10 pentester jobs at 9 companies in Washington, DC
2mo
Save
Mark Applied
Hide
2mo
Senior Penetration Tester
Arlington, Virginia, United States
HybridFull Time
CoStar GroupNASDAQ: CSGP: Provides global real estate information, analytics, and online marketplaces.
6+ YOE6+ years in a technical role; 3+ years in penetration testing; Bachelor's in CS/Cybersecurity or related; web/API pentesting experience; security reporting; scripting in Python/PowerShell; security certifications.
GovCIO: Provides technology and mission support services to federal agencies.
10+ YOEHigh school with 10+ years experience; TS/SCI CI Poly; 10 yrs DoD cybersecurity RMF; cloud and data security; pentesting; DoD 8570.01-M IAT Level II.
RMF, Penetration testing, Vulnerability assessment, Cloud security, Data protection
CoStar GroupNASDAQ: CSGP: Global provider of commercial and residential real estate data.
6+ YOEBachelor's degree required; 6 years technical experience with at least 3 years in penetration testing; web/API pentesting, secure code review, scripting (Python/PowerShell), report writing, and security certifications (e.g., OSCP) required.
AttainX: Provides IT, cybersecurity, and program management services to federal agencies.
5+ YOEMinimum 5 years pentesting; AWS/Azure/On-Prem; 5+ years with security tools; CISSP/CISA/GCIH/GSNA/CEH/CGRC/SCNP/SCNA within 6 months; US citizen; Moderate Public Trust clearance.
Burp Suite, Metasploit, Wireshark, Tenable Security Center, ArcSight, IBM BigFix
Applied Research Associates: Provides scientific research and engineering solutions for complex problems.
2+ YOEBachelors or equivalent experience in cyber security, 2-4 years relevant defensive cyber experience, active Top Secret clearance with SCI eligibility, IAT II and CSSP Auditor certifications (Security+, CySA+, Pentest+), Linux and network analysis skills.
Virtru: Provides data-centric encryption and privacy control software for organizations.
4+ YOE4+ years in application security or secure development, strong cryptography and web security knowledge, experience with Node.js and Go, SAST/DAST/IAST/SCA tooling, vulnerability programs (bug bounty, pentest), and familiarity with cloud infra (GCP/AWS) and Kubernetes preferred.
Node.js, Go, Trusted Data Format (TDF), SAST, DAST, IAST, SCA, Burp, ZAP, Qualys, Nessus, GCP, AWS, Kubernetes, Slack, Zoom
SOSi: Provides technology and mission solutions for national security.
5+ YOE5-7 years pentest experience; red team; IoT/mobile/cloud testing; MITRE ATT&CK, OSSTMM, OWASP, NIST, PTES, ISSAF; Bachelor's; Certifications: GPEN or GXPN; CISA with AES HVA Lead/Technical Lead plus one of GRTP/CRTL/OSCP/CRTP/CMWAPT/CEPT/CPT/LPT; Secret clearance.
Peraton: National security and mission-critical government technology services provider.
1+ YOEBachelor's degree and 1 year of related experience or 4 additional years in lieu of degree; basic networking/security knowledge; evaluate configurations; identify vulnerabilities; use PenTesting tools (Metasploit, Burp Suite, Nmap); understand web vulnerabilities; perform root-cause analysis; able to work independently or in small teams; one of lis...