Penetration Tester

SteelToadDahlgren, United States
Full TimeOn-siteJuniorLimited info disclosed
21 views0 applications

Description

Company Description SteelToad is a cybersecurity firm focused on mitigating risk, increasing organizational resilience, and protecting critical data while supporting regulatory compliance. As a HUBZone Certified Small Business with over 20 years of cybersecurity experience across its team, SteelToad delivers cyber assessments, security services, and governance, risk, and compliance (GRC) solutions to public sector and Defense Industrial Base (DIB) clients. The company holds multiple accreditations and certifications, including ISO 9001, ISO 20000-1:2018, ISO 27001:2022, and operates as a CMMC Third-Party Independent Assessment Organization (C3PAO) and A2LA accredited provider. SteelToad is deeply familiar with frameworks such as NIST SP 800-53/30/66, CMMC, RMF, HIPAA, and FISMA, and designs tailored solutions addressing complex security needs. Team members collaborate closely with government agencies and regulated organizations to strengthen cyber resilience through services like penetration testing, red teaming, vulnerability management, and continuous monitoring. Role Description the Vulnerability Assessment Analyst and Penetration Tester delivers continuous cyber assessments, solves complex technology problems, builds tools, and helps identify, influence, and mitigate threats. This role performs manual assessments of systems, services, and software, specializing in security issues beyond those identified by static analysis tools. The individual helps ensure services, applications, and websites are designed and implemented to the highest security standards. Responsibilities include application and hardware penetration testing, automating repetitive tasks with scripting languages, mentoring and leading engineers through complex penetration tests and vulnerability assessments, advancing penetration testing capabilities through automation and tooling, and creating threat mitigation plans. Education Bachelor’s degree in Cybersecurity, Cyber Operations, Cyber Engineering, Information Systems, Information Technology, Computer Engineering, Electrical Engineering, Electronics Engineering, Software Engineering, Computer Science, Mathematics with a concentration in Computer Science, or an equivalent discipline. Required Certificaton/Qualification · DoW 8570.01-M in accordance with DFARS 252.239-7001 Baseline Certification: minimum CSSP Auditor. · One of the following certifications: Offensive Security Certified Professional (OSCP), Offensive Security Certified Expert (OSCE), Offensive Security Exploitation Expert (OSEE), or Offensive Security Wireless Professional (OSWP). Experience Seven (7) years of full-time professional experience conducting penetration testing or offensive cyber operations in the following areas: · Developing and using penetration testing tools such as Metasploit, NMAP, Kali Linux, and Cobalt Strike. · Mimicking threat behavior. · Using multiple operating systems, including Linux, Windows, macOS, and related platforms. · Using Active Directory. · Performing exploit development. · Identifying gaps in tools and development techniques. · Developing with at least two scripting or programming languages, such as Python, C++, Java, Rust, Assembly, or C#. Bachelor’s degree in Cybersecurity, Cyber Operations, Cyber Engineering, Information Systems, Information Technology, Computer Engineering, Electrical Engineering, Electronics Engineering, Software Engineering, Computer Science, Mathematics with a concentration in Computer Science, or an equivalent discipline. Required Certification/Qualification · DoD 8570.01-M in accordance with DFARS 252.239-7001 Baseline Certification: minimum CSSP Auditor. · One of the following certifications: Offensive Security Certified Professional (OSCP), Offensive Security Certified Expert (OSCE), Offensive Security Exploitation Expert (OSEE), or Offensive Security Wireless Professional (OSWP). Benefits & Compensation · New employees are eligible to participate in the company’s benefits plan on their date of hire unless noted otherwise. · Medical insurance. · Vision and dental insurance. · Long-term disability, short-term disability, group life, and AD&D insurance: 100% employer paid. · Flexible Spending Plan. ·   Health Savings Account. · 401(k) Savings Plan: 100% match for the first 3% contributed, plus 50% of the next 2% contributed; no vesting period, with eligibility on date of hire. · Eleven (11) paid holidays per year. · One hundred twenty (120) accrued hours of Paid Time Off per year. · Professional Development Program. · Salary will be determined based on the individual’s education and experience level. Company Overview SteelToad Consulting LLC is a leading provider of IT support, cybersecurity, training, and development services to the Department of Defense (DoD) and other government agencies. We are seeking an experienced Red Team Penetration Tester III to support cyber assessment and offensive security work in the defense sector. Equal Employment Opportunity Policy Statement It is the policy of SteelToad Consulting LLC. and its subsidiaries (the “Company”) not to discriminate against any employee or applicant for employment because of race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, marital status, genetic information, mental or physical disability (and medical condition, for employees in California), or because he or she is a protected veteran. It is also the policy of the Company to take affirmative action to employ and advance in employment all persons regardless of race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, marital status, genetic information, mental or physical disability (and medical condition, for employees in California), or protected veteran status, and to base all employment decisions only on valid job requirements. This policy applies to all employment actions, including but not limited to recruitment, hiring, upgrading, promotion, transfer, demotion, layoff, recall, termination, rates of pay or other forms of compensation, and selection for training, including apprenticeship, at all levels of employment. Employees and applicants of the Company will not be subject to harassment on the basis of race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, marital status, genetic information, mental or physical disability (and medical condition, for employees of Maryland), or because he or she is a protected veteran. Retaliation, including intimidation, threats, or coercion, because an employee or applicant has objected to discrimination, engaged or may engage in filing a complaint, assisted in a review, investigation, or hearing, or otherwise sought to obtain legal rights under any Federal, State, or local EEO law is prohibited.