Security Penetration Tester

DataLock Consulting Group

Poland

On-site

PLN 252,951 - 379,426

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A cybersecurity consulting firm is seeking a Security Penetration Tester in Poland. The role involves developing security plans, conducting assessments, and ensuring compliance with federal security guidelines. A successful candidate will have experience in security testing and control assessments, alongside necessary certifications like CISSP or CEH. The company values strong communication and technical writing skills, providing a collaborative environment for advanced security challenges.

Qualifications

  • 2+ years’ experience as a lead penetration tester.
  • 4+ years’ experience performing security testing.
  • Experience with the NIST Cybersecurity Framework.

Responsibilities

  • Develop security assessment plans and reports.
  • Perform quality control on assessments.
  • Conduct security controls assessment.

Skills

Lead penetration testing
Security control assessments
Technical writing
Communication skills
Risk assessment

Education

BS/BA in Information Technology

Tools

Nessus
Web Inspect
Db Protect
Splunk

Job description

Overview

Job Description – Security Penetration Tester

Responsibilities
  • Develop, document and review System Rules of Engagement (ROE), Security Assessment Plans (SAPs) and Security Assessment Reports (SARs).
  • Have a working knowledge of the FedRAMP Penetration Guidance and Requirements
  • Develop associated schedules and resource plans to complete the assessments.
  • Perform quality control on the assessment and associated deliverables.
  • Participate as an individual contributor for complex system assessments.
  • Develop practical and risk-based approaches for security control implementation and vulnerability remediation.
  • Work closely with ISSOs (contractors and Government) and the technical team and ensure all appropriate A&A supporting documentation is provided prior to conducting the assessment.
  • Review and provide feedback system boundaries, common controls, the security categorization of information systems, applicable security control baseline based on system categorization.
  • Review and provide feedback system boundaries, common controls, the security categorization of information systems, applicable security control baseline based on system categorization.
  • Conduct/participate in Security Assessment Kickoff briefings and SAR briefings.
  • Review cyber/system/network security body of evidence and documentation for accuracy and completeness.
  • Conduct security controls assessment of applicable security controls and privacy controls; assess implemented security controls and provide assurance that they are operating as intended.
  • Analyze security control findings for information systems and applications to convey weaknesses.
  • Document security assessment results accurately; read, understand, and convey vulnerabilities found during the assessments.
  • Create security assessment results and document recommendations in a SAR for remediations and security control measures.
  • Perform audits of each system and provide an authorization recommendation based on determination of risk to the customer.
  • Audits will include unprivileged and privileged scans against each applicable system.
  • Audits will include unprivileged and privileged database scans against each applicable database management system (DBMS).
  • Perform quality control on the assessment and associated deliverables.
  • Conduct Post Assessment Meetings with the customer.
  • Provide Plan of Action and Milestones (POA&M) support to ensure mitigations are completed or the teams are working to mitigate all vulnerabilities in a timely fashion and within customer policy timelines.
  • Develop and maintain a schedule for conducting reoccurring Continuous Monitoring and ongoing CDM efforts once the initial assessments are complete.
  • Perform continuous monitoring to ensure implemented security controls remain functional throughout the lifecycle of the information system.
Minimum Experience and Skills
  • 2+ years’ experience as a lead penetration tester
  • 4+ years’ experience performing security testing and/or security control assessments.
  • 4+ years’ experience with developing and documenting the ROEs, SAPs, and SARs.
  • 4+ years’ experience and expert knowledge of the NIST Cybersecurity Framework, Risk Management Framework, FIPS, and other NIST A&A publications.
  • 4+ years' of experience utilizing NIST 800-53 and 800-53A.
  • Experience conducting Penetration Tests in a commercial and or federal environment.
  • Experience assessing and providing recommendation on the following: Privacy Impact Assessment, Risk Assessment, System Security Plan, Disaster Recovery / Contingency Plan, and Incident Response Plan.
  • Knowledge of the Systems Development Life Cycle (SDLC) and its application in the development of technology solutions.
  • Knowledge and skills to perform and document the assessment.
  • Experience with tools such as Nessus, Web Inspect, Db Protect and Splunk.
  • Technical background with Windows, Unix, legacy systems, databases, web servers/applications, cloud and virtualization environments.
  • Familiar with the cloud environments (services/security) and FedRAMP A&A process.
  • Familiar with FedRAMP Penetration Testing Guidance.
  • Effective verbal and written communication skills with ability to effectively communicate with all levels of users and teammates both written and verbally.
  • Effective technical writing and documentation processing skills.
Minimum Education
  • BS/BA degree in Information Technology or related cyber/cyber-security field.
  • Experience may be substituted for education on a case-by-case basis.
Certifications
  • Must possess one of the following certifications:
  • Cisco Certified Network Professional CCNP / Security
  • CompTIA Advanced Security Practitioner (CASP+)
  • Certified Information Systems Security Professional (CISSP)
  • Certified Secure Software Lifecycle Professional (CSSLP)
  • CISSP-Information Systems Security Engineering Professional (CISSP-ISSEP)
  • SANS GIAC Penetration Tester (GPEN)
  • Open Web Application Security Project Penetration Tester (OWASP)
  • Certified Ethical Hacker (CEH)
  • GIAC Certified Forensic Analyst (GCFA)
  • OffSec Certified Professional (OSCP)
  • OffSec Experienced Pentester (OSEP)
  • OffSec Web Assessor (OSWA)
  • Certified Professional Penetration Tester (eCPPT)
  • Web Application Penetration Tester (eWPT)
  • Web Application Penetration Tester eXtreme (eWPTX)
  • Hack the Box Certified Penetration Testing Specialist (HTB CPTS)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Assessor
Security Assessor

DataLock Consulting Group • Poland

Remote
PLN 210,000 - 296,000
Technical Manager
Technical Manager

DataLock Consulting Group • Poland

Remote
PLN 100,000 - 120,000
Competitive salary
Health insurance
Professional development opportunities
Application Security Engineer – Penetration Tester
Application Security Engineer – Penetration Tester

Jobtailor • Warszawa

On-site
PLN 120,000 - 180,000
Cybersecurity Vulnerability Analyst
Cybersecurity Vulnerability Analyst

ARHS • Warszawa

On-site
PLN 180,000 - 260,000
Offensive Security Engineer, Penetration Testing
Offensive Security Engineer, Penetration Testing

Procter & Gamble • Poland

On-site
PLN 180,000 - 260,000
Senior Penetration Tester
Senior Penetration Tester

Capgemini Polska • Wrocław, Gdańsk, Poznań

On-site
PLN 120,000 - 180,000
Senior Pentester (Security Engineer)
Senior Pentester (Security Engineer)

DEVTALENTS Sp. z o.o. • Województwo mazowieckie

On-site
PLN 80,000 - 100,000
Influence over security architecture
Supportive culture for professional growth
Penetration Tester
Penetration Tester

Atos • Bydgoszcz

Hybrid
PLN 120,000 - 170,000
Hybrid work model
Private medical care
Benefits platform
+4
Senior Penetration Testing Engineer IRC301690
Senior Penetration Testing Engineer IRC301690

GlobalLogic • Kraków

On-site
PLN 180,000 - 280,000
Empowering Projects
Empowering Growth
DE&I Matters
+3
Senior GRC Engineer
Senior GRC Engineer

DataLock Consulting Group • Poland

Remote
PLN 294,000 - 380,000
Competitive compensation
Comprehensive benefits package
Commitment to work-life balance