Senior Software Assurance and Vulnerability Assessment Engineer

ANALYGENCE

Washington (District of Columbia)

On-site

USD 120,000 - 190,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Tharros in Washington, DC is seeking a Senior Software Assurance and Vulnerability Assessment Engineer to identify, assess, and validate vulnerabilities across DHS Intelligence Enterprise cloud and on-premise systems through penetration testing, software assurance, and vulnerability assessment.

The role emphasizes manual, expert-driven techniques, SOC validation, source code reviews, and ongoing SOP updates, with on-site work in a Government SCIF.

Qualifications

  • BS degree or 10+ years IT/cybersecurity experience.
  • 7+ years' experience in penetration testing or vulnerability assessment.
  • Active TS/SCI clearance and U.S. citizenship; willingness to undergo a DHS counterintelligence-scope polygraph.
  • Knowledge of penetration testing methodologies and frameworks (e.g., MITRE ATT&CK, OWASP, PTES).
  • Knowledge of software assurance and secure code review practices.
  • Knowledge of common attack vectors across network, application, and cloud layers.
  • Skill in manual exploitation using tools such as Burp Suite, Metasploit, or Core Impact.
  • Skill in static code analysis using tools such as SonarQube or Fortify.
  • Ability to write clear penetration test reports with recommended corrective actions.
  • Proficient in Microsoft Office Suite to include Teams or similar workplace chat and videoconferencing tools.
  • Excellent written and oral communications skills.

Responsibilities

  • Perform penetration tests across the DHS IE portfolio using standard methodologies (e.g., MITRE ATT&CK, OWASP), from rules of engagement through exploitation, post-exploitation, and reporting.
  • Use manual techniques to find vulnerabilities commonly missed by automated tools.
  • Validate SOC incident response procedures through controlled testing.
  • Perform software assurance through vulnerability and compliance testing of software requests; provide approval recommendations.
  • Conduct source code reviews using automated tools and manual processes.
  • Perform vulnerability assessments and supply chain risk management reviews.
  • Maintain the security posture of the penetration testing kit.
  • Update penetration testing, SCRM, and vulnerability assessment SOPs.

Skills

Penetration testing
Vulnerability assessment
Report writing
Communication skills
Manual testing

Education

Bachelor degree in IT/Cybersecurity/IS/CS
10+ years IT/cybersecurity experience

Tools

Burp Suite
Metasploit
Core Impact
SonarQube
Fortify

Job description

Tharros supports the Department of Homeland Security (DHS) with cybersecurity services across its Intelligence Enterprise.

In support of this mission, we have an immediate opportunity for a Senior Software Assurance and Vulnerability Assessment Engineer. In this role you will identify, assess, and validate vulnerabilities across DHS Intelligence Enterprise cloud and on-premise systems through penetration testing, software assurance, and vulnerability assessment. You will emphasize manual, expert-driven techniques to find what automated tools miss and validate SOC detection and response. This position is on-site in a Government SCIF in Washington, DC.

  • Perform penetration tests across the DHS IE portfolio using standard methodologies (e.g., MITRE ATT&CK, OWASP), from rules of engagement through exploitation, post-exploitation, and reporting.
  • Use manual techniques to find vulnerabilities commonly missed by automated tools.
  • Validate SOC incident response procedures through controlled testing.
  • Perform software assurance through vulnerability and compliance testing of software requests; provide approval recommendations.
  • Conduct source code reviews using automated tools and manual processes.
  • Perform vulnerability assessments and supply chain risk management reviews.
  • Maintain the security posture of the penetration testing kit.
  • Update penetration testing, SCRM, and vulnerability assessment SOPs.
  • BS degree in Information Technology, Cybersecurity, Information Systems, or Computer Science OR minimum of 10 years' experience in IT or cybersecurity.
  • Minimum of 7 years' experience in penetration testing or vulnerability assessment.
  • Active TS/SCI clearance and U.S. citizenship; willingness to undergo a DHS counterintelligence-scope polygraph.
  • Knowledge of penetration testing methodologies and frameworks (e.g., MITRE ATT&CK, OWASP, PTES).
  • Knowledge of software assurance and secure code review practices.
  • Knowledge of common attack vectors across network, application, and cloud layers.
  • Skill in manual exploitation using tools such as Burp Suite, Metasploit, or Core Impact.
  • Skill in static code analysis using tools such as SonarQube or Fortify.
  • Ability to write clear penetration test reports with recommended corrective actions.
  • Proficient in Microsoft Office Suite to include Teams or similar workplace chat and videoconferencing tools.
  • Excellent written and oral communications skills.
Desired
  • OSCP, GPEN, GWAPT, CEH, or CISSP certification.
  • Cloud (AWS, Azure) or Cross Domain Solution testing experience.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Software Assurance and Vulnerability Assessment Engineer
Senior Software Assurance and Vulnerability Assessment Engineer

Jimmy Jazz • Washington

On-site
USD 140,000 - 200,000
Senior Penetration Tester / Vulnerability Assessment Engineer
Senior Penetration Tester / Vulnerability Assessment Engineer

Cybersecurity Jobs • Washington

On-site
USD 180,000 - 230,000
Senior Software Assurance & Vulnerability Engineer
Senior Software Assurance & Vulnerability Engineer

Jimmy Jazz • Washington

On-site
USD 140,000 - 200,000
Senior Software Assurance & Penetration Testing Engineer
Senior Software Assurance & Penetration Testing Engineer

ANALYGENCE • Washington

On-site
USD 120,000 - 190,000
Senior Security Control Assessor
Senior Security Control Assessor

ANALYGENCE • Washington

On-site
USD 140,000 - 170,000
Security Control Assessor
Security Control Assessor

ANALYGENCE • Washington

On-site
USD 120,000 - 180,000
Junior Security Control Assessor
Junior Security Control Assessor

ANALYGENCE • Washington

On-site
USD 65,000 - 90,000
Junior Security Control Assessor
Junior Security Control Assessor

Jimmy Jazz • Washington

On-site
USD 70,000 - 100,000
Junior Security Engineer
Junior Security Engineer

ANALYGENCE • Washington

On-site
USD 75,000 - 110,000
Senior Security Control Assessor
Senior Security Control Assessor

Jimmy Jazz • Washington

On-site
USD 120,000 - 150,000