Security Auditor/ Penetration Testing
MBL Technologies Inc.About the role
Description
MBL Technologies, Inc. offers a diverse set of management and technology consulting services to Federal government and commercial markets. Our solutions are tailored to support each client’s mission, accounting for their unique needs and operating environments to ensure success. We bring the right people, capabilities, and expertise together to assist our clients with enabling their mission. Together our individual differences drive successful business results.
If you are transitioning from military to civilian life, have prior service, are a retired veteran, or a member of the National Guard or Reserves, or spouse of an active military service member, we encourage you to apply. Please visit our webpage for information on our policies and benefits for the military and veteran community.
Why Work With Us?
- We trust, empower, and believe in our employees to soar to their fullest potential!
- We offer a robust benefits package (medical, dental, vision, STD, Accident, Life, Hospital Insurance, FSA, HSA, 401K match, professional development stipend, etc.).
- We love to have fun and give back to the community. Community Service and Employee Engagement events are atop our calendar events!
- We genuinely like each other and champion everyone to achieve their own greatness!
MBL Technologies is seeking a Security Auditor/ Penetration Testing to join our team. The individual will be instrumental in supporting and enhancing our organizational initiatives by supporting our team. This role requires a blend of analytical skills, leadership capabilities, and effective communication to address customer requirements and drive successful project outcomes. Directly manages information technology projects to provide a unique service or product.
This position offers a REMOTE environment.
RequirementsPosition Overview:
The SME Security Engineer will support and provide expertise to a successful cybersecurity and Privacy program for a government customer. The SME Security Engineer will be responsible for designing, implementing, and maintaining secure systems and networks in a DevSecOps environment. You will work closely with cross-functional teams, including IT, network engineering, and cybersecurity, to ensure that systems and networks are secure, compliant with applicable regulations, and protected against unauthorized access and other security risks. You will be responsible for identifying vulnerabilities and potential threats, conducting risk assessments, and developing and implementing security solutions to mitigate risks. You will also be involved in incident response, security monitoring, and security policy development.\
Mandatory Requirements:
- CISM, CISSP, GSLC, CEH, LPT, CPT. Similar level certifications considered on a case-by-case basis.
- U.S. Citizenship
- Must possess or be able to obtain a federal background investigation of Tier 4 Critical Non-Sensitive (Form SF 85P)
- Bachelor’s degree in business, information technology, or related field of study or 10 years of experience in computer security may substitute for degree.
- Minimum seven years of experience in cybersecurity.
Preferred Qualifications:
- AWS Solutions Architect – Professional (network certified), AWS Certified Security – Specialty, Splunk Enterprise Certified Architect
- Experience with Webinspect, BurpSuite, Splunk Expert (+), Tenable
- Expertise with Sonar Qube (source code analysis. static source code analysis)
- Splunk Power User
- Strong in vul analysis. Using Splunk on top of that.
- Experience demonstrating strong analytical, troubleshooting, and problem-solving skills for cybersecurity.
- Excellent in oral, written, and verbal communication skills.
- Knowledge of:
o NIST Cybersecurity, Zero Trust Architecture and Risk Management frameworks and associated requirements.
o Risk management processes (e.g., methods for assessing and mitigating risk).
o Cybersecurity/privacy principles and cyber threats and vulnerabilities.
- Knowledge of Networking Protocols (TCP/IP, SNMP, DNS, DHCP, ISCSI)- penetration tester.
- Experience implementing, running, and maintaining tools and/or processes to reliably identify security issues such as SQLi, XSS, CSRF, and business logic flaws across large code bases (SAST, DAST, PenTesting, Security Unit Testing)
- Knowledgeable regarding browser security controls (CSP, XFO, HSTS,), web application security topics such as OWASP (pen tester) Top 10, and authentication infrastructure (SAML, OAUT
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s