time

    About Peraton Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our...

  • Technical Help Desk Professional with Security Clearance

    Found in: Dice One Red US C2 - 6 days ago


    Beltsville, United States General Dynamics Information Technology Full time

    We are GDIT. We stay at the forefront of innovation to solve complex technical challenges. GDIT is your place. Make it your own by discovering new ways to securely and expertly apply the latest technology. Own your opportunity at GDIT and you’ll be a meaningful part of improving how agencies operate. Our work depends on a Technical Help Desk Professional...


  • Beltsville, United States Cybermgt Full time

    Location: Beltsville, MD Terms: Full-time Requirements: Must be a U.S. Citizen with Active Security Clearance About us Cyber Management is a rapidly growing Veteran Owned Small Business (VOSB). To us, Cyber is no buzzword…it is all of the technology supporting our business, government, and personal information, and we understand how vital it is to...


  • Beltsville, United States Peraton Full time

    About Peraton Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our...

  • Safety and Health Engineer with Security Clearance

    Found in: Dice One Red US C2 - 2 weeks ago


    Beltsville, United States Building People LLCThe Full time

    As a recognized leader in real estate and facilities services, The Building People provides innovative solutions that integrate technology, buildings, and people through strategic thought leadership and expertise. We enhance our customers' ability to build a culture that optimizes performance in the built environment. Our strategy leads clients towards the...


  • Beltsville, United States CareerBuilder Full time

    Minimum Qualifications & Skills: Minimum of 14 years with BS/BA; OR 12 years with MS/MA; OR 9 years with PhD ONE of the following certifications required: CASP+ CE, CCNP Security, CISA, CISSP, GCED, GCIH Experience with network design, network monitoring, and software systems and technologies that demonstrate the ability to monitor and defend an enterprise...