Penetration Tester, Lead

Washington, DC
May 24, 2019
May 26, 2019
Full Time
Job Number: R0054170

Penetration Tester, Lead
The Challenge:

Everyone knows security needs to be "baked in" to a system architecture, but you actually know how to bake it in. You can identify and implement ways to harden systems and reduce their attack surface. What if you could use your Cyber penetration testing skills to lead the design and building of secure systems for the federal government? We're looking for a lead penetration tester, who can create solutions for a large government agency that will stand up to even the most advanced Cyber threats.

As a lead penetration tester on our project, you'll lead a Red team to identify gaps in detection and response capabilities of client networks. You'll coordinate work with a senior-level client and internal leadership to identify the right mix of tools and techniques to translate your customer's IT needs and future goals into a plan that will enable secure and effective solutions. We need to come up with the best solution, so you'll advise on new techniques, break free from the legacy model, and go where the industry is going. You'll lead the team through a critical approach to network design, providing alternatives and customizing solutions to maintain a balance of security and mission needs. This is a chance to lead a team of experts to make a difference in the security of our client's network and applications. You'll lead efforts to help customers overcome their most difficult challenges by integrating secure practices like identifying vulnerabilities and creating security testing standards via offensive detection methods. You'll broaden your skillset into areas like C-Suite advisory and project management specifically, within network vulnerability assessments, Web app security testing, and network pen testing. while building piece of mind in a critical infrastructure. As a technical leader, you'll identify new opportunities to use Cybersecurity solutions to help your customers meet their toughest challenges. Become a leader on our team as we improve our client's defense against outside threats through Cybersecurity.

Empower change with us.

Build Your Career:

Rewarding work, fun challenges, and a ton of investment in our people-that's Booz Allen cyber. When you join Booz Allen, we'll help you develop the career you want.

Competitions - From programming competitions at our PyNights (Python competition and learning events) to competing in CTFs, we've got plenty of chances for you to show off your skills.

Paid Research - Have an innovative idea to explore or hypothesis to test? You can participate in challenges via our crowdsourcing platform, the Garage, and other programs to be awarded dedicated time and/or funding to advance your skills.

Cyber University - CyberU has more than 5000 instructor-led and self-paced cyber courses, a free online library that you can access from just about anywhere-including your phone-and certification exam prep guides that include practical assessments to prepare you for your exam.

Academic Partnerships - In addition to our tuition reimbursement benefit, we've partnered with University of Maryland University College to offer two graduate certificate programs in cybersecurity-fully funded without a tuition cap.

Maker/Hackerspaces - Race drones, print 3D gadgets, drink coffee from our Wi-Fi coffee maker, and get hands-on training on tools and tech from in-house experts in our dedicated maker and hackerspaces.

You Have:

-3+ years of experience with performing hands on Web application security testing, network penetration testing, and network vulnerability assessments

-Experience with Metasploit, BeEF, or Nessus and

-Experience with a database scanner, including Imperva, Guardium, or AppDetective

-Experience with at least one of the following: Java, JavaScript, Perl, Python, Ruby, Bash, C or C++, C#, PHP, or SQL

-Experience with Windows and NIX environments, applications, database, and Web server design, HTML, and implementation

-Knowledge of Burp Suite Pro and Kali Linux tools relevant to penetration testing

-Knowledge of open security testing standards and projects, including OWASP

-Ability to conduct a Web app pen test without the use of a vulnerability scanner or exploit framework using a browser, proxy, and editor

-Ability to obtain a security clearance required

-BA or BS degree

Nice If You Have:

-Experience with wireless LAN security, including 802.11 standards

-BS degree in Computer Engineering, CS, or a technical field preferred

-Offensive Security Web Expert (OSWE) or SANS GIAC Web Application Penetration Tester (GWAPT) Certification

-SANS GIAC GCIH, GPEN, GCFE, GREM, GPYC, Offensive Security OSCP, OSCE, OSEE, OSWP, AWS, or CCSP Certification

-SANS Certification


Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information.

We're an EOE that empowers our people-no matter their race, color, religion, sex, gender identity, sexual orientation, national origin, disability, veteran status, or other protected characteristic-to fearlessly drive change.

Similar jobs