Today
Secret
Unspecified
Unspecified
IT - QA and Test
Remote/Hybrid• (Off-Site/Hybrid)
Who we are:
ShorePoint is a fast-growing, industry recognized, and award-winning cybersecurity services firm with a focus on high-profile, high-threat, private and public-sector customers who demand experience and proven security models to protect their data. ShorePoint subscribes to a "work hard, play hard" mentality and celebrates individual and company successes. We are passionate about our mission and going above and beyond to deliver for our customers. We are equally passionate about an environment that supports creativity, accountability, diversity, inclusion, and a focus on giving back to our community.
The Perks:
As recognized members of the Cyber Elite, we work together in partnership to defend our nation's critical infrastructure while building meaningful and exciting career development opportunities in a culture tailored to the individual technical and professional growth. We are committed to the belief that our team members do their best work when they are happy and well cared for. In support of this philosophy, we offer a comprehensive benefits package, including major carriers for health care providers. Highlighted benefits offered: 18 days of PTO, 11 holidays, 80% of insurance premium covered, 401k, continued education, certifications maintenance and reimbursement, etc.
Who we're looking for:
We are seeking a skilled Penetration Tester with experience conducting security assessments of web applications, mobile platforms, APIs, and client-side tools. The ideal candidate will have a strong background in penetration testing methodologies, proficiency in using industry-standard tools, and a proven ability to identify and remediate vulnerabilities. The Penetration Tester role involves working closely with clients and internal teams to enhance security posture and ensure compliance with federal standards. This is a unique opportunity to shape the growth, development, and culture of an exciting and fast-growing company in the cybersecurity market.
What you'll be doing:
What you need to know:
Must have's:
Beneficial to have the following:
Where it's done:
ShorePoint is a fast-growing, industry recognized, and award-winning cybersecurity services firm with a focus on high-profile, high-threat, private and public-sector customers who demand experience and proven security models to protect their data. ShorePoint subscribes to a "work hard, play hard" mentality and celebrates individual and company successes. We are passionate about our mission and going above and beyond to deliver for our customers. We are equally passionate about an environment that supports creativity, accountability, diversity, inclusion, and a focus on giving back to our community.
The Perks:
As recognized members of the Cyber Elite, we work together in partnership to defend our nation's critical infrastructure while building meaningful and exciting career development opportunities in a culture tailored to the individual technical and professional growth. We are committed to the belief that our team members do their best work when they are happy and well cared for. In support of this philosophy, we offer a comprehensive benefits package, including major carriers for health care providers. Highlighted benefits offered: 18 days of PTO, 11 holidays, 80% of insurance premium covered, 401k, continued education, certifications maintenance and reimbursement, etc.
Who we're looking for:
We are seeking a skilled Penetration Tester with experience conducting security assessments of web applications, mobile platforms, APIs, and client-side tools. The ideal candidate will have a strong background in penetration testing methodologies, proficiency in using industry-standard tools, and a proven ability to identify and remediate vulnerabilities. The Penetration Tester role involves working closely with clients and internal teams to enhance security posture and ensure compliance with federal standards. This is a unique opportunity to shape the growth, development, and culture of an exciting and fast-growing company in the cybersecurity market.
What you'll be doing:
- Conduct security assessments of web applications, mobile applications, databases, client-side tools, and APIs.
- Collaborate with team members and clients to define project scopes, develop business cases, review test results, and identify remediation steps.
- Perform risk analysis and root cause analysis for security findings.
- Use approved test protocols and procedures to perform network- and application-level penetration tests.
- Generate comprehensive reports with detailed findings, exploitation procedures, and mitigation strategies.
- Participate in client meetings, providing incremental progress updates, and addressing roadblocks or technical challenges.
- Attend client meetings to document findings, record technical interviews, and create detailed reports and memoranda.
- Execute script writing and payload crafting to simulate attacks and evaluate system security.
What you need to know:
- Strong knowledge of penetration testing methodologies and best practices for assessing system security.
- Familiarity with security assessment tools and techniques used in identifying vulnerabilities across networks, applications, and cloud technologies.
- General understanding of federal cybersecurity frameworks, compliance standards, and risk management principles.
- Proficiency in analyzing and communicating complex security findings to both technical and non-technical stakeholders.
Must have's:
- Demonstrated ability to apply critical thinking to develop undefined tasks into actionable processes and work streams.
- Experience using scanning tools like Nessus and Nmap, as well as penetration tools like the Kali Linux suite, Burp Suite and Metasploit.
- One or more of the following certifications: OSCP, OSWA, OSWE, CBBH, GWAPT or other relevant hands-on certification.
- Knowledge of FISMA and NIST 800 series standards.
- Ability to participate in cybersecurity control testing engagements for the customer's network, websites, applications, and cloud technologies.
- Proven experience in web application penetration testing.
- Experience in network mapping, vulnerability scanning, and penetration testing of web applications.
- Experience using approved test protocols and procedures to conduct network and application-level penetration tests.
- Experience attending client meetings, recording internal and technical client interviews and preserving the contents of reports and memoranda.
- Experience in script writing and crafting of payloads.
- Must be willing to travel as needed.
- Must be able to obtain and maintain a Secret Clearance.
Beneficial to have the following:
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Mathematics, Engineering or a related field.
Where it's done:
- Remote (Herndon, VA).
group id: 91085370