|
Tharros supports the Department of Homeland Security (DHS) with cybersecurity services across its Intelligence Enterprise. In support of this mission, we have an immediate opportunity for a Senior Penetration Tester / Vulnerability Assessment Engineer. In this role you will identify, assess, and validate vulnerabilities across DHS Intelligence Enterprise cloud and on-premise systems through penetration testing, software assurance, and vulnerability assessment. You will emphasize manual, expert-driven techniques to find what automated tools miss and validate SOC detection and response. This position is on-site in a Government SCIF in Washington, DC. Duties include but not limited to:
- Perform penetration tests across the DHS IE portfolio using standard methodologies (e.g., MITRE ATT&CK, OWASP), from rules of engagement through exploitation, post-exploitation, and reporting.
- Use manual techniques to find vulnerabilities commonly missed by automated tools.
- Validate SOC incident response procedures through controlled testing.
- Perform software assurance through vulnerability and compliance testing of software requests; provide approval recommendations.
- Conduct source code reviews using automated tools and manual processes.
- Perform vulnerability assessments and supply chain risk management reviews.
- Maintain the security posture of the penetration testing kit.
- Update penetration testing, SCRM, and vulnerability assessment SOPs.
- BS degree in Information Technology, Cybersecurity, Information Systems, or Computer Science OR minimum of 10 years' experience in IT or cybersecurity.
- Minimum of 7 years' experience in penetration testing or vulnerability assessment.
- Active TS/SCI clearance and U.S. citizenship; willingness to undergo a DHS counterintelligence-scope polygraph.
- Knowledge of penetration testing methodologies and frameworks (e.g., MITRE ATT&CK, OWASP, PTES).
- Knowledge of software assurance and secure code review practices.
- Knowledge of common attack vectors across network, application, and cloud layers.
- Skill in manual exploitation using tools such as Burp Suite, Metasploit, or Core Impact.
- Skill in static code analysis using tools such as SonarQube or Fortify.
- Ability to write clear penetration test reports with recommended corrective actions.
- Proficient in Microsoft Office Suite to include Teams or similar workplace chat and videoconferencing tools.
- Excellent written and oral communications skills.
Desired
- OSCP, GPEN, GWAPT, CEH, or CISSP certification.
- Cloud (AWS, Azure) or Cross Domain Solution testing experience.
|