Senior Penetration Tester

Quzara LLC

Washington (District of Columbia)

Hybrid

USD 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Quzara LLC in Washington, DC is seeking a Senior Penetration Tester to lead advanced testing and vulnerability assessments. The role involves mentoring a team and utilizing expertise in web applications, cloud security, and various scripting languages.

With a full-time schedule, you will work both remotely and on-site, contributing to the organization’s mission of strengthening cybersecurity measures. Qualified applicants must have a Bachelor's degree in a related field and an OSCP+ certification.

Qualifications

  • 10+ years of experience in cybersecurity.
  • 7+ years of experience in penetration testing.
  • Expertise in various scripting languages.

Responsibilities

  • Execute advanced penetration testing methods for Web Applications.
  • Conduct vulnerability assessments on Azure cloud infrastructures.
  • Lead a team of penetration testers and provide mentorship.

Skills

Penetration Testing
Vulnerability Assessment
Web Application Testing
Scripting Languages (Python, SQL, etc.)
Communication Skills

Education

Bachelor's degree in Cyber Security, Computer Science, IT or related field
OSCP+ Certification

Tools

Kali Linux
BurpSuite
Wireshark

Job description

Job Title: Senior Penetration Tester

Pay Type: SALARIED EXEMPT

Location: Hybrid, Washington, DC

US Citizenship: Required

Summary

Quzara LLC, a SBA Certified WOSB, EDWOSB, and 8(a) cybersecurity firm, specializes in compliance advisory, cloud security, and managed security operations. Driven by innovation and dedication, our mission is to secure our clients' digital landscapes. Our services include Federal Security & Compliance, Vulnerability Management, Continuous Monitoring, Advanced Security Analytics, and Cloud Security, among others. Join our team and contribute to a culture of excellence and continuous improvement in the cybersecurity domain.

Essential Functions
  • Plan, create, and execute advanced penetration methods, scripts, and tests for the team, with a focus on Web Applications.
  • Assess and test the security of internal networks and underlying application infrastructure.
  • Conduct penetration testing and vulnerability assessments on Azure cloud infrastructure and applications.
  • Lead and mentor a team of penetration testers, providing guidance and sharing expertise.
  • Carry out remote and on-site testing of client networks and infrastructure to expose security weaknesses.
  • Simulate security breaches to assess a system's relative security.
  • Create detailed reports and recommendations based on findings, including uncovered security issues and associated risk levels.
  • Present findings, risk assessments, and conclusions to management and other relevant parties.
  • Maintain advanced knowledge of networking, cryptography, reverse engineering, web applications, operating systems, and databases.
  • Possess expertise in various scripting and programming languages, including Python, SQL, C/C++, JavaScript, PHP, Java, and Ruby.
  • Provide strong written and oral communication skills to effectively convey assessment results and potential weaknesses.
  • Assist in penetration testing intake, coordination with client teams for scheduling and delivery of reports/debriefs.
Marginal Functions
  • Other duties as assigned.
Normal Work Schedule

This is a full-time position. Standard business hours are Monday through Friday 8:00 AM to 5:30 PM. If your role falls within our Security Operations Center, you will be assigned a specific shift. As a result, your working schedule may require flexibility to cover any shift that falls within a 24/7 cycle, and it may also change and rotate, including nights, weekends, and holidays.

Education, Training, And Experience
  • Bachelor's degree in cyber security, computer science, IT or a related field and at least 10 years of experience in cybersecurity. Additional years of relevant experience may be considered in lieu of a Bachelor's degree.
  • 7 years minimum of work experience directly related to Red Team assessments, and penetration testing (intranet, internet, web, wireless, social engineering), with a focus on Web Application testing.
  • Must have an active OSCP+ certification in addition to one of the following:
    • CompTia PenTest+
    • CEH
    • CompTia CySa+
    • GCIH
    • GCFA
    • CISSP
  • Expertise with scripting languages (e.g., Python, PowerShell, Java, Perl, etc).
  • A fundamental understanding and experience with business/application logic vulnerabilities.
  • Expertise with API focused penetration testing.
  • Proficiency with penetration testing tools (Kali Linux, Binwalk, BurpSuite, Wireshark, etc).
  • Experience acting as a Subject Matter Expert or team lead, providing guidance to others.
  • Proven track record of reviewing cybersecurity vulnerabilities for risk and relevance.
  • Experience in planning mitigations for systems vulnerabilities.
  • Exceptional communication skills; able to successfully communicate with management personnel, technical personnel, and third parties.
Nice To Have
  • Certification focused on Web Application penetration testing.
    • eWPT, BSCP, etc.
  • Relevant security research.
    • Accredited CVEs, research papers or contributions to the cyber security sphere.
EEO Statement

The Company is an Equal Employment Opportunity (EEO) employer and does not discriminate based on race, color, religion, sex, sexual orientation, national origin, age, marital status, disability, veteran's status, or any other basis protected by applicable discrimination laws.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Penetration Tester | Red Team Lead (Hybrid DC)
Senior Penetration Tester | Red Team Lead (Hybrid DC)

Quzara LLC • Washington

Hybrid
USD 120,000 - 150,000
Penetration Tester
Penetration Tester

OVA.Work • New York (NY)

Hybrid
USD 110,000 - 180,000
Penetration Tester
Penetration Tester

WarCollar Industries, LLC • Herndon (VA)

On-site
USD 110,000 - 180,000
Medical insurance premium coverage
PTO based on billable hours
Federal holidays plus your birthday
+6
Penetration Tester
Penetration Tester

Phase2 Technology • Fort Meade (MD)

Hybrid
USD 86,000 - 198,000
Penetration Tester / Red Team Operator
Penetration Tester / Red Team Operator

Digital-Global-Connectors • McLean (VA)

Hybrid
USD 110,000 - 170,000
Penetration Tester
Penetration Tester

TalentFish • Illinois

Remote
USD 100,000 - 160,000
Vulnerability Management Engineer
Vulnerability Management Engineer

Quzara LLC • United States

Remote
USD 90,000 - 120,000
Penetration TesterWashington DC Metro Area
Penetration TesterWashington DC Metro Area

BuddoBot Inc. • Washington

On-site
USD 130,000 - 145,000
Penetration Tester
Penetration Tester

SteelToad • Dahlgren (VA)

On-site
USD 120,000 - 180,000
Medical insurance
Vision and dental insurance
Disability and life insurance
+6
Senior System Security Specialist
Senior System Security Specialist

Compunnel, Inc. • Baltimore (MD)

On-site
USD 120,000 - 150,000