Jobs and Careers
AG
Senior Penetration Tester
Agile DefenseAlexandria, United Statesfull_timeVerifiedPosted 25 Oct 2024
About the role
At Agile Defense we know that action defines the outcome and new challenges require new solutions. That’s why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next.
Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility—leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation’s vital interests.
Requisition #641 Job Title: Penetration TesterLocation: REMOTEClearance Level: Active DoD - Public Trust
SUMMARYThe United States Patent and Trademark Office (USPTO), Cybersecurity Division, has a requirement to enhance existing Pen Test resources with the goal of improving the Pen Test team’s capability in assessing external-facing agency systems.
JOB DUTIES AND RESPONSIBILITIES· Conduct Penetration Testing (application and/or infrastructure) and articulate security issues to both technical and non-technical audiences· Identify, research, validate, and exploit various known and unknown security vulnerabilities· Coordinate with business and technical contacts to assist in the development and delivery of secure solutions· Compose detailed, technical, attack narratives which outline specific attack chains utilized, clear impact of vulnerabilities discovered, and suggested paths to remediation which address root cause of identified weak points in enterprise security architecture
QUALIFICATIONSRequired Certifications· PNPT, OSCP, OSCE, GXPN, GPEN, GCIH, GWAPT, GCFA or possess a willingness to pursue certifications after hireEducation, Background, and Years of Experience· Bachelor’s degree/University degree or equivalent experience
ADDITIONAL SKILLS & QUALIFICATIONSRequired Skills· 3+ years of relevant experience with the requirements below:· Extensive experience working with Offensive Security Methodologies and Attack Simulation Techniques· Offensive Security testing tools. e.g., Cobalt Strike, Kali Linux, Bloodhound, Red Team Toolkits· Exploitation frameworks, e.g., Metasploit, CANVAS, Core Impact· Deep understanding of OSI model· OS Security. e.g., Unix/Linux, Windows, OSX· Understanding of common protocols. e.g., HTTP, LDAP, SMTP, DNS· Web application infrastructure. e.g., Application Servers, Web Servers, Databases· Demonstrated ability to collaborate with a variety of analytical groups and service delivery organizations· Advanced analytical and problem-solving skills· Consistently demonstrates clear and concise written and verbal communication· Proficient in interpreting and applying policies, standards, and procedures· Demonstrated ability to remain unbiased in a diverse working environment
Preferred Skills· Experience leveraging the MITRE ATT&CK Framework· Vulnerability Assessment tools. e.g., Nessus, Qualys, Rapid7· Social Engineering campaigns. e.g., email phishing, phone calls, SET· Security devices, i.e., Firewalls, VPN, AAA systems· Web development and programming languages. e.g. Python, Perl, Ruby, Java, .Net
WORKING CONDITIONSEnvironmental Conditions· Office setting.Strength Demands· Sedentary – 10 lbs. Maximum lifting, occasional lift/carry of small articles. Some occasional walking or standing may be required. Jobs are sedentary if walking and standing are required only occasionally, and all other sedentary criteria are met.Physical Requirements· Stand or Sit; Repetitive Motion; Use Hands / Fingers to Handle or Feel; SeeEmployees of Agile Defense
Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility—leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation’s vital interests.
Requisition #641 Job Title: Penetration TesterLocation: REMOTEClearance Level: Active DoD - Public Trust
SUMMARYThe United States Patent and Trademark Office (USPTO), Cybersecurity Division, has a requirement to enhance existing Pen Test resources with the goal of improving the Pen Test team’s capability in assessing external-facing agency systems.
JOB DUTIES AND RESPONSIBILITIES· Conduct Penetration Testing (application and/or infrastructure) and articulate security issues to both technical and non-technical audiences· Identify, research, validate, and exploit various known and unknown security vulnerabilities· Coordinate with business and technical contacts to assist in the development and delivery of secure solutions· Compose detailed, technical, attack narratives which outline specific attack chains utilized, clear impact of vulnerabilities discovered, and suggested paths to remediation which address root cause of identified weak points in enterprise security architecture
QUALIFICATIONSRequired Certifications· PNPT, OSCP, OSCE, GXPN, GPEN, GCIH, GWAPT, GCFA or possess a willingness to pursue certifications after hireEducation, Background, and Years of Experience· Bachelor’s degree/University degree or equivalent experience
ADDITIONAL SKILLS & QUALIFICATIONSRequired Skills· 3+ years of relevant experience with the requirements below:· Extensive experience working with Offensive Security Methodologies and Attack Simulation Techniques· Offensive Security testing tools. e.g., Cobalt Strike, Kali Linux, Bloodhound, Red Team Toolkits· Exploitation frameworks, e.g., Metasploit, CANVAS, Core Impact· Deep understanding of OSI model· OS Security. e.g., Unix/Linux, Windows, OSX· Understanding of common protocols. e.g., HTTP, LDAP, SMTP, DNS· Web application infrastructure. e.g., Application Servers, Web Servers, Databases· Demonstrated ability to collaborate with a variety of analytical groups and service delivery organizations· Advanced analytical and problem-solving skills· Consistently demonstrates clear and concise written and verbal communication· Proficient in interpreting and applying policies, standards, and procedures· Demonstrated ability to remain unbiased in a diverse working environment
Preferred Skills· Experience leveraging the MITRE ATT&CK Framework· Vulnerability Assessment tools. e.g., Nessus, Qualys, Rapid7· Social Engineering campaigns. e.g., email phishing, phone calls, SET· Security devices, i.e., Firewalls, VPN, AAA systems· Web development and programming languages. e.g. Python, Perl, Ruby, Java, .Net
WORKING CONDITIONSEnvironmental Conditions· Office setting.Strength Demands· Sedentary – 10 lbs. Maximum lifting, occasional lift/carry of small articles. Some occasional walking or standing may be required. Jobs are sedentary if walking and standing are required only occasionally, and all other sedentary criteria are met.Physical Requirements· Stand or Sit; Repetitive Motion; Use Hands / Fingers to Handle or Feel; SeeEmployees of Agile Defense
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s