Penetration Tester Connsci
Overview
Connsci seeks a Penetration Tester to support a government program. This role involves direct involvement in penetration testing vulnerability and compliance testing web application testing API testing and audit reporting functions.
What You'll Do11
- 1Conduct authenticated vulnerability scans and compliance evaluations across networks systems endpoints and cloud platforms.
- 2Perform security assessments of agency web applications using OWASP Top 10 and industry best practices.
- 3Identify vulnerabilities such as injection flaws authentication weaknesses session mismanagement and sensitive data exposure.
- 4Validate application security controls against NIST CSF subcategories.
- 5Evaluate REST GraphQL APIs for authentication authorization and input validation weaknesses.
- 6Conduct fuzzing and misuse testing to find broken object level authorization BOLA and mass assignment vulnerabilities.
- 7Assess security of API tokens keys and session management practices.
- 8Review error handling data leakage and logging practices for compliance.
- 9Perform controlled penetration testing internal and external to simulate adversary behaviors and evaluate defensive effectiveness.
- 10Document findings prepare audit evidence and provide recommendations for improving governance risk and compliance posture.
- 11Provide technical assistance to Agency OIGs and coordinate with operational IT and security teams to ensure findings are actionable and evidence based.
Requirements8
- 1Bachelor's degree in Cybersecurity Information Systems or related field or equivalent experience.
- 2At least 5 years of experience in penetration testing including web application testing and API testing.
- 3At least 2 years of experience supporting audit compliance or oversight functions including preparing audit ready documentation evidence and reports for executive leadership.
- 4At least 2 years of experience with NIST Cybersecurity Framework including NIST 800-53.
- 5One cybersecurity certification such as CISSP CISA CISM CCE CFCE GCFE or CEH.
- 6Master's degree in Cybersecurity Information Technology or Computer Science preferred.
- 77+ years of experience in penetration testing.
- 83+ years of experience with cloud technologies and Cloud Security Posture Management.
Salary Insight
$100 - $130k per year
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.
AGR LLC
VerifiedSenior-Level Red Cell Penetration Tester
Lead Red Cell operations supporting the Federal Strategic Cyber program. Own penetration testing initiatives and mentor junior testers. Deliver actionable insights that enhance national cyber defense capabilities.
OCT Consulting, LLC
VerifiedIT Security Vulnerability Specialist - OCT Consulting
OCT Consulting seeks an Associate IT Security Vulnerability Specialist to lead vulnerability remediation for federal clients. This hybrid role requires 3 days weekly presence in Suitland MD. The ideal candidate will drive efficiency in vulnerability management while articulating risk to leadership. You will conduct assessments monitor tools develop policies and participate in incident response. Experience with NIST RMF and security frameworks is essential.
Peraton
VerifiedCybersecurity Vulnerability Analyst at Peraton
Peraton seeks a Cybersecurity Vulnerability Analyst in Linthicum MD to lead the Department of Defense Vulnerability Disclosure Program. The analyst will triage reports via HackerOne, evaluate severity, and coordinate mitigation efforts. This role combines offensive security research with collaboration to protect national security assets.
Sealing Technologies, a Parsons Company
VerifiedCybersecurity Engineer - Sealing Technologies
Sealing Technologies seeks a Cybersecurity Engineer to lead vulnerability management and detection tuning for a DoD program. This role drives protection of mission critical systems through hardening and incident response. The ideal candidate will own security operations and mentor junior engineers.
AT&T Technical Services Company, Inc.
VerifiedCyber Auditor Full Performance Government
The Cyber Auditor will own and scale cybersecurity monitoring while supporting the Global Network Operation Center. This role involves vulnerability scanning and risk mitigation across government infrastructure. The ideal candidate thrives in a dynamic environment and drives proactive security improvements.
00100 LEIDOS, INC.
VerifiedCyber Infrastructure Support Lead 50-60 chars
Lead a team to enhance enterprise IT reliability performance and security across Windows and Linux platforms. Drive system improvements while maintaining compliance and mentoring staff. This role offers unique opportunities to shape security architecture and lead impactful initiatives.