Jobs and Careers
MA

Systems Security Specialist - Penetration Testing

Matrix Systems and Technologies Inc.
United Statesfull_timeVerifiedPosted 14 May 2026
💰 $130,000/yr($85,000/yr$130,000/yr)

About the role

Benefits:
  • Health insurance
  • Paid time off
  • Training & development

Matrix Systems and Technology is seeking a Systems Security Specialist to perform internal and external penetration testing of networks, web applications, API's, and cloud environments to identify security vulnerabilities and exploit paths, and other related tasks.

Duties/ Responsibilities:
  •  Conduct internal and external penetration testing of networks, web applications, APIs, and cloud environments to identify security vulnerabilities and exploit paths. 
  • Perform red team engagements simulating real-world adversary tactics, techniques, and procedures (TTPs) aligned with MITRE ATT&CK. 
  • Execute vulnerability assessments and validate remediation efforts through retesting and technical verification. 
  • Develop comprehensive penetration testing reports, including executive summaries, risk ratings, proof-of-concept evidence, and actionable remediation guidance. 
  • Perform threat modeling and attack surface analysis to identify high-risk exposure areas and privilege escalation pathways. 
  • Conduct secure configuration reviews of operating systems, network infrastructure, cloud platforms, and identity systems. 
  • Evaluate application security through dynamic and manual testing techniques, including authentication, session management, input validation, and access control testing. 
  • Review source code for security weaknesses and secure coding gaps, particularly in C/C++, Python, Java, or similar languages. Develop and maintain custom scripts or tooling to automate testing activities and enhance offensive security capabilities. 
  • Support incident response activities by recreating attack chains, validating compromise scenarios, and identifying root causes. Assess Zero Trust implementations, micro-segmentation strategies, and identity-based security controls for effectiveness. 
  • Conduct phishing simulations and social engineering exercises to evaluate user awareness and organizational resilience. 
  • Provide technical briefings to executive leadership and technical stakeholders regarding risk posture and remediation prioritization. 
  • Collaborate with engineering, DevOps, and infrastructure teams to remediate identified vulnerabilities and strengthen security architecture. 
  • Contribute to the development of security policies, testing methodologies, and enterprise security standards. 
  • Support compliance efforts by mapping testing results to NIST, OWASP, CIS, or other applicable security frameworks.
  • Participate in continuous improvement of penetration testing methodologies, tools, and adversary emulation strategies. 
  • Adhere to all security, change control, and Project Management Office (PMO) policies, processes, and methodologies.

Minimum Qualifications: 
  •  A Minimum eight (8) years of progressive experience in cybersecurity 
  • A minimum of five (5) years performing penetration testing or red team engagements. 
  • A minimum of five (5) years conducting network penetration testing, web application and API testing, internal and external vulnerability assessments and threat modeling and attack path analysis 
  • A minimum of five (5) years developing and delivering formal penetration test reports, including executive summaries and technical remediation guidance. 
  • A minimum of five (5) years supporting incident response investigations and validation testing. 
  • A minimum of five (5) years with common penetration testing tools (e.g., Metasploit, Burp Suite, Nmap, Wireshark, Nessus, etc.). 
  • Strong knowledge of Secure coding practices, Application security testing (SAST/DAST concepts), Network architecture and segmentation and Identity and access management concepts 
  • A minimum of five (5) years of demonstrated scripting or development ability in at least one language (e.g., Python, C/C++, PowerShell, Bash). 
  • A minimum of five (5) years of working with NIST Cybersecurity Framework, NIST 800-53 or similar federal control frameworks, MITRE ATT&CK and OWASP Top 10 A minimum of five (5) years of experience mapping findings to security control frameworks. 
  • At least one recognized offensive security certification (e.g., OSCP, GPEN, GXPN, CEH, or major experience can substitute for certification). 
  • Demonstrated ability to communicate technical findings to executive and non-technical audiences, and provide actionable remediation recommendations. Demonstrated experience working in government or highly regulated environments.
Preferred Qualifications:
  •  A Minimum ten (10) years of progressive experience in cybersecurity 
  • A minimum of eight (8) years of exper

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Matrix Systems and Technologies Inc.

View company profile →