Security Software Engineer/Penetration Tester

3 days ago


Dahlgren, United States Cydecor Full time

Cydecor is a premier Federal Government solutions provider, delivering differentiated innovations in mission systems and business platforms. We leverage leading-edge secure systems and software development, backed by industry-leading subject matter expertise, and business intelligence to enable decision-support and remain ahead of ever-evolving national security challenges. Our success rests squarely on three bedrock principles: People, our center of gravity; Mission, what inspires us; and an unyielding commitment to Excellence, what separates us. Job Description: Cydecor is seeking a Security Software Engineer/Penetration Tester to support advanced cybersecurity and software assurance efforts for U.S. Department of Defense (DoD) systems. The ideal candidate will combine deep technical experience in software engineering, penetration testing, and reverse engineering with a strong understanding of secure system design and vulnerability mitigation for enterprise and tactical environments. Responsibilities include: * Debug and reverse engineer software to identify vulnerabilities and optimize security performance. * Analyze Windows Event logs, Linux syslogs, boot logs, and dmesg logs to identify anomalies and security concerns. * Program and debug software using Web 2.0, Java, Perl, Ada, C++, and Tool Command Language (Tcl/Tk) scripts, including GUIs and configuration management tools such as Microsoft Visual Studio and Rational ClearCase. * Recommend and implement software modifications to mitigate known vulnerabilities. * Administer systems running HP-UX, UNIX, Solaris, Linux, and Microsoft Windows operating systems. * Identify and remediate security flaws in both compiled and human-readable source code. * Understand and work with real-time operating systems (VxWorks, LynxOS), CORBA, firewalls, and networking protocols. * Implement NSA-approved encryption technologies and devices and apply DISA Security Technical Implementation Guides (STIGs). * Incorporate virtual hosting, server technologies, and deceptive technologies (e.g., honeypots) into system architectures. * Perform and participate in code reviews, static source code analysis, and author recommendations to improve software design and security posture. * Contribute to the System Security Administrator and Operator's Manual (SSAOM) and ensure all cybersecurity documentation is maintained to DoD standards. Here's what you need: * Experience: * Five (5) years of software engineering experience supporting program development or modeling and simulation for DoD or IT systems. * Five (5) years of Linux experience, demonstrating firm command-line and system administration skills. * CompTIA Linux+ or FedVTE Linux+ (Linux) * Five (5) years of Windows experience with solid understanding of enterprise network environments. * Microsoft course (MCSA; Various) * Strong working knowledge of common Penetration Testing (PENTEST) tools: * Kali, Metasploit, NMAP, Cobalt Strike * Associated Training: Certified Ethical Hacker or Offensive Security Certified Professional * Documented experience in at least one of the following areas: * Penetration Testing (PENTEST) (government or contractor) * Red Team Operations (government or contractor) * Tool/Software Development (exploits/malware, C2, reverse engineering, bug bounties) * Python, C, C Sharp, C++, Go, Perl, Powershell * Web Dev/Web App Dev/Web Penetration testing * NSX, vCenter, vRealize Suite, Horizon View (VDI) and others * PAN-OS * FirePower, Nexus, IOS, ASA * ONTAP, SnapMirror * Active-Directory * Entra ID (Azure AD), Active Directory, SSO, MFA, Azure application integration, Identity Federation. * utomation using Powershell, PowerAutomate, Logic Apps, Graph API. * Microsoft Entra ID and Microsoft 365 in a hybrid environment. * xperience with Palo Alto, Cisco, VMWare, NetApp and Microsoft products. * Extending or integrating on premises AD with Entra ID. * Managing identity and access in Microsoft Entra ID. * Experience conducting Red Team operations in an MDE environment. * Experience with AWS, Cloud Audit, Serverless and Microservice Architecture * Experience working with AWS services (such as EC2, S3, KMS, RDS) and security best practices relevant to those services * Experience with Web Services penetration testing (RESTful and SOAP) Web Authentication protocols (e.g. OAuth2, SAML, LDAP) * PHP, ASP, SQL db's, Java, HTML, No SQL * Certifications: * Minimum IAT Level II certification per DoD 8570.01 (or successor). * Minimum penetration testing certification, holding at least one of the following: * Offensive Security Certifications: OSCP, OSCE, OSEE, OSWP * SANS Certifications: GPEN, GWAPT, GXPN, or equivalent Red Team / Penetration Testing certifications * COAC Graduate (OSD-sponsored Cyber Operations Academy Course) * Capture the Flag (CTF) participation (e.g., DEFCON, Over-The-Wire, Hack the Box, USS Secure CTFs). * Published security research resulting in a Common Vulnerabilities and Exposures (CVE) submission. * Knowledge: * Strong understanding of computer security principles, military system specifications, and DoD Cybersecurity policies for both land-based and afloat/tactical systems. * Ability to communicate effectively and succinctly in both written and verbal formats. Bonus Points If You Have: * Experience developing or integrating cyber tools for vulnerability research and exploitation testing. * Experience leading software assurance or cyber tool development projects in classified environments. * Familiarity with DoD Risk Management Framework (RMF) and A&A processes. Security Clearance: * Active Top Secret clearance with SCI eligibility. Education: * Bachelor's degree Work Schedule: * Hybrid, Monday-Friday (8 hours/day). * Position is primarily remote, with potential on-site requirements as needed. Compensation and Benefits: Cydecor offers a comprehensive compensation package including Health and Dental Insurance, Vision and Life Insurance, Short-Term & Long-Term Disability, 401(K) + company match, Paid Time Off (PTO), Paid Company Holidays, Tuition and Professional Development Assistance and more. What We Believe We have an unwavering commitment to diversity with the aim that every one of our people has a full sense of belonging within our organization. As a business imperative, every person at Cydecor has the responsibility to create and sustain an inclusive environment. Equal Employment Opportunity Statement Cydecor is an Equal Employment Opportunity/Affirmative Action Employer (EEO/AA). All employment and hiring decisions are based on qualifications, merit, and business needs without regard to race, religion, color, sexual orientation, nationality, gender, ethnic origin, disability, age, sex, gender identity & expression, veteran status, marital status, or any other characteristic protected by applicable law. If you are a qualified individual with a disability and/or a disabled veteran, you may request a reasonable accommodation if you are unable or limited in your ability to access job openings or apply for a job on this site because of your disability. You can request assistance by contacting or calling 703-884-2105.



  • Dahlgren, United States ANALYGENCE, Inc. Full time

    Job Description ANALYGENCE is seeking a skilled Security Software Engineer with a strong foundation in reverse engineering, penetration testing, and secure software development. This role will contribute to the design, analysis, and testing of secure systems and applications, with a focus on offensive security capabilities in complex DoD and enterprise...


  • Dahlgren, United States Data Intelligence LLC. Full time

    Data Intelligence is seeking a seasoned Security Software Engineer — Red Team / Penetration Tester to join a hands-on offensive security team supporting mission systems in the defense domain. This role is ideal for a pragmatic, technically deep engineer who blends software development, exploitation tooling, and operational red-team experience to assess and...


  • Dahlgren, United States Amentum Full time

    Amentum is seeking software testing professionals with related education and/or experience to support systems and software development in support of the Navy and Marine Corps at Dahlgren, VA. You will be part of our growing systems & software engineering team and contribute to our diverse skillsets across multiple contracts in support of our Centers of...


  • Dahlgren, United States ARES Corporation Full time

    ARES is hiring a senior software security engineer to support a critical Department of Defense cybersecurity program. The ideal candidate will have demonstrated experience supporting software security assessments in accordance with DoD and Navy requirements, including RMF processes and STIG compliance The candidate should have experience supporting software...


  • Dahlgren, United States ARES Corporation Full time

    ARES is hiring a senior software security engineer to support a critical Department of Defense cybersecurity program. The ideal candidate will have demonstrated experience supporting software security assessments in accordance with DoD and Navy requirements, including RMF processes and STIG compliance. The candidate should have experience supporting software...


  • Dahlgren, United States ARES Corporation Full time

    A leading defense contractor in Dahlgren, VA is seeking a Senior Software Security Engineer to support critical cybersecurity programs for the Department of Defense. The ideal candidate will have experience in software security assessments and a strong background in secure code development, penetration testing, and cyber standards. Applicants must have a...


  • Dahlgren, United States ESTUDIO DE INGENIERIA Y CONTROL DE OBRAS SL Full time

    Join to apply for the Software Engineer role at ESTUDIO DE INGENIERIA Y CONTROL DE OBRAS SL . 2 weeks ago Be among the first 25 applicants BecTech, Inc. is seeking a Mid- to Senior- Level Software Engineer to join their team in King George, VA. The qualified applicant will support missile and ballistic missile defense software development, testing, and...


  • Dahlgren, United States Peerless Technologies Corporation Full time

    Team Peerless is looking for a Software Engineer to join our Enhanced Modeling and Simulation (M&S) team. In this role, you’ll collaborate with a multidisciplinary group of software engineers, data scientists, and operations research analysts to support the Joint Warfare Analysis Center and other Department of Defense and Intelligence Community partners....


  • Dahlgren, United States Amentum Full time

    Amentum is seeking a DevSecOps Senior System Administrator to work with software testing on a current Naval program. A Continuous Integration System Administrator to assist with the DevOps process, and system software testing. Some full stack web development experience is helpful. Job is approximately 50/50 Systems Admin and Software Testing, varying per...


  • Dahlgren, United States Anonymous Employer Full time

    Software Engineer (Secure Dev / DevSecOps) — What You’ll Do You’ll help build and ship secure, high-performance software that supports mission-critical DoD programs. This is a hands-on role where you’ll own features end-to-end—from requirements through deployment—while working closely with developers and DevSecOps engineers. Key Responsibilities...