Senior Software Assurance and Vulnerability Assessment Engineer

Jimmy Jazz

Washington (District of Columbia)

On-site

USD 140,000 - 200,000

Full time

9 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Tharros, a cybersecurity services provider, seeks a Senior Software Assurance and Vulnerability Assessment Engineer for on-site work in a Government SCIF, Washington, DC. The role focuses on identifying and validating vulnerabilities through penetration testing, software assurance, and vulnerability assessment across DHS Intelligence Enterprise cloud and on-premises systems.

Requirements include a TS/SCI clearance, a BS degree or 10+ years in IT/cyber, and 7+ years in relevant testing.

Qualifications

  • BS degree or 10+ years in IT/cybersecurity
  • Minimum 7 years in penetration testing or vulnerability assessment
  • Active TS/SCI clearance and US citizenship; willing to take DHS polygraph
  • Knowledge of MITRE ATT&CK and OWASP frameworks
  • Knowledge of software assurance and secure code review practices
  • Knowledge of attack vectors across network, application, and cloud layers
  • Experience with manual exploitation using Burp Suite, Metasploit, or Core Impact
  • Proficient with MS Office; strong written and oral communication
  • Certifications: OSCP/GPEN/GWAPT/CEH/CISSP
  • Cloud testing experience (AWS/Azure) or Cross Domain Solution testing

Responsibilities

  • Perform penetration tests across DHS IE portfolio using standard methodologies
  • Use manual techniques to identify vulnerabilities overlooked by automated tools
  • Validate SOC incident response through controlled testing
  • Conduct software assurance via vulnerability and compliance testing of software requests
  • Perform source code reviews using automated tools and manual processes
  • Carry out vulnerability assessments and supply chain risk reviews
  • Maintain the penetration testing kit and update SOPs

Skills

Penetration testing
Vulnerability assessment
Software assurance
Secure code review
SOC validation

Education

B.S. in IT/Cybersecurity/IS/CS

Tools

Burp Suite
Metasploit
Core Impact
SonarQube
Fortify

Job description

  • Location 1790 Ash Street Southeast,Washington, DC, 20032,United States
  • Employee Type Regular Full-Time
  • Required Degree 4 Year Degree
Contact information
  • Name Talent Acquistion
  • Email recruiting@tharros.com
Description

Tharros supports the Department of Homeland Security (DHS) with cybersecurity services across its Intelligence Enterprise.

In support of this mission, we have an immediate opportunity for a Senior Software Assurance and Vulnerability Assessment Engineer. In this role you will identify, assess, and validate vulnerabilities across DHS Intelligence Enterprise cloud and on-premise systems through penetration testing, software assurance, and vulnerability assessment. You will emphasize manual, expert-driven techniques to find what automated tools miss and validate SOC detection and response. This position is on-site in a Government SCIF in Washington, DC.

  • Perform penetration tests across the DHS IE portfolio using standard methodologies (e.g., MITRE ATT&CK, OWASP), from rules of engagement through exploitation, post-exploitation, and reporting.
  • Use manual techniques to find vulnerabilities commonly missed by automated tools.
  • Validate SOC incident response procedures through controlled testing.
  • Perform software assurance through vulnerability and compliance testing of software requests; provide approval recommendations.
  • Conduct source code reviews using automated tools and manual processes.
  • Perform vulnerability assessments and supply chain risk management reviews.
  • Maintain the security posture of the penetration testing kit.
  • Update penetration testing, SCRM, and vulnerability assessment SOPs.
Requirements
  • BS degree in Information Technology, Cybersecurity, Information Systems, or Computer Science OR minimum of 10 years' experience in IT or cybersecurity.
  • Minimum of 7 years' experience in penetration testing or vulnerability assessment.
  • Active TS/SCI clearance and U.S. citizenship; willingness to undergo a DHS counterintelligence-scope polygraph.
  • Knowledge of penetration testing methodologies and frameworks (e.g., MITRE ATT&CK, OWASP, PTES).
  • Knowledge of software assurance and secure code review practices.
  • Knowledge of common attack vectors across network, application, and cloud layers.
  • Skill in manual exploitation using tools such as Burp Suite, Metasploit, or Core Impact.
  • Skill in static code analysis using tools such as SonarQube or Fortify.
  • Ability to write clear penetration test reports with recommended corrective actions.
  • Proficient in Microsoft Office Suite to include Teams or similar workplace chat and videoconferencing tools.
  • Excellent written and oral communications skills.
  • OSCP, GPEN, GWAPT, CEH, or CISSP certification.
  • Cloud (AWS, Azure) or Cross Domain Solution testing experience.
Summary

Tharros combines extensive cyber defense knowledge with the world’s preeminent vulnerability expertise to identify and defend against attacks before they become problems. Working at mission speed, we harden mission systems faster and secure them for longer, so agencies never lose the mission edge. Tharros lifts the veil of enterprise cybersecurity to detect zero days before they affect you, enabling mission maneuverability and the confidence to move missions forward.

In the ever-evolving realm of cyberspace, we are dedicated to becoming the paramount defender in the 5th warfighting domain. By pioneering innovative security solutions and fostering an environment of continuous learning and vigilance, we aim to protect the interests of our nation’s security. Our commitment to excellence in cybersecurity will establish new benchmarks, transforming the digital landscape into a secure and thriving frontier for future generations.

Tharros. See Everything. Secure Anything.

Tharros is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Opportunity/Affirmative Action Employer and make employment decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected status.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Control Assessor
Senior Security Control Assessor

Jimmy Jazz • Washington

On-site
USD 120,000 - 150,000
Junior Security Engineer
Junior Security Engineer

Jimmy Jazz • Washington

On-site
USD 90,000 - 130,000
Junior Security Control Assessor
Junior Security Control Assessor

Jimmy Jazz • Washington

On-site
USD 70,000 - 100,000
IT Security Operations Specialist
IT Security Operations Specialist

Jimmy Jazz • Washington

On-site
USD 90,000 - 130,000
Security Governance and Policy Analyst
Security Governance and Policy Analyst

Jimmy Jazz • Washington

On-site
USD 120,000 - 170,000
Junior Information System Security Officer, National Vetting Center
Junior Information System Security Officer, National Vetting Center

Jimmy Jazz • Washington

On-site
USD 90,000 - 120,000
Senior Penetration Tester / Vulnerability Assessment Engineer
Senior Penetration Tester / Vulnerability Assessment Engineer

Cybersecurity Jobs • Washington

On-site
USD 180,000 - 230,000
Junior Information System Security Officer
Junior Information System Security Officer

Jimmy Jazz • Washington

On-site
USD 80,000 - 110,000
Senior Software Assurance & Vulnerability Engineer
Senior Software Assurance & Vulnerability Engineer

Jimmy Jazz • Washington

On-site
USD 140,000 - 200,000
Information Security Analyst
Information Security Analyst

Jimmy Jazz • Maryland

On-site
USD 90,000 - 120,000