Jobs and Careers
CR

Senior Systems Security Specialist – Baltimore, MD

Creative Information Technology, Inc.
Falls Church, United StatescontractVerifiedPosted 13 May 2026

About the role


Senior Systems Security Specialist – Baltimore, MD

About us 

Creative Information Technology Inc (CITI) is an esteemed IT enterprise renowned for its exceptional customer service and innovation. We serve both government and commercial sectors, offering a range of solutions such as Healthcare IT, Human Services, Identity Credentialing, Cloud Computing, and Big Data Analytics. With clients in the US and abroad, we hold key contract vehicles including GSA IT Schedule 70, NIH CIO-SP3, GSA Alliant, and DHS-Eagle II.


Join us in driving growth and seizing new business opportunities.

Background 

The Client an independent unit of state government, provides accessible, affordable health coverage to Marylanders. MHBE administers Client (MHC), the state’s health insurance marketplace. Through MHC, Maryland residents explore health insurance plans, compare rates, and determine their eligibility for advanced premium tax credits (APTC), cost-sharing reductions (CSR), and public assistance programs such as Medicaid and the Client (MCHP). 


Client seeks one (1) Senior Systems Security Specialist to perform internal and external penetration testing of networks, web applications, APIs, and cloud environments to identify security vulnerabilities and exploit paths, and other related tasks

Role and Responsibilities 


  • Conduct internal and external penetration testing of networks, web applications, APIs, and cloud environments to identify security vulnerabilities and exploit paths.
  • Perform red team engagements simulating real-world adversary tactics, techniques, and procedures (TTPs) aligned with MITRE ATT&CK.
  • Execute vulnerability assessments and validate remediation efforts through retesting and technical verification.
  • Develop comprehensive penetration testing reports, including executive summaries, risk ratings, proof-of-concept evidence, and actionable remediation guidance.
  • Perform threat modeling and attack surface analysis to identify high-risk exposure areas and privilege escalation pathways.
  • Conduct secure configuration reviews of operating systems, network infrastructure, cloud platforms, and identity systems.
  • Evaluate application security through dynamic and manual testing techniques, including authentication, session management, input validation, and access control testing.
  • Review source code for security weaknesses and secure coding gaps, particularly in C/C++, Python, Java, or similar languages.
  • Develop and maintain custom scripts or tooling to automate testing activities and enhance offensive security capabilities.
  • Support incident response activities by recreating attack chains, validating compromise scenarios, and identifying root causes.
  • Assess Zero Trust implementations, micro-segmentation strategies, and identity-based security controls for effectiveness.
  • Conduct phishing simulations and social engineering exercises to evaluate user awareness and organizational resilience.
  • Provide technical briefings to executive leadership and technical stakeholders regarding risk posture and remediation prioritization.
  • Collaborate with engineering, DevOps, and infrastructure teams to remediate identified vulnerabilities and strengthen security architecture.
  • Contribute to the development of security policies, testing methodologies, and enterprise security standards.
  • Support compliance efforts by mapping testing results to NIST, OWASP, CIS, or other applicable security frameworks.
  • Participate in continuous improvement of penetration testing methodologies, tools, and adversary emulation strategies.
  • Adhere to all security, change control, and MHBE Project Management Office (PMO) policies, processes, and methodologies

Minimum Qualifications

  • A Minimum eight (8) years of progressive experience in cybersecurity
  • A minimum of five (5) years performing penetration testing or red team engagements.
  • A minimum of five (5) years conducting network penetration testing, web application and API testing, internal and external vulnerability assessments and threat modeling and attack path analysis
  • A minimum of five (5) years developing and delivering formal penetration test reports, including executive summaries and technical remediation guidance.
  • A minimum of five (5) yea

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Creative Information Technology, Inc.

View company profile →