1

Cyber Security Social Engineering Jobs in Virginia

Nessus, Burp, Metasploit, and the Social Engineering Toolkit. • Researches and maintains ... Cybersecurity & Risk management, Testing, Forensics & Fraud services and human capital management.

GLI Secure is seeking an experienced Cybersecurity Consultant II (penetration tester) at our ... Experience with physical security testing, phishing and social engineering techniques. Location:

Possess expertise in network protocols, application security, social engineering, and scripting * Possess knowledge of cybersecurity frameworks, industry standards, and advanced security tools Pen ...

Penetration Tester

Chantilly, VA · On-site

$100 - $125/hr

Possess expertise in network protocols, application security, social engineering, and scripting * Possess knowledge of cybersecurity frameworks, industry standards, and advanced security tools Pen ...

Penetration Tester

Chantilly, VA · On-site

$100 - $125/hr

Possess expertise in network protocols, application security, social engineering, and scripting * Possess knowledge of cybersecurity frameworks, industry standards, and advanced security tools Pen ...

Possess expertise in network protocols, application security, social engineering, and scripting * Possess knowledge of cybersecurity frameworks, industry standards, and advanced security tools Pen ...

next page

Showing results 1-20

Cyber Security Social Engineering information

See Virginia salary details

$40.2K

$121.8K

$178.5K

How much do cyber security social engineering jobs pay per year?

As of Sep 9, 2026, the average yearly pay for cyber security social engineering in Virginia is $121,836.00, according to ZipRecruiter salary data. Most workers in this role earn between $101,100.00 and $140,800.00 per year, depending on experience, location, and employer.

What is a cyber security social engineering?

A Cyber Security Social Engineering job focuses on identifying, analyzing, and preventing attacks that manipulate human psychology to gain unauthorized access to systems and data. Professionals in this role conduct security awareness training, simulate phishing attacks, and develop strategies to mitigate human-related security risks. They work closely with IT teams, security analysts, and organizations to strengthen defenses against deception-based cyber threats. Their ultimate goal is to educate employees, improve security protocols, and reduce the risk of successful social engineering attacks.

What does a cyber security social engineering do?

A typical day often involves designing and simulating phishing campaigns, conducting security awareness training, and assessing organizational vulnerabilities related to human behavior. You may spend time analyzing results from recent simulations, preparing reports for stakeholders, or meeting with different departments to discuss risk mitigation strategies. The role often includes constant learning and adapting to new techniques used by threat actors, making each day dynamic. Collaboration with IT security teams, HR, and executive leadership is also a central part of the job, ensuring a coordinated approach to reducing social engineering risks.

What are the key skills and qualifications needed to thrive in cyber security social engineering?

Excelling in Cyber Security Social Engineering requires a solid understanding of security protocols, human psychology, and risk assessment, often supported by degrees in cybersecurity or related fields. Familiarity with penetration testing tools, social engineering frameworks, and certifications like CEH (Certified Ethical Hacker) or OSCP is highly valuable. Exceptional communication, analytical thinking, and adaptability are crucial soft skills for success in this position. These capabilities enable professionals to effectively identify vulnerabilities, educate teams, and help organizations strengthen their human defenses against social engineering attacks.

What is an example of social engineering in cybersecurity?

In cybersecurity, social engineering involves manipulating individuals to disclose confidential information or grant unauthorized access. For example, an attacker may impersonate a trusted employee or authority figure to persuade someone to reveal passwords or click malicious links, often exploiting human trust and lack of awareness. Cybersecurity professionals need strong awareness training and verification protocols to prevent such attacks.

What are popular job titles related to Cyber Security Social Engineering jobs in Virginia?

For Cyber Security Social Engineering jobs in Virginia, the most frequently searched job titles are:

What job categories do people searching Cyber Security Social Engineering jobs in Virginia look for?

The top searched job categories for Cyber Security Social Engineering jobs in Virginia are:

Infographic showing various Cyber Security Social Engineering job openings in Virginia as of September 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $121,836 per year, or $58.6 per hour.

Cyber Security Analyst

Chantilly, VA • On-site

Ampcus Inc
IT Services • 1 - 5K employees

Full-time

Re-posted 17 days ago


Job description

Job Summary:
Ampcus Cyber Inc, a leading global pioneer in Cybersecurity, is looking for a Cyber Security Analyst to join their team in Chantilly, VA. The role involves performing penetration testing, vulnerability analysis, and providing mitigation strategies to secure business applications and networks against cyber threats.
Responsibilities:
• Perform recon on applications and networks
• Perform penetration testing and system exploitation against desktops, servers, applications, operating systems, and security systems to gain root and administrator access for highly specialized network systems
• Perform internal and external pentest against systems to determine vulnerabilities and offer mitigation strategies
• Perform reconnaissance, privilege escalation persistence, lateral movement, and payload generation against information systems
• Analyze vulnerabilities, delivering clear and coherent written reporting, identifying network risks, and providing mitigation recommendations
• Conduct penetration and malicious user testing in Cloud environments, including Amazon Web Services (AWS), Azure, and on-premise systems
• Translate systems and applications into security test plans, performing hands-on security testing and leveraging adversarial tactics
• Must be able to use at least two of the following proficiently and instruct others on them: Nessus, Burp, Metasploit, and the Social Engineering Toolkit.
• Researches and maintains proficiency in tools, techniques, countermeasures, and trends in computer network vulnerabilities, data hiding and network security and encryption
• Ability to assist with researching and evaluating security policies and guidance
• Ability to train other team members on security concepts
• Excellent communication skills
Qualifications:
Required:
• 4-5 years of experience in related field
• Demonstrated real-world experience performing grey and black box penetration testing.
• Must be proficient in exploiting common web application vulnerabilities like XSS, CSRF, Command Injection, SQLi, single sign-on bypass, etc.
• Must be proficient in any of the following: PowerShell Empire, Metasploit Framework, Cobalt Strike, Burp Suite, Canvas, Kali Linux, A/V evasion methodologies, Exploit Dev.
• Must have solid working experience and knowledge of Windows operating systems (incl. Active Directory), Linux operating systems; VMware ESXi or similar; mobile platforms are a plus.
• Solid understanding of networking, TCP/IP, virtualization and cloud architecture.
• Strong familiarity with some of the following: OWASP top 10, DoD and NSA Vulnerability and Penetration Testing Standards.
• Knowledge of exploitation concepts including phishing and social engineering tactics, buffer overflows, fuzzing, SQLi, MiTM, covert channels, secure tunneling and open-source exfiltration techniques.
• Experience with Linux, Windows, wireless, and virtual platforms
• Knowledge of information security policies and guidance
• Proactive interest in emerging technologies and techniques related to penetration testing
• Excellent communication skills
Preferred:
• Experience with IOT device is a plus
• Certifications such as CEH or OSCP
• Malware analysis or digital computer forensics experience is a plus
• Scripting (Windows/*nix), Bash, Python, Perl or Ruby, Systems Programming is a plus
Company:
Ampcus is a global business, technology consulting and an staff augmentation firm specializing in AI/ML,digital solutions, Cybersecurity & Risk management, Testing, Forensics & Fraud services and human capital management. Founded in 2004, the company is headquartered in Chantilly, USA, with a team of 1001-5000 employees. The company is currently Late Stage.

Ampcus logo

About Ampcus

Sourced by ZipRecruiter

Ampcus Inc. is a ISO 20000, ISO 27000, ISO 9001, CMMI DEV/3 SM and CMMI SVC/3 SM certified global provider of a broad range of Technology and Business consulting services. From strategy to execution, our disciplined yet flexible approach starts and ends with our clients. By listening hard and working harder, client goals become our goals. Their success is our satisfaction. It’s why our clients sleep well at night. We believe that the success of an engagement is determined by strong project management, as well as clear communication and mutual commitment working collaboratively. Our methodology begins with listening to the customer about their needs, then working with their team to gain a clear understanding of the requirements, while providing knowledge transfer of best practices for the organization.

Industry

It services

Company size

1,001 - 5,000 Employees

Headquarters location

Chantilly, VA, US

Year founded

2004