IT Security Specialist - Penetration Tester

Attainx,inc-

Silver Spring (MD)

Hybrid

USD 125,000 - 145,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Paid vacation
Medical
Dental
Vision
Matching 401K plan
Tuition/training reimbursement
Long & Short-Term Disability

Job summary

AttainX Inc. is seeking a seasoned IT Security Specialist – Penetration Tester to join our cyber security program supporting a U.S. federal government client.

The role requires hands-on testing across AWS, Azure and on‑prem environments, with strong experience in Burp Suite, Metasploit and RMF. Hybrid work in the Silver Spring area is expected, with US citizenship and Moderate Public Trust readiness. The ideal candidate will lead penetration testing efforts, report findings, and develop

Qualifications

  • A minimum of 5 years of proven penetration testing and ethical hacking experience.
  • Hands-on experience in penetration testing across AWS, Azure, and On-Premise environments.
  • 5+ years using IT security tools: Burp Suite, Metasploit, Wireshark.
  • 5+ years with enterprise architecture methodologies, concepts and tools.
  • 5+ years applying NIST guidance and contingency planning best practices.
  • 5+ years using tools like Tenable Security Center, ArcSight, IBM BigFix.
  • 5+ years conducting penetration tests or coordinating external testers.
  • 5+ years performing RMF assessments on Federal Information Systems.
  • Certifications: CISSP, CISA, GCIH, GSNA, CEH, CGRC, SCNP, SCNA.
  • Ability to multitask, manage projects, adapt to priorities, and work in a team.

Responsibilities

  • Perform protocol analysis, vulnerability discovery and exploitation, and post-exploitation impact analysis.
  • Analyze software architectures, security, protocols, virtualization and hardware with engineers to resolve issues.
  • Conduct manual and automated firmware analysis on target devices.
  • Carry out pen tests, fuzzing and custom exploits against client systems.
  • Review architectures and topologies for regulatory compliance and security mandates.
  • Produce security reports for regulatory bodies.
  • Conduct scenario-based security testing and red team activities to identify gaps.
  • Research and test in support of client requirements and security needs.
  • Design, integrate and support security solutions and company products.
  • Analyze information systems and implement protective measures against unauthorized access.

Skills

Penetration testing
AWS
Azure
On-Premise
Burp Suite
Metasploit
Wireshark
Enterprise architecture
NIST guidelines
Tenable Security Center
ArcSight
IBM BigFix
RMF
CISSP
CISA
GCIH
GSNA
CEH
CGRC
SCNP
SCNA
Multitasking
Project management
Adaptability
Team player

Education

Bachelor's degree in a related field

Tools

Burp Suite
Metasploit
Wireshark
Tenable Security Center
ArcSight
IBM BigFix

Job description

IT Security Specialist - Penetration Tester

Full Time Professional Silver Spring, MD, US


10 days ago Requisition ID: 1969


Salary Range: $125,000.00 To $145,000.00 Annually


Job Title: IT Security Specialist – Penetration Tester


Location: Hybrid (Reside within a commutable distance of Silver Spring, MD to work onsite as required)


Security Clearance: Moderate Public Trust


AttainX, Inc. is in search of a highly energetic Penetration Tester to join our team on a cyber security program supporting our US federal government client.


Are you a seasoned penetration tester with a passion for uncovering vulnerabilities and securing complex systems? We’re looking for a highly skilled and experienced professional with a minimum of 5 years of proven expertise in penetration testing and ethical hacking to join our team. In this role, you’ll take a hands-on approach to identify, exploit, and report security weaknesses across diverse environments, including AWS, Azure, and on-premises infrastructure. Your work will directly contribute to fortifying critical systems and protecting sensitive data from evolving cyber threats.


If you thrive in dynamic, high-stakes environments and excel at devising creative solutions to complex security challenges, we want to hear from you. Join us in our mission to build a safer digital future.


Qualifications and Education Requirements

Basic Qualifications


  • A minimum of 5 years of proven penetration testing and ethical hacking experience.

  • Hands-on experience in penetration testing across AWS, Azure, and On-Premise environments.

  • At least 5 years of recent experience (within the last 6 years) in applying IT security concepts, methodologies, principles, procedures and using industry-standard IT security tools (e.g. Burp Suite, Metasploit, Wireshark).

  • At least 5 years of recent experience (within the last 6 years) with enterprise architecture methodologies, concepts, procedures, principles, and tools.

  • At least 5 years of recent experience (within the last 6 years) in contingency planning and backup and recovery best practices and application of NIST guidance in this area.

  • At least 5 years of recent experience (within the last 6 years) in using technical testing tools (Tenable Security Center, ArcSight, IBM Big Fix, etc.).

  • At least 5 years of recent experience (within the last 6 years) in conducting penetration testing or the ability to bring in a penetration tester when required.

  • At least 5 years of performing assessments of Federal Information Systems using the Risk Management Framework.

  • Possess at least one of the following Certifications or be able to Obtain within six (6) months of hire:

  • Certified Information Systems Security Professional (CISSP).

  • Certified Information Systems Auditor (CISA).

  • GIAC Certified Incident Handler (GCIH).

  • GIAC Systems and Network Auditor (GSNA).

  • Electronic Commerce Council Certified Ethical Hacker (CEH).

  • ISC2 Certified in Governance, Risk and Compliance (CGRC).

  • Security Certified Network Professional (SCNP).

  • Security Certified Network Architect (SCNA).

  • Proficiency in handling multiple tasks concurrently.

  • Proficiency in project and time management.

  • Ability to adjust to changing priorities.

  • Ability to work in a cohesive team-oriented environment.

  • Must be a US Citizen able to obtain and maintain a Moderate Public Trust.


Preferred Qualifications


  • Knowledge of DOC, NOAA, and NWS IT security policies and implementation standards or those of similar sized organizations AND comprehensive understanding of NIST guidance toinclude NIST Special Publications and Federal Information Processing Standards.

  • Self-starter, highly motivated individual who adapts to a dynamic work environment.

  • Strong attention to detail with an ability to operate effectively across multiple priorities.


Education / Experience

Ideal for candidates with 5–7 years of hands‑on penetration testing experience who are looking to advance into intermediate‑level roles.


Skills

Duties

We are searching for Penetration Tester to support Security Assessment and Authorization initiatives for our Government client. Job duties include:



  • Protocol analysis, vulnerability discovery and exploitation, post exploitation impact analysis, and physical security.

  • Highly technical problem‑solver who understands software architectures, security, communication protocols, virtualization, and hardware, and work with other engineers to the resolution of problems in design, development, and operations.

  • Perform manual and automated firmware analysis on target devices.

  • Perform pen tests, fuzzing and custom exploit attacks against client systems.

  • Review deployment architectures, topologies and conops for compliance regulatory security mandates.

  • Produce security reports suitable for submission to regulatory bodies.

  • Conduct hands‑on technical testing beyond automated tool validation, including full exploitation and leveraging of access within multiple environments.

  • Conduct scenario‑based security testing, or red teaming to identify gaps in detection and response capabilities of client end systems.

  • Conducting research and testing in support of client requirements.

  • Designing, implementation, and integration of security solutions.

  • Designing, development and support of the company’s line of technology products.

  • Analyzes information security systems and applications.

  • Recommends and develops security measures to protect information against unauthorized modification or loss.

  • Familiar with a variety of the field’s concepts, practices, and procedures.

  • Relies on experience and judgment to plan and accomplish goals.

  • Performs a variety of complicated tasks.


Non‑Essential Functions


  • General Duty Requirements.


Work Location

Shall perform all functional and technical tasks remotely, hybrid work environment with occasional travel for client engagement, industry events, contract negotiations or at AttainX facility.


About Us

AttainX Inc. is SBA Certified 8(a), Women Owned Small Business (WOSB), Economically Disadvantaged WOSB (EDWOSB), CMMI Level 3, ISO 9001:2015 certified QMS and Silver Level SaFe Partner. For more than 12 years, AttainX, Inc. has delivered emergent technologies, software products, and high‑quality services that meet the needs of our Federal Government customers.


The last 4 years have shown significant company growth as we have increased our contracts portfolio and hold the “Best in Class” contract vehicles, GSA MAS and OASIS Small Business and 8(a) Pools 1, 2 and 3. In addition, we are prime on several Agency Specific IDIQ’s and BPA’s with the National Oceanic and Atmospheric Administration, Department of Energy, Navy, Health and Human Service and the Defense Intelligence Agency.


AttainX is dedicated to quality and best practices for the services we provide. We understand our people are the key ingredient to ensuring our customers Mission and Goals are met with excellence.



  • paid vacation

  • medical

  • dental

  • vision

  • matching 401K plan

  • tuition/training reimbursement

  • Long & Short-Term Disability.


EEO Commitment

AttainX is an equal employment opportunity employer, we are committed to providing a workplace that is free from discrimination based on Title VII of the Civil Rights Act, VEVRAA and Section 503, or other status protected by applicable federal, state, local, or international law. These protections also extend to applicants.


Accommodation

If you are an individual with a disability and would like to request a reasonable workplace accommodation, please send an email to AttainX HR indicating the specifics of the assistance needed.


Physical Demands

Sitting and working on a computer for long, continuous periods each day; effective communications by telephone, email, and face‑to‑face; standing, walking, and sitting; handling and feeling objects or controls; reaching; talking and hearing; lifting and/or moving up to 10 pounds; and specific vision abilities including close vision, distance vision, color vision, peripheral vision, depth perception, and the ability to adjust and focus.


Work Environment

The noise level in the work environment is usually moderate.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT Security Specialist - Penetration Tester
IT Security Specialist - Penetration Tester

Attainx Inc. • Silver Spring (MD)

On-site
USD 125,000 - 150,000
Competitive compensation package
Benefits package
Hybrid work arrangement
Cyber & A&A Security Specialist - Hybrid Remote
Cyber & A&A Security Specialist - Hybrid Remote

ATTAINX INC • Silver Spring (MD)

Hybrid
USD 98,000 - 110,000
Paid vacation
Medical, dental, and vision coverage
Matching 401(k) plan
+1
Cyber & A&A Security Specialist - Hybrid Remote
Cyber & A&A Security Specialist - Hybrid Remote

Attainx Inc. • Silver Spring (MD)

Hybrid
USD 98,000 - 110,000
Paid vacation
Medical, dental, and vision coverage
Matching 401(k) plan
+1
QA Tester
QA Tester

RiseMe • Columbus (OH)

On-site
USD 70,000 - 100,000
Medical benefits
Dental benefits
Vision benefits
+4
Cybersecurity Validation and Test Engineer
Cybersecurity Validation and Test Engineer

Amyx, Inc. • United States

On-site
USD 100,000 - 140,000
Medical, Dental, and Vision Plans
Flexible Spending Accounts (FSA)
Health Savings Account (HSA)
+4
Site Lead / Project Programmer (Construction)
Site Lead / Project Programmer (Construction)

ATTAINX INC • Herndon (VA)

On-site
USD 117,000 - 129,000
Competitive compensation and benefits
Vacation and health benefits
Tuition reimbursement and 401K
Cyber Security Manager
Cyber Security Manager

Point Blank Enterprises, Inc. • Pompano Beach (FL)

On-site
USD 100,000 - 130,000
Program Manager - Level IV
Program Manager - Level IV

Attainx,inc- • Herndon (VA)

Hybrid
USD 180,000 - 200,000
Competitive compensation package
Paid time off (PTO)
Health, dental, vision benefits
Information Systems Security Manager II
Information Systems Security Manager II

Amyx, Inc. • Springfield (VA)

On-site
USD 120,000 - 160,000
Medical, Dental, and Vision Plans
401(k) with matching
Wellness Program
+5
Site Lead / Project Programmer (Construction)
Site Lead / Project Programmer (Construction)

Attainx Inc • Colorado

On-site
USD 117,000 - 129,000
Paid vacation
Medical insurance
Dental insurance
+4