Penetration Tester - TS/SCI w/ Polygraph

Reposted 3 Days Ago
Be an Early Applicant
Annapolis Junction, MD
In-Office
Expert/Leader
Information Technology • Software • Cybersecurity • Automation
The Role
The Lead Penetration Tester will perform security assessments, including pentesting, incident response, and compliance formulation, while collaborating with teams to enhance network security.
Summary Generated by Built In

Location: Annapolis Junction, MD

Category: Penetration Tester
Travel Required: No
Remote Type: No
Clearance: TS/SCI w/ Polygraph

Penetration Tester

A Lead Penetration Tester is needed to join a high performing agile team using the Scaled Agile Framework (SAFe) methodology on a large, complex program that provides system engineering, development, test, integration and operational support. The selected individual will work on a team of cyber Subject Matter Experts (SMEs) who are providing support to a large, complex technical program for preventing, identifying, containing and eradicating cyber threats to networks through monitoring, intrusion detection, and protective security services on information systems including local area networks/wide area networks (LAN/WAN), commercial Internet connections, public facing websites, security devices, servers and workstations. She/he will be responsible for the overall security of Enterprise-wide information systems, and will collect, investigate, and report any suspected and confirmed security violations.

Primary Responsibilities

  • Perform internal and external pentests against systems to determine vulnerabilities and develop mitigation strategies.
  • Perform web app pentests.
  • Perform vulnerability risk assessments.
  • Perform physical pentests and social engineering analysis.
  • Perform cyber incident response as needed.
  • Evaluate the impact of new development on the operational security posture of IT systems.
  • Evaluate, review, and test critical software.
  • Formulate security compliance requirements for new system features.
  • Identify and remediate security issues throughout the system.
  • Audit and assess system security configuration settings using common methodologies and tools.
  • Work with development teams to enrich team-wide understanding of different types of vulnerabilities, attack vectors, and remediation approaches.
  • Work closely with System Engineering, Test Engineering, and Integration teams to ensure hardware and software architecture and implementations meet strict security requirements.
  • Propose, assess, coordinate, implement, and enforce information systems security policies, standards, and methodologies.
  • Serve as a Subject Matter Expert in security architecture, to include providing advice to Program Managers, Customer technical experts, and internal program teams.

Basic Qualifications

  • Must have experience with penetration testing tools.
  • Must have experience in web development and programming languages such as Java, XML, Perl and HTML.
  • Must have experience with programming/scripting in Python, Powershell, C, JavaScript, etc.
  • Must have extensive experience performing IT security risk assessments.
  • Must have experience performing web app and physical pentests.
  • Must have experience with or strong familiarity of the following Web Application tools; Burp Suite, Web Inspect, Appdetective.
  • Must have experience with or strong familiarity of Kali.
  • Must have experience with or strong familiarity of IPS/IDS solutions.
  • Must have a strong understanding of the Cyber Kill Chain methodology.
  • Must have experience applying Risk Management Framework.
  • Must have experience with secure configurations of commonly used desktop and server operating systems.
  • Must have the ability to effectively collaborate with technical staff and customers to form mitigation strategies and plan for continuous modernization and legacy integration.
  • Must have experience managing multiple projects simultaneously and quickly and effectively adjusting to shifting priorities in resolving issues.

Preferred Qualifications

  • Bachelor's degree in a technical/information assurance field and at least 12 years of relevant experience.
  • Certifications in one or more of the following areas strongly preferred:
    • GIAC Web Applications Penetration Tester (GWAPT)
    • GIAC Penetration Tester (GPEN)
    • Certified Ethical Hacker (CEH)
    • Certified Information Security Manager (CISM)
    • Certified Web Application Defender (GWEB)
    • Certified Information System Security Professional (CISSP)
  • Extensive experience developing/implementing integrated security services management processes, such as assessing and auditing network penetration testing, anti-virus planning assistance, risk analysis, and incident response.
  • Extensive experience providing information assurance support for application development that includes system security certifications and project evaluations for firewalls that encompass development, design, and implementation.​

Who We Are 

Sunayu, LLC serves as a premier technology partner to the Defense and Intelligence communities, delivering mission-critical engineering solutions across the nation. Our operations are anchored in a commitment to trust, accountability, and ethical transparency, ensuring the high-performance outcomes necessary to protect our country's most vital interests. 

Culture

Our strength lies in our community: Our team prioritizes collaboration, professional growth, and encourages open communication. At Sunayu, we don't just secure the mission—we grow together.

Career Development

We support and encourage our team members to continue their professional growth by providing company-reimbursed training and continuing education of up to $5,000 per year. We also participate in many industry conferences and events where we share our expertise and experiences.

Pay Rate

Salary range considers factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience, education/ training, key skills, as well as market and business considerations when extending an offer.


Benefits

  • 3 Medical Plan Options
  • Dental and Vision 
  • FSA, DCFSA, HSA
  • Life/AD&D Insurance
  • Short-Term & Long-Term Disability 
  • Employee Assistance Program (EAP)
  • Training and Educational Assistance
  • Paid Time Off (PTO)
  • 11 Federal holidays 
  • 401k plan with up to a 6% match (100% immediate vesting) 

Equal Opportunity Employer

Sunayu, LLC is an Equal Opportunity/Affirmative Action Employer.  All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, gender expression, national origin, age, protected veteran status, disability status, marital status, genetic information, medical condition, or any other characteristic protected by law.

Top Skills

Appdetective
Burp Suite
C
HTML
Ips/Ids
Java
JavaScript
Kali
Perl
Powershell
Python
Web Inspect
XML
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Annapolis Junction, Maryland
13 Employees
Year Founded: 2014

What We Do

Sunayu is the catalytic agent of engineering change helping company’s, both large and small mature and evolve their technological footprint to resolve their most complex and enduring obstacles.

We focus on a DevOps culture to implement and enhance infrastructure as code with specialties in cyber security and big data development. This methodology allows us to provide world class service to all of our customers. We foster a culture of innovation, hard teamwork, perseverance, balance and family.

Sunayu delivers innovative creativity using bleeding edge technology. We will re-envision and remodel your infrastructure by focusing on automation, deployment, system engineering, analytics development, configuration management, and information security.

Similar Jobs

Zscaler Logo Zscaler

Cyber Incident Response/Customer Security Operations - SkillBridge Intern

Cloud • Information Technology • Security • Software • Cybersecurity
Remote or Hybrid
Maryland, USA
8697 Employees

CrowdStrike Logo CrowdStrike

Manager, Software Engineering - Observability (Remote, EST)

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
23 Locations
10000 Employees
140K-215K Annually

CrowdStrike Logo CrowdStrike

Senior Back-end Engineer

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
24 Locations
10000 Employees
140K-215K Annually

CrowdStrike Logo CrowdStrike

Engineer II - Sensor (Remote)

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
35 Locations
10000 Employees
100K-145K Annually

Similar Companies Hiring

Standard Template Labs Thumbnail
Software • Information Technology • Artificial Intelligence
New York, NY
15 Employees
PRIMA Thumbnail
Travel • Software • Marketing Tech • Hospitality • eCommerce
US
15 Employees
Milestone Systems Thumbnail
Software • Security • Other • Big Data Analytics • Artificial Intelligence • Analytics
Lake Oswego, OR
1500 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account