Penetration Tester (Part Time & Remote)
United States - Remote
TestPros
Since 1988, TestPros has provided leading IT compliance services to both government & commercial clients, ensuring regulatory adherence.Company Overview
TestPros is a successful and growing business, established in 1988 to provide Information Technology (IT) technical support services to a wide range of Commercial and U.S. Federal, State, and Local Government customers. Our capabilities include Program Management, Program Oversight, Process Audit, Intelligence Analysis, Cyber Security, NIST SP 800-171 Assessment and Compliance, ATO Support, Computer Forensics, Software Assurance, Software Testing, Test Automation, Section 508 / WCAG / ADA Accessibility Assessment, Customer Experience (CX), Localization Testing, Independent Verification and Validation (IV&V), Quality Assurance (QA), Compliance, and Research and Development (R&D) services. TestPros is an Equal Opportunity Employer.
TestPros delivers innovative independent IT assessment solutions to critical challenges facing the nation and the world. We support the U.S. Federal Government and Commercial clients within the continental USA. TestPros is dedicated to making lives better, safer and more secure.
Job Summary
TestPros is looking for an experienced Penetration Tester professional to support our IT Security consulting work for various Commercial and Federal consulting services projects.
This role is responsible for the successful delivery of penetration testing in both classic hosted and also in cloud hosted environments. In this role, the selected candidate will work with our client’s product development teams to plan for, execute, and report on the results of penetration testing. You must be delivery and efficiency focused, with the ability to manage all aspects of a consulting project to include requirements analysis, bid and proposal development, resource planning, process improvement, and customer relationship management. The ideal candidate will thrive in a fast-paced environment where personal responsibility and open, direct, respectful communications are highly valued.
Location: Remote
Responsibilities:
- Conduct complete penetration tests, report on results, and provide improvement recommendations
- Ensure customer satisfaction through the delivery of high-quality consulting services across a portfolio of commercial and federal government projects
- Ability to elicit and understand customer requirements and covert those requirements into a technical services solution
- Ability to accurately estimate time and cost for each project
- Foster an environment of continuous learning, innovation and excellence
- Work closely with development teams, product managers, and customer success teams to ensure successful delivery of consulting services or product implementation projects and remove roadblocks
- Develop, review and approve formal statements of work, change requests, and proposals
- Formulate timely reports and documentation to track progress
- Effectively collaborate with peers and company leadership to accomplish team, corporate and client objectives
- Answer developer, designer, and content contributor questions about IT Security requirements.
Experience Requirements:
- Minimum of 5 years of experience in penetration testing
- Desired certifications – Security+, CEH, GPEN, OSCP, AWS, or equivalent
- Understanding of OWASP Top 10 and “industry best practices” for penetration testing
- Understanding of all aspects of Penetration Testing with an emphasis on white box testing, black box testing, internal networks, external networks, web applications, and application/code review
- Understanding of Pen Test methods such as Open Source Security Testing Methodology Manual (OSSTMM), Open Web Application Security Project (OWASP), Penetration Testing Execution Standard (PTES), FedRAMP Penetration Test Guide, NIST, etc.
- Proficient with the command line interface of multiple operating systems – Windows, macOS, Linux, etc.
- Solid understanding of manual scripting and scripting languages- ex. Python, Bash, PowerShell, C/C++, etc.
- Proficient with using commercial and open source penetration testing tools – ex. Metasploit, Nikto, SQLMAP, Responder, Nessus, Netcat, Burp Suite, etc.
- Conduct and document vulnerability scans and penetration testing on web-based applications and their underlying hosts
- Proven ability to perform computer network vulnerability assessment and penetration testing
- Understanding of risk planning and mitigation strategies
- Ability to prepare and present documents and briefing materials
- Advise on new threats to the technologies and environment and provide mitigation steps when applicable
- Provide security guidance on design, deployment, and architecture of web-based and cloud hosted applications.
- Participate in technical discussions and collaborate with team members
- Exceptional communication skills - both orally and written
- Strong customer service skills
- Strong organizational and time-management skills with the ability to handle multiple tasks at once, while still paying attention to detail
- A strong work ethic and self-starter attitude, with the ability to thrive in a fast-paced environment
- Bachelor’s degree in a related field or equivalent work experience and advance
Benefits
TestPros offers a competitive salary, medical/dental/vision insurance, life insurance, disability insurance, paid time off, paid holidays, 401(k) retirement plan with company match, opportunities for professional growth, cell phone discounts, and much more! All benefits are per TestPros current policies and are subject to change without notice. Benefits are available to full-time employees.
TestPros, Inc. is an Equal Opportunity Employer.
EEO Statement
All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, sexual orientation, gender identity, marital status, age, national origin, or protected veteran status.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Application security Automation AWS Bash Black box Burp Suite C CEH Cloud Compliance FedRAMP Forensics GPEN Linux MacOS Metasploit Nessus NIST Open Source OSCP OWASP Pentesting PowerShell Python R&D Scripting Vulnerability scans White box Windows
Perks/benefits: 401(k) matching Career development Competitive pay Health care Insurance Startup environment
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Senior Product Security Engineer jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Information Security Specialist jobs
- Open Senior Cyber Security Engineer jobs
- Open Ethical hacker / Pentester H/F jobs
- Open Cyber Security Architect jobs
- Open Cyber Security Specialist jobs
- Open Product Security Engineer jobs
- Open Cybersecurity Analyst jobs
- Open Security Specialist jobs
- Open Chief Information Security Officer jobs
- Open Staff Security Engineer jobs
- Open Manager Pentest H/F jobs
- Open Senior Information Security Analyst jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Consultant SOC / CERT H/F jobs
- Open IT Security Analyst jobs
- Open Senior Information Security Engineer jobs
- Open Cybersecurity Consultant jobs
- Open IT Security Engineer jobs
- Open Senior Penetration Tester jobs
- Open Cybersecurity Specialist jobs
- Open Security Operations Analyst jobs
- Open Sr. Security Engineer jobs
- Open Security Consultant jobs
- Open CISM-related jobs
- Open Windows-related jobs
- Open Network security-related jobs
- Open Pentesting-related jobs
- Open Agile-related jobs
- Open Application security-related jobs
- Open GCP-related jobs
- Open Vulnerability management-related jobs
- Open ISO 27001-related jobs
- Open Threat intelligence-related jobs
- Open CISA-related jobs
- Open Analytics-related jobs
- Open IAM-related jobs
- Open Security assessment-related jobs
- Open Malware-related jobs
- Open Java-related jobs
- Open APIs-related jobs
- Open Security Clearance-related jobs
- Open Forensics-related jobs
- Open SaaS-related jobs
- Open CEH-related jobs
- Open EDR-related jobs
- Open DevOps-related jobs
- Open IDS-related jobs
- Open DoD-related jobs