Penetration Tester

UltraViolet Cyber Remote

Company

UltraViolet Cyber

Location

Remote

Type

Full Time

Job Description

Make a difference here.


UltraViolet Cyber is a leading platform-enabled unified security operations company providing a comprehensive suite of security operations solutions. Founded and operated by security practitioners with decades of experience, the UltraViolet Cyber security-as-code platform combines technology innovation and human expertise to make advanced real-time cybersecurity accessible for all organizations by eliminating risks of separate red and blue teams.


By creating continuously optimized identification, detection, and resilience from today’s dynamic threat landscape, UltraViolet Cyber provides both managed and custom-tailored unified security operations solutions to the Fortune 500, Federal Government, and Commercial clients. UltraViolet Cyber is headquartered in McLean, Virginia, with global offices across the U.S. and in India. 


UltraViolet Cyber (UV Cyber) is seeking an experienced Penetration Tester with a background in Web & Mobile Application testing, Network, and Cloud Security related security assessments. This individual will play a key role in conducting penetration tests as one of the core capabilities of UltraViolet Cyber and in support of our growing customers base. We operate as a collaborative team, unified by integrity, passion, and communication.


The Penetration Tester will execute simulated attacks against client information technology systems to demonstrate susceptibility to such attacks by an adversary, similar to how an advanced persistent threat (APT) would attempt to breach into an organizations' information systems. Qualified candidates must be able to assess target systems, identify vulnerabilities, safely exploit those vulnerabilities, and effectively communicate the risk to the client.


US Citizenship required, and candidates must be willing to be submitted for a US Government background investigation.


No third-party candidates will be considered


Familiarity with Security Content Automation Protocols (SCAP), Common Vulnerabilities and Exposures (CVE), Common Vulnerability Scoring System (CVSS), Common Weakness Enumeration (CWE), or Common Platform Enumeration (CPE)


Understanding US Government Configuration Baseline (USGCB), Security Technical Implementation Guides (STIGs), NSA Guides, National Checklist Program (NCP) or Common Secure configurations

Work You'll Do:

  • Conduct mobile application, web application, Application Programming Interface (API), network, and cloud penetration tests.
  • Use common penetration testing and red-team tools, tactics, techniques, and procedures.
  • Analyze Proof of Concept (PoC) exploits to understand the underlying vulnerability and tailor the PoC to be safely used in target space.
  • Automate Red Teaming and Penetration Testing techniques, to efficiently scale offensive operations, using common scripting and programing languages (e.g. Golang, Python, JavaScript, Bash, PowerShell, etc.).
  • Conduct security assessments of cloud environments and application source code review.
  • Conduct penetration tests in accordance with standard methodologies (i.e. OWASP, NIST, PTES).
  • Utilize custom penetration testing tools, frameworks, and infrastructure.
  • Assess risk of discovered vulnerabilities based on likelihood and severity of exploitation.
  • Document and deliver technical reports on detailed findings and vulnerability remediation recommendations.
  • Collaborate with clients throughout an assessment on status and vulnerability information.
  • Evolve our capabilities and toolset

Penetration Testing in three (3) or more of the following:

  • Web Applications
  • External Networks
  • Internal Networks
  • Active Directory
  • Cloud Environments (e.g. AWS, Azure, GCP)

Tools / Services:

  • NMAP
  • BurpSuite
  • CrackMapExec
  • BloodHound
  • Ansible
  • Terraform
  • Git
  • AWS

What You Have:

  • Bachelor’s Degree in Cybersecurity or related field preferred
  • At least 2 years of experience related to conducting penetration tests or red-team assessments .
  • Offensive Security Certified Professional (OSCP) preferred but not required: OSCP experience and knowledge is highly preferred.
  • Experience performing SAST, DAST, and code reviews

UltraViolet Cyber maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect our company's differing products, services, industries and lines of business. Candidates are typically placed into the range based on the preceding factors.



We sincerely thank all applicants in advance for submitting their interest in this position. We know your time is valuable.


UltraViolet Cyber welcomes and encourages diversity in the workplace regardless of race, gender, religion, age, sexual orientation, gender identity, disability, or veteran status. 


If you want to make an impact, UltraViolet Cyber is the place for you! 

Apply Now

Date Posted

12/31/2024

Views

0

Back to Job Listings ❤️Add To Job List Company Info View Company Reviews
Positive
Subjectivity Score: 0.9

Similar Jobs

QA Analyst - Zowie

Views in the last 30 days - 0

Zowie is a company focused on enhancing customer experience through AI solutions They are trusted by top online brands for customer care efforts handl...

View Details

Security Analyst - Penetration Tester - The PNC Financial Services Group

Views in the last 30 days - 0

PNC is seeking a Security Analyst Penetration Tester for its Technology organization The role involves conducting automated and manual security testin...

View Details

Lead Security Engineer - Curai Health

Views in the last 30 days - 0

Curai Health an AIpowered virtual clinic is seeking a Lead Security Engineer to ensure infrastructure and operational security controls for HIPAA and ...

View Details

Director, Healthcare Sales - Pendulum

Views in the last 30 days - 0

Pendulum is a company revolutionizing health and wellness by focusing on the human microbiome They have developed proprietary probiotic pipelines and ...

View Details

Application Security Engineer II - Spring Health

Views in the last 30 days - 0

Spring Health is a leading mental healthcare provider partnering with over 450 companies to deliver bestinclass outcomes for their employees They offe...

View Details

Head of Global Travel, Sales - StackAdapt

Views in the last 30 days - 0

StackAdapt is a selfserve advertising platform specializing in multichannel solutions They are seeking a Head of Global Travel to lead sales efforts a...

View Details