Senior Penetration Tester Job at ANALYGENCE Inc, Washington DC

  • ANALYGENCE Inc
  • Washington DC

Job Description

Description

Tharros is seeking a Senior Penetration Testing, Software Assurance and Vulnerability Assessment Engineer to support a DHS Intelligence and Analysis cybersecurity program in the National Capital Region.


This role will support advanced penetration testing, software assurance, vulnerability assessment, cyber supply chain risk management, secure cloud and hybrid engineering, and cross-domain security assessment activities. The ideal candidate is a senior technical assessor who can go beyond automated scanning to identify systemic weaknesses, validate exploitability, assess operational impact, and provide clear remediation recommendations for complex mission environments.


Responsibilities:

  • Conduct penetration testing, vulnerability assessments, software assurance, and cyber supply chain risk management activities for Federal mission systems.
  • Perform full-scope security testing using established methodologies such as MITRE ATT&CK, OWASP, NIST 800-115, and related Federal or IC assessment practices.
  • Support pre-engagement planning, rules of engagement, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting.
  • Use approved automated and manual testing methods to identify vulnerabilities, validate exploitability, and assess potential business and operational impacts.
  • Identify vulnerabilities commonly missed by automated tools through manual, expert-driven testing techniques.
  • Assess SOC detection and response capabilities through controlled testing activities.
  • Produce penetration testing reports, vulnerability assessment reports, software assurance recommendations, and corrective action guidance.
  • Support software assurance through vulnerability and compliance testing, source code review, static/dynamic analysis, dependency review, and software supply chain risk identification.
  • Conduct vulnerability assessments and interpret results to recommend corrective actions and mitigation strategies.
  • Support secure cloud, hybrid, DevSecOps, application, identity, API, microservices, CI/CD, Zero Trust, and cross-domain assessment activities.
  • Maintain secure testing kits and assessment tooling, including patching, configuration updates, and approved tool management.
  • Update and maintain penetration testing, SCRM, and vulnerability assessment procedures.
  • Support audits, working groups, and stakeholder briefings related to penetration testing, software assurance, vulnerability assessment, and cyber supply chain risk.
  • Identify opportunities to improve testing processes, automate assessment workflows, strengthen reporting, and produce useful metrics for leadership and technical stakeholders.
  • Translate assessment findings into actionable remediation plans, risk insights, POA&M inputs, dashboards, and decision-ready reporting.
Requirements
  • Active TS/SCI w Poly
  • 10+ years of related cybersecurity assessment, penetration testing, software assurance, vulnerability assessment, or cyber supply chain risk experience.
  • 2+ years of recent experience in each of the following areas: software assurance, penetration testing with automated tools, vulnerability assessment, security patch management, secure cloud and hybrid engineering, and
  • Cross Domain Solutions.
  • CEH and CISSP certifications, or comparable demonstrable experience.
  • Experience conducting penetration testing, vulnerability assessments, software assurance, source code review, SCRM, and cyber supply chain management activities.
  • Experience using both automated tools and manual testing processes to identify, validate, and document vulnerabilities.
  • Experience producing technical reports, corrective action recommendations, mitigation strategies, and executive-ready summaries.
  • Strong understanding of vulnerability management, exploitability, secure configuration, remediation validation, and operational risk.
  • Strong written and verbal communication skills.
  • Ability to work onsite at a government-approved location as required.
Preferred Qualifications:
  • Prior DHS, Intelligence Community, DoD, CISA, classified red team, software assurance, SCRM, CVPA, vulnerability research, or national security cyber assessment experience.
  • Experience with MITRE ATT&CK, OWASP, NIST 800-115, IC "Raise the Bar," NIST SP 800-161, CNSSI 1253, DHS 4300C, or related Federal/IC cybersecurity frameworks.
  • Experience testing cloud, application, identity, API, microservices, CI/CD, DevSecOps, Zero Trust, cross-domain, and hybrid TS/SCI environments.
  • Experience with SBOM analysis, static/dynamic code analysis, dependency review, source code review, exploit validation, secure configuration, and remediation validation.
  • Experience with GRC platforms such as Archer, eMASS, or Xacta, including the ability to translate findings into POA&Ms, dashboards, scorecards, and remediation workflows.

Job Tags

Similar Jobs

Impleo

Animator Job at Impleo

 ...gameplay mechanics to life through expressive, high-quality 3D animation. The Game Animator will collaborate closely with animators, artists...  ....-based full-time project hires.Paid time off.Paid holidays.Remote work opportunity within the United States.Opportunity to... 

Tx-Star Speech Language Services

Orientation and Mobility Specialist Job at Tx-Star Speech Language Services

 ...provide specialized educational services for students with a wide range of learning needs. We are currently seeking Orientation and Mobility Specialists for school-based assignments across Texas. These opportunities are well suited for professionals who are committed... 

Harry Buffalo

BAR MANAGER Job at Harry Buffalo

 ...Bar Manager We are searching for a committed, proactive bar manager who would enjoy work in an exciting, fast-paced environment. The bar manager will train and guide staff to build food and beverage sales that meet or exceed budgeted guidelines. Promote excellent service... 

Catholic Health Service

Blood Bank Supervisor Job at Catholic Health Service

 ...utilize evidence based practice to improve outcomes - to every patient, every time. Job Details Position Summary The Blood Bank Supervisor, under the direction of the Laboratory Director and Technical Supervisor, oversees the daily operations of the Blood Bank... 

Barclays

Penetration Tester, AVP Job at Barclays

 ...Penetration Tester, AVP To identify potential vulnerabilities within the banks IT systems using penetration testing tools and techniques to ensure security of computer systems, applications, servers, and networks. Accountabilities Development and execution...