Site icon A Job Zone

Cyber Penetration Tester


Job title: Cyber Penetration Tester

Company: The Squires Group

Job description: Overview :The Squires Group is seeking an experienced Cyber Penetration Tester to support a critical federal program focused on advancing cybersecurity and technology security initiatives. In this role you will, support the team by leading penetration tests, identifying vulnerabilities and recommending NIST 800-53-compliant remediations, reporting findings to system owners and engineers, maintaining infrastructure, and developing or modifying tools to automate discovery and exploitation.Work will be performed ONSITE in Arlington, VA. Per our client contract, candidates must be U.S. Citizens, possessing a Secret clearance with eligibility to obtain a final Top Secret security clearance. Responsibilities :Perform and lead penetration testing efforts in support of the Team to evaluate the security posture of client systems.Identify system vulnerabilities and develop remediation strategies in alignment with NIST 800-53 security control requirements.Communicate and present security findings to system owners and engineering teams.Manage and maintain the operational infrastructure of the Team environment.Create or enhance tools to automate vulnerability discovery and exploitation processes. Qualifications :Required Qualifications:

Preferred Qualifications:Active Top Secret or TS/SCI security clearance.Possession of one of the following certifications, or another verifiable credential demonstrating IT security proficiency:CompTIA CASP+ISC2 CISSP, CCSP, or ISSEPPossession of one of the following certifications, or another verifiable credential reflecting practical penetration testing skills:Offensive Security Certified Professional (OSCP)Hack The Box Certified Penetration Testing Specialist (CPTS)TCM Security Practical Network Penetration Tester (PNPT)GIAC GXPNZero Point Security Red Team Ops II * Advanced understanding of the following areas:NIST Risk Management Framework (RMF) and the Assessment & Authorization (A&A) lifecycleCore security principles including CIA triad, IAAAA, access control models, and risk management conceptsNetworking fundamentals such as IP routing, TCP/UDP, VPNs, NAT, and firewall configurationsCommon network protocols (SSH, FTP, SMTP, SMB, HTTP, etc.)Operating system architecture including process, device, and file system managementData security techniques such as encoding, hashing, and encryptionScripting and programming in languages like Bash, Python, PowerShell, and JavaScriptCommon application vulnerabilities including outdated software, misconfigured permissions, insufficient input validation, and monitoring deficienciesWeb application vulnerabilities such as XSS, SQL injection, local file inclusion, insecure file upload, and broken authenticationActive Directory (AD) enumeration and exploitation techniques including kerberoasting, AS-REP roasting, privilege abuse, and golden ticket attacksUnderstanding of PKI and secure environments implementing multifactor authenticationCloud computing platforms including AWS, Microsoft Azure, and Google Cloud Platform (GCP) :Check out our Referral Program!
The Squires Group will pay you for every qualified professional that you refer and we place. If you see a position posted by The Squires Group and know the perfect person for the job, please send us your referral. For more information, go to .

Expected salary:

Location: Arlington, VA

Job date: Sat, 26 Apr 2025 06:01:23 GMT

Apply for the job now!

Exit mobile version