Jobs and Careers
PH

Senior Penetration Testing Engineer

phia, LLC
Merrifield, United Statesfull_timeVerifiedPosted 13 Feb 2024

About the role

At phia we hire talented and passionate people who are focused on collaborative, meaningful work, providing technical and operational subject matter expertise and support services to our partners and clients.
phia is seeking a Senior Penetration Testing Engineer with a passion for protecting large enterprises from cyber threats and a desire to advance their career in a dynamic and challenging environment. In this role, you will provide senior security testing (pen-testing, red teaming, application security testing, etc.) support for a nationwide IT enterprise supporting over 600,000 employees, and infrastructure providing services to tens of millions of users.  This is a remote job. Qualified candidates will live and work within the United States and be U.S. Citizens able to achieve Public Trust. What You’ll Do Plan and conduct penetration testing activities across the following disciplines:o  Web Application testingo   Network Penetration testingo   API and serverless penetration testingo   Cloud based penetration testing (one of the three): AWS, Microsoft Azure, Google Cloud Platform (GCP)

Responsibilities

  • Work both individually and as part of a team, sometimes with very specific direction and sometimes with broad guidelines and requiring thoughtfulness and innovation.
  • Demonstrate detailed knowledge of web application and network based penetration testing security tools.
  • Provide expert-level guidance regarding penetration testing and vulnerability assessment industry best practices.
  • Define procedures for penetration testing assessment for servers, endpoints, network appliances, and applications.
  • Perform assessments of systems and networks within the enterprise and identify where those systems/networks deviate from acceptable configurations, enclave policy, or local policy.
  • Perform application security assessments of key business services and provide written reports on the security posture of those systems.
  • Measure the effectiveness of defense-in-depth architecture against known vulnerabilities and attack techniques.
  • Other relevant duties as assigned/

Required: Education + Experience

  • Bachelor’s degree in a technical specialty such as cyber security, computer science, management information systems, or related IT (Information Technology) field with 9 years of professional experience or 7 years of experience with a relevant master’s degree; additional years of experience may be substituted for degree.
  • Diverse experience in cyber security vulnerability assessments with a focus on application security assessments
  • Ethical hacking experience including experience in Information Security, application vulnerability testing, code-level security auditing, and secure code reviews
  • Proven history of operational decision-making authority with Government management collaboration
  • Senior-level knowledge of penetration testing best practices and tool usage.
  • Highly skilled in web application testing, API testing, and network testing.
  • Prior experience with Burp Suite Professional or similar DAST tools.
  • Proficiency in tools such as Metasploit Pro and Cobalt Strike for pen-testing operations.
  • Proficiency in scripting, such as Python and/or PowerShell.
  • Technical writing skills, with the ability to communicate concepts related to security vulnerabilities and attack path scenarios.
  • Familiarity with OWASP Application Security Verification Standard (ASVS) and MITRE ATT&CK framework.

Desired Certifications and Experience

  • Offensive Security Certified Professional (OSCP)
  • Global Information Assurance Certification (GIAC) Penetration Tester (GPEN)
  • Certified Penetration Testing Engineer (CPTE)
  • Certified Information Systems Auditor (CISA)
  • Certified Ethical Hacker (CEH)
  • Certified Information Systems Security Professional (CISSP)
  • Security +
  • Equivalent advanced certifications may be considered

Security Clearance

  • U.S. Citizenship required
  • Ability to obtain Public Trust (or higher) government clearance
#LI-LC1
Who You Are A proactive problem solver that appreciates the challenges of working in a fast-paced, dynamic environment.Intellectually curious with a genuine desire to learn and advance your career.An effective communicator, both verbally and in writing.Customer service-oriented and mission-focused.Critical thinker with excellent problem-solving skills If your experience and qualifications aren’t a match for this position, you will remain in our database for consideration for future opportunities that may be a better fit.
Who We Arephia, LLC is a Northern Virginia-based, small business established in 2011 with a focus on Cyber Intelligence, Cyber Security/Defense, Intrusion Analysis & Incident Response, Cyb

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

phia, LLC

View company profile →