Job
- Level
- Erfahren
- Job Feld
- IT, Security
- Anstellung
- Vollzeit
- Vertragsart
- Unbefristetes Dienstverhältnis
- Gehalt
- 80.000 bis 128.000€ Brutto/Jahr
- Ort
- Wiesbaden
- Arbeitsmodell
- Onsite
Job Zusammenfassung
In dieser Rolle führst du Sicherheitsbewertungen und Penetrationstests durch, nutzt OWASP-Methoden zur Identifikation von Schwachstellen und unterstützt bei der Risikoanalyse und Umsetzung von Abhilfe-Maßnahmen.
Job Technologien
Deine Rolle im Team
- Conduct vulnerability assessments and penetration tests against USAREUR-AF network infrastructure, endpoints, and applications in support of CSSP assessment missions (NAVs and PPTs).
- Perform web application security testing using OWASP methodology and tools including Burp Suite and OWASP ZAP, identifying and validating vulnerabilities across mission partner web services.
- Execute Active Directory and Linux security assessments to identify privilege escalation paths, credential exposure risks, and lateral movement opportunities within target environments.
- Utilize penetration testing frameworks including Metasploit and Burp Suite to safely exploit validated vulnerabilities and demonstrate risk to mission owners in a controlled manner.
- Document all assessment findings in structured reports, including vulnerability descriptions, evidence screenshots, CVSS risk ratings, and actionable remediation recommendations.
- Support mission owners and network defenders with post-assessment remediation guidance, answering technical questions and providing clarification on findings to facilitate effective risk reduction.
Unsere Erwartungen an dich
Ausbildung
- Bachelors degree and a minimum of 5 years of penetration testing or vulnerability assessment experience.
- Associate's degree + 7 years specialized experience; or 11 years of experience (no degree).
Qualifikationen
- DoW 8140 - Cybersecurity (Vulnerability Analyst) - Intermediate.
- Certifications - must hold active certifications (one of the following): TCM Security PNPT; HTB CPTS (Hack The Box Certified Penetration Testing Specialist); Zero Point Security RTO (Red Team Ops); OSCP (Offensive Security Certified Professional); OSCE (Offensive Security Certified Expert); GPEN (GIAC Penetration Tester); GWAPT (GIAC Web Application Penetration Tester); GAWN (GIAC Assessing and Auditing Wireless Networks); GXPN (GIAC Exploit Researcher and Advanced Penetration Tester); GWEB (GIAC Certified Web Application Defender).
- U.S. citizenship required.
- Active DoW TS/SCI clearance.
- Proficiency with Burp Suite Pro for manual and automated web application security testing.
- Familiarity with OWASP ZAP for web vulnerability scanning and validation.
- Working knowledge of BloodHound for Active Directory enumeration and attack path analysis.
- Scripting proficiency in Python, Bash, or PowerShell for custom tool development and test automation.
- Familiarity with vulnerability scoring frameworks (CVSS) and risk-based reporting methodologies.
Erfahrung
- Hands-on experience with Metasploit Framework for vulnerability exploitation and post-exploitation activities.
- Experience with Nmap and Nessus/OpenVAS for network discovery and vulnerability scanning.
- Experience with vulnerability management platforms (e.g., Tenable.sc, Rapid7 InsightVM).
Unser Angebot
- Target Salary Range: $80,000 - $128,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual's experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations.
- Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.
- Peraton offers eligible employees a variety of benefits including medical, dental, vision, life, health savings account, short/long term disability, EAP, parental leave, 401(k), paid time off (PTO) for vacation, and company paid holidays.
Themen mit denen du dich im Job beschäftigst
Job Standorte
Das ist dein Arbeitgeber
Peraton
Peraton, gegründet 2017, ist auf nationale Sicherheits- und Technologieleistungen fokussiert und bietet Dienstleistungen in Raumfahrt, Cyber-Sicherheit und Verteidigung an.
Description
- Unternehmenstyp
- Etablierte Firma
- Arbeitsmodell
- Onsite
- Branche
- Energiewirtschaft, Umwelt