Penetration Tester positions focus on delivering results in their domain. This page aggregates open Penetration Tester roles and what employers typically expect.
GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk. About GuidePoint Security GuidePoint Security is a leading cybersecurity solutions and services firm enabling federal government organizations to make smarter security decisions that minimize risk. With more than 800 vetted technology vendor partnerships and deep practitioner expertise across every major cybersecurity domain, GuidePoint serves more than half of the U.S. Government’s cabinet-level agencies across Civilian, DoD, and Intelligence Community segments, as well as Federal System Integrators and major defense prime contractors. We are growing our federal engineering team and looking for technically exceptional engineers who thrive at the intersection of federal mission and cybersecurity technology. The Pen Tester role will be responsible for performing comprehensive Risk and Vulnerability Analysis (RVA) assessments, functioning as penetration and purple team assessments. The role will be in response to performing penetration testing engagements using major frameworks like OWASP and NIST, against a range of technologies such as web applications, servers, operating systems, cloud services, AI workflows, and network devices. Onsite requirement (Candidates must reside within the Washington, D.C. metropolitan area) - This role supports a federal customer in Alexandria, VA. What You'll Get To Do: Perform analysis of submitted findings and vulnerabilities and provide a written report covering risk, likelihood of exploitation, and recommendations for remediation. Handle vetting of multiple vulnerabilities simultaneously, demonstrating efficiency and organization, to ensure all vulnerabilities are addressed in a timely manner. Swiftly confirm or deny the legitimacy of submitted vulnerabilities, ensuring rapid response times while maintaining the integrity of the vulnerability disclosure process. Provide insightful guidance and support to system owners regarding the agency's patching processes and timelines, helping them navigate and comply with these procedures. Ensure all findings and analyses are reported in a timely and efficient manner, maintaining a consistent flow of information and updates. Provide comprehensive start-to-finish RVA assessments, encompassing initial customer outreach, meticulous planning, thorough execution, and detailed reporting. Utilize expertise in assessing both current and emerging technology platforms and architectures, ensuring assessments are relevant and comprehensive. Conduct expert-level assessments using major frameworks like OWASP and NIST, covering a range of technologies such as web applications, servers, operating systems, cloud services, AI workflows, and network devices. Perform in-depth insider threat analysis, integrating it as a crucial part of the assessment process to identify potential internal security risks. Research and simulate emerging zero-day threats, creating mock-up scenarios to demonstrate the feasibility of exploitation and assess system vulnerabilities. Develop custom scripts for specialized exploitation scenarios, tailoring attack strategies to effectively test specific system vulnerabilities. Demonstrate hands-on experience with popular penetration testing software such as Meterpreter Pro, Nessus, and Cobalt Strike, using these tools to conduct thorough assessments. Analyze vulnerability scans and perform follow-on testing of systems to verify exploitability, ensuring comprehensive identification of security weaknesses. Conduct trend analysis across assessments to identify common vulnerabilities among disparate systems,…