Vulnerability Assessment Analyst and Penetration Tester

SteelToad

Annapolis (MD)

On-site

USD 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical Insurance
401(k) Plan with matching contributions
Paid Time Off
Professional Development Program
Professional Development Program

Job summary

A cybersecurity firm located in Annapolis, Maryland, seeks a Vulnerability Assessment Analyst and Penetration Tester to enhance security measures through continuous assessments and penetration testing. The ideal candidate will possess five years of hands-on experience with operating systems and security tools such as Burp Suite and Metasploit. Candidates must hold relevant certifications and have strong communication skills. This full-time position offers competitive benefits and a supportive work environment.

Qualifications

  • Five years of hands-on penetration testing experience.
  • Administrator-level knowledge of Windows and Linux Server.
  • Experience with security frameworks and testing tools.
  • Strong written and verbal communication skills.
  • Knowledge of network defense technologies, including ACLs, firewalls, IDS/IPS, EDR, and web content filtering.
  • Strong written and verbal communication skills, including explaining complex topics to non-technical audiences.
  • Onboarding certifications: OSCP or OSWA.
  • Acquire GXPN or OSEP within 9 months of onboarding.

Responsibilities

  • Conduct continuous cyber assessments to identify threats.
  • Perform application and hardware penetration testing.
  • Drive automation and tooling to enhance security capabilities.
  • Create threat mitigation plans.
  • Create threat mitigation plans.

Skills

Penetration testing
Operating systems knowledge
Security frameworks and tools
Communication skills
Mentoring

Education

Relevant cybersecurity certifications (OSCP, OSWA)

Tools

Burp Suite
Metasploit
Nessus
Kali Linux
Nessus
PowerShell Empire

Job description

Vulnerability Assessment Analyst and Penetration Tester

Position Description

The Vulnerability Assessment Analyst and Penetration Tester is responsible for the delivery of continuous cyber assessments, solving complex technology problems, building tools, and identifying and influencing response to and mitigation of threats. Perform manual assessment of systems, services, and software; specializing in security issues beyond those identified by static analysis tools. The individual ensures services, applications, and websites are designed and implemented to the highest security standards. Responsible for application and hardware penetration testing, automating repetitive tasks using various scripting languages, mentoring, and leading other engineers to deliver complex penetration tests and vulnerability assessments. The individual will be expected to drive automation, tooling, efficiency, and advance the team’s penetration testing capabilities. Responsible for creating threat mitigation plans.

Qualifications
  • Five years of hands‑on penetration testing experience with operating systems, web applications, and network infrastructure.
  • Administrator‑level knowledge of Windows and Linux Server operating systems.
  • Experience with operating system security.
  • Competent with testing frameworks and tools, such as Burp Suite, Metasploit, Cobalt Strike, Kali Linux, Nessus, PowerShell Empire.
  • Knowledge of the functionality and capabilities of computer network defense technologies, including router Access Control Lists (ACLs), firewalls, Intrusion Detection System (IDS)/Intrusion Prevention System (IPS), antivirus/Endpoint Detection and Response (EDR), and web content filtering.
  • Strong written and verbal communication skills, including the ability to explain complex technical topics to non‑technical audiences.
  • Possess one of the following certifications upon onboarding:
    • Offensive Security Certified Professional (OSCP)
    • Offensive Security Web Assessor (OSWA)
  • Obtain one of the following certifications within 9 months of onboarding:
    • GIAC Exploit Researcher and Advanced Penetration Tester (GXPN)
    • Offsec Experienced Penetration Tester (OSEP)
Reports To

Assigned Program Manager

Security Clearance Requirements

Secret

Travel Requirements

Travel is anticipated to be 10% - 15% within the Continental United States and 5% - 10% outside the Continental United States.

Benefits & Compensation
  • New employees are eligible to participate in the company’s benefits plan on their day of hire unless noted otherwise.
  • Medical Insurance
  • Long Term & Short-Term Disability, Group Life and AD&D Insurance – 100% Employer Paid
  • Health Savings Account
  • 401(k) Savings Plan – 100% match for the first 3% contributed plus 50% of the next 2% contributed. (no vesting period and eligibility is your date of hire).
  • Paid holidays – Eleven (11) per year
  • Paid Time Off – One hundred‑twenty (120) accrued hours per year
  • Professional Development Program
  • Salary will be determined based on the individual’s education and experience level
Overview

Lumbee Holdings is a leading provider of IT Support, Cybersecurity and Training and Development to the Department of Defense (DoD) and other government agencies.

Equal Employment Opportunity Policy Statement

It is the policy of Lumbee Tribe Holdings, Inc. and its subsidiaries (the “Company”) not to discriminate against any employee or applicant for employment because of race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, marital status, genetic information, mental or physical disability (and medical condition, for employees in California) or because he or she is a protected veteran. It is also the policy of the Company to take affirmative action to employ and to advance in employment, all persons regardless of race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, marital status, genetic information, mental or physical disability (and medical condition, for employees in California) or protected veteran status, and to base all employment decisions only on valid job requirements. This policy shall apply to all employment actions, including but not limited to recruitment, hiring, upgrading, promotion, transfer, demotion, layoff, recall, termination, rates of pay or other forms of compensation and selection for training, including apprenticeship, at all levels of employment.

Employees and applicants of the Company will not be subject to harassment on the basis of race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, marital status, genetic information, mental or physical disability (and medical condition, for employees of California) or because he or she is a protected veteran. Additionally, retaliation, including intimidation, threats, or coercion, because an employee or applicant has objected to discrimination, engaged or may engage in filing a complaint, assisted in a review, investigation, or hearing or have otherwise sought to obtain their legal rights under any Federal, State, or local EEO law is prohibited.

NOTE: These statements are intended to describe the general nature and level of work involved for this job. It is not an exhaustive list of all responsibilities, duties, and skills required of this job.

Seniority Level

Mid‑Senior level

Employment Type

Full‑time

Job Function

Business Development and Sales

Industries

Computer and Network Security

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Vulnerability Researcher
Cyber Vulnerability Researcher

SG2 Recruiting • California (MO)

On-site
USD 110,000 - 120,000
Cyber Vulnerability Researcher
Cyber Vulnerability Researcher

SG2 Recruiting • San Onofre (CA)

On-site
USD 110,000 - 120,000
Comprehensive benefits
On-site at Camp Pendleton
Cybersecurity Engineer
Cybersecurity Engineer

SG2 Recruiting • Oceanside (CA)

On-site
USD 110,000 - 120,000
Comprehensive benefits
Cybersecurity Engineer
Cybersecurity Engineer

SG2 Recruiting • California (MO)

On-site
USD 110,000 - 120,000
Penetration Tester
Penetration Tester

SteelToad • Dahlgren (VA)

On-site
USD 120,000 - 180,000
Medical insurance
Vision and dental insurance
Disability and life insurance
+6
System Security Engineer
System Security Engineer

Lumark Technologies, Inc. • Fairfax (VA)

On-site
USD 120,000 - 170,000
Health insurance
Dental insurance
Vision insurance
+2
Penetration Tester (RELOCATION BONUS AVAILABLE)
Penetration Tester (RELOCATION BONUS AVAILABLE)

BuddoBot Inc. • Ogden (UT)

Hybrid
USD 110,000 - 160,000
Vulnerability Researcher
Vulnerability Researcher

Lumbee Tribe Enterprises, Llc • California (MO)

On-site
USD 110,000 - 120,000
Cybersecurity and Vulnerability Management Systems Administrator
Cybersecurity and Vulnerability Management Systems Administrator

NexGen Data Systems • Columbus (OH)

On-site
USD 120,000 - 160,000
Premium health insurance for employee
401(k) match
Training & development program
+1
ME00629-System Vulnerability Analyst 4
ME00629-System Vulnerability Analyst 4

Momentum Engineering, Inc. • Fort Meade (MD)

On-site
USD 150,000 - 200,000
11 paid holidays
Minimum of 3 weeks PTO
Company sponsored group medical plan
+2