- Location
- US
- Type
- Full-time
- Education
- Bachelor
- Visa
- Not sponsored
- Source
- ApplicantPro
Description
NikSoft Systems Corporation is a recognized Information Technology solutions provider. Founded in 1998 and based in Reston, Virginia, NikSoft is a CMMI Level 3 Certified company with an established reputation for excellence and on-time delivery with a consistently high customer satisfaction rating from its Federal Government and private consulting contracts.
NikSoft is currently conducting a search for a Penetration Tester to join our federal client's cyber security team. The successful candidate will experience an unparalleled large-scale enterprise environment with over 800 Information Technology systems, supporting billions of dollars in annual revenue, supporting a diverse user base spread across the entire US. Join the NikSoft team to scale up your career to the next level.
Responsibilities:
- The successful candidate will use both automated tools and manual techniques to test the security controls deployed at various points within Agency's information systems and networks.
- Penetration tester will be required to perform testing, document results, engage with stakeholders, conduct meetings, discuss findings, provide recommendations, explain testing techniques, and stay current on weaknesses and vulnerabilities which are announced both publicly and privately.
- The Penetration tester will perform in-depth testing, which may include exploitation of Agency's assets in order to determine the resiliency and permeability of Agency's networks and IT systems.
- Perform security testing of web applications, client/server applications, web services, APIs, operating systems, databases, and network fabric devices (i.e. switches, routers, firewalls, load balancers, WAPs, etc.).
- Provide technical security assessments of applications and infrastructure, security design reviews as well as risk assessments.
- Ensure current penetration testing tools are sufficient to the task of conducting penetration testing for Agency and regularly look for and recommend additional software that which may fill gaps in Agency's current security testing toolset.
Qualifications:
- Bachelor's degree in Computer Science or a related IT field.
- 7+ years of relevant experience in software development, cyber security, and testing.
- Highly skilled in web application testing, API testing, and network testing
- Prior experience with Burp Suite Professional, or other similar DAST tools
- Experience with AI and penetration testing AI
- Experience with Kali Linux and most of the tools available in the distro for penetration testing
- Experience with tools such as Metasploit Pro and Cobalt Strike for red team operations
- Experience with Red Team engagements from planning to execution
- Experience with phishing network users to gain access for lateral movement on the network
- Experience with Purple Team engagements to test monitoring controls in coordination with engineering teams and CSOC teams.
- Proficiency in scripting, such as Python and/or PowerShell
- Experience with penetration testing supporting PCI-DSS
- Technical writing skills, along with ease in communicating concepts related to security vulnerabilities and attack path scenarios.
- Familiar with OWASP Application Security Verification Standard (ASVS) and MITRE ATT&CK framework
- Penetration testing certification recommended. Acceptable certifications: Offensive Security Certified Professional (OCSP), Global Information Assurance Certification (GIAC) Certifications (e.g., GIAC Certified Penetration Tester (GPEN), GIAC Web Application Penetration Tester (GWAPT), or GIAC Exploit Researcher and Advanced Penetration Tester (GXPN))
****Candidates must be able to obtain a Postal Sensitive Clearance (US Citizenship or Green Card required). Additionally, candidates must not have traveled outside of the USA for a combined period exceeding 6 months within the last 3 years.***