Web Application Security Testing Team Lead Location: National Capital Region Security Clearance: Secret Duties and Responsibilities The Web Application Security Testing Team Lead supports this ...
Web Application Security Testing Team Lead Location: National Capital Region Security Clearance: Secret Duties and Responsibilities The Web Application Security Testing Team Lead supports this ...
Security Testing IT Project Manager Location: National Capital Region Security Clearance: Secret Duties and Responsibilities The Security Testing Information Technology Project Manager supports this ...
Security Testing IT Project Manager Location: National Capital Region Security Clearance: Secret Duties and Responsibilities The Security Testing Information Technology Project Manager supports this ...
National Security Programs * Professional, Administrative, and Management Support * Mission and ... Penetration Testing Team Lead Location: National Capital Region Clearance: Secret Duties and ...
National Security Programs * Professional, Administrative, and Management Support * Mission and ... Penetration Testing Team Lead Location: National Capital Region Clearance: Secret Duties and ...
Perform FIPS 140 validation testing on active Cryptographic Security Testing Laboratory testing projects for submission to the Cryptographic Module Validation Program (CMVP) * Perform testing on ...
New
Perform FIPS 140 validation testing on active Cryptographic Security Testing Laboratory testing projects for submission to the Cryptographic Module Validation Program (CMVP) * Perform testing on ...
New
Demonstrated work experience in cyber security or related IT field Experience with cyber security penetration testing Experience leveraging adversarial tactics to conduct hands-on security testing ...
Demonstrated work experience in cyber security or related IT field Experience with cyber security penetration testing Experience leveraging adversarial tactics to conduct hands-on security testing ...
Information Security SME
Arlington, VA · On-site
Innovate new application security testing methods and support team effort to leverage tools and develop effective process to automate the security test cases. * Serves as a Subject Matter Expert (SME ...
Information Security SME
Arlington, VA · On-site
Innovate new application security testing methods and support team effort to leverage tools and develop effective process to automate the security test cases. * Serves as a Subject Matter Expert (SME ...
Information Security SME
Arlington, VA · On-site
Innovate new application security testing methods and support team effort to leverage tools and develop effective process to automate the security test cases. * Serves as a Subject Matter Expert (SME ...
Information Security SME
Arlington, VA · On-site
Innovate new application security testing methods and support team effort to leverage tools and develop effective process to automate the security test cases. * Serves as a Subject Matter Expert (SME ...
Conducts security testing of web applications, web services, end points, (and other web-related assets) using both Information Assurance & Cybersecurity Division (IAD)-provided automated testing ...
Conducts security testing of web applications, web services, end points, (and other web-related assets) using both Information Assurance & Cybersecurity Division (IAD)-provided automated testing ...
Senior Security Code Reviewer
$120K - $164K/yr
This Key Personnel role will lead application security testing, secure code review, DevSecOps pipeline integration, secure development guidance, risk assessments, and cloud/network security ...
Quick apply
Senior Security Code Reviewer
$120K - $164K/yr
This Key Personnel role will lead application security testing, secure code review, DevSecOps pipeline integration, secure development guidance, risk assessments, and cloud/network security ...
Security Engineer (Web Application)
$67.50 - $90.25/hr
Application testing will require authenticated and non-authenticated testing to ensure full ... Conducts security testing of web applications, web services, end points, (and other web-related ...
Security Engineer (Web Application)
$67.50 - $90.25/hr
Application testing will require authenticated and non-authenticated testing to ensure full ... Conducts security testing of web applications, web services, end points, (and other web-related ...
Senior Security Code Reviewer
Camp Springs, MD · On-site
$120K - $164K/yr
This Key Personnel role will lead application security testing, secure code review, DevSecOps pipeline integration, secure development guidance, risk assessments, and cloud/network security ...
Senior Security Code Reviewer
Camp Springs, MD · On-site
$120K - $164K/yr
This Key Personnel role will lead application security testing, secure code review, DevSecOps pipeline integration, secure development guidance, risk assessments, and cloud/network security ...
Senior Security Code Reviewer
Camp Springs, MD · On-site
$120K - $164K/yr
This Key Personnel role will lead application security testing, secure code review, DevSecOps pipeline integration, secure development guidance, risk assessments, and cloud/network security ...
Senior Security Code Reviewer
Camp Springs, MD · On-site
$120K - $164K/yr
This Key Personnel role will lead application security testing, secure code review, DevSecOps pipeline integration, secure development guidance, risk assessments, and cloud/network security ...
Senior Security Test Engineer with Security Clearance
Fairfax, VA · On-site
$113K - $155K/yr
Everforth ECS is seeking a Senior Security Test Engineer to work in the National Capital Region ... testing activities directly into DevSecOps pipelines spanning NIPRNet, SIPRNet, and JWICS. This is ...
Senior Security Test Engineer with Security Clearance
Fairfax, VA · On-site
$113K - $155K/yr
Everforth ECS is seeking a Senior Security Test Engineer to work in the National Capital Region ... testing activities directly into DevSecOps pipelines spanning NIPRNet, SIPRNet, and JWICS. This is ...
Application Security Engineer 1
Arlington, VA · On-site
$67.50 - $90.25/hr
Responsible for supporting application security through security testing, vulnerability management, secure design collaboration, automation support, and incident response participation, contributing ...
Application Security Engineer 1
Arlington, VA · On-site
$67.50 - $90.25/hr
Responsible for supporting application security through security testing, vulnerability management, secure design collaboration, automation support, and incident response participation, contributing ...
Application Security Engineer 1
Arlington, VA · On-site
$67.50 - $90.25/hr
Responsible for supporting application security through security testing, vulnerability management, secure design collaboration, automation support, and incident response participation, contributing ...
Application Security Engineer 1
Arlington, VA · On-site
$67.50 - $90.25/hr
Responsible for supporting application security through security testing, vulnerability management, secure design collaboration, automation support, and incident response participation, contributing ...
Secret Duties and Responsibilities The Security Analyst supports this Transportation Security Administration Information Technology (TSA IT) Task Order (TO) by executing security testing in a variety ...
Secret Duties and Responsibilities The Security Analyst supports this Transportation Security Administration Information Technology (TSA IT) Task Order (TO) by executing security testing in a variety ...
Senior DevSecOps Engineer with Security Clearance
Arlington, VA · On-site
$131K - $180K/yr
Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), Container and image scanning, Secret detection and credential management ...
Senior DevSecOps Engineer with Security Clearance
Arlington, VA · On-site
$131K - $180K/yr
Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), Container and image scanning, Secret detection and credential management ...
Maintains and stays current with in-depth technical knowledge of operating system security testing tools in use by the Information Assurance & Cybersecurity Division (IAD), and testing techniques in ...
Maintains and stays current with in-depth technical knowledge of operating system security testing tools in use by the Information Assurance & Cybersecurity Division (IAD), and testing techniques in ...
... testing activities directly into DevSecOps pipelines spanning NIPRNet, SIPRNet, and JWICS. This is ... security, performance, and compliance requirements. • Translates contract-level DevSecOps and ...
... testing activities directly into DevSecOps pipelines spanning NIPRNet, SIPRNet, and JWICS. This is ... security, performance, and compliance requirements. • Translates contract-level DevSecOps and ...
Lead Security Engineer
Suitland, MD · On-site
Direct Static and Dynamic Application Security Testing (SAST/DAST), vulnerability assessments, and penetration testing to identify, triage, and remediate security weaknesses * Lead threat modeling ...
Lead Security Engineer
Suitland, MD · On-site
Direct Static and Dynamic Application Security Testing (SAST/DAST), vulnerability assessments, and penetration testing to identify, triage, and remediate security weaknesses * Lead threat modeling ...
Security Testing information
See Washington, DC salary details
$19.60 - $26.42
8% of jobs
$26.42 - $33.25
7% of jobs
$33.25 - $40.08
8% of jobs
$40.08 - $46.91
0% of jobs
$47.42 is the 25th percentile. Wages below this are outliers.
$46.91 - $53.74
11% of jobs
The median wage is $58.24 / hr.
$53.74 - $60.57
23% of jobs
$66.41 is the 75th percentile. Wages above this are outliers.
$60.57 - $67.40
20% of jobs
$67.40 - $74.22
5% of jobs
$74.22 - $81.05
12% of jobs
$81.05 - $87.88
2% of jobs
$87.88 - $94.71
3% of jobs
$19
$57
$94
How much do security testing jobs pay per hour?
What is the difference between Security Testing vs Penetration Testing?
| Aspect | Security Testing | Penetration Testing |
|---|---|---|
| Purpose | Identify security flaws and vulnerabilities in systems and applications | Simulate cyberattacks to exploit vulnerabilities and assess security defenses |
| Scope | Broad, including security policies, configurations, and overall security posture | Focused on exploiting specific vulnerabilities to test defenses |
| Certifications | Security+ (CompTIA), CEH, CISSP (common but not exclusive) | OSCP, CEH, GPEN |
| Work Environment | Security teams, testing labs, development environments | Security consultants, ethical hackers, penetration testers |
Security Testing and Penetration Testing are related but distinct roles. Security Testing provides a comprehensive assessment of security weaknesses, while Penetration Testing focuses on actively exploiting vulnerabilities to evaluate defenses. Both are essential for maintaining robust security but serve different purposes within cybersecurity strategies.
What does a security tester do?
What is security testing?
How does a security testing professional typically collaborate with development and IT teams during a project?
Is security testing in demand?
Is 40 too old for cyber security?
What are the key skills and qualifications needed to thrive as a Security Tester, and why are they important?
Can you make $500,000 a year in cyber security?
Job description
gTANGIBLE Corporation (gTC), www.gtangible.com, is a C corporation and a registered Government contractor that provides services and solutions in:
- National Security Programs
- Professional, Administrative, and Management Support
- Mission and Warfighter Support
We are a Service Disabled Veteran Owned Small Business (SDVOSB) and the founder has years of successful experience in the Government contracting arena. Our leadership team is an exceptional group of Government contracting professionals. gTANGIBLE is in the process of identifying candidates for the following position.
Requisition Type: Full Time
Position Status: Contingent
Position Title: Web Application Security Testing Team Lead
Location: National Capital Region
Security Clearance: Secret
Duties and ResponsibilitiesThe Web Application Security Testing Team Lead supports this Transportation Security Administration Information Technology (TSA IT) Task Order (TO) by web application testing that require testing both via automated tools and with manual testing techniques. Application testing will require authenticated and non-authenticated testing to ensure full evaluation of the cybersecurity controls for the applications. Off hours testing conducted on a as needed basis. Periodic travel required.
Team duties include the following:
- Become, and remain, familiar with TSA and DHS security policies and Technical Standards relating to web applications and web application development to facilitate effective security assessments. Make recommendations for updates, additions, and modifications to TSA security policy as gaps or deficiencies in security policy are identified.
- Engage with testing engagement stakeholders to gather all required information needed to create detailed test plans.
- Conduct security testing of web applications and services (and other web-related assets) using both Information Assurance and Cybersecurity Division (IAD)-provided automated testing tools and manual testing techniques.
- Troubleshoot any technical issues preventing successful completion of testing engagements within the scheduled time allotted for the engagement (i.e. insufficient credentials, proxy blocking, accounts blocked/expired, etc.).
- Participate in findings meetings to review and provide input on the validity of application stakeholder responses to IAD findings.
- Recommend adjustments of finding validity (valid or false positive) and severity (high, medium, low) to Governance, Risk, and Compliance (GRC) Portfolio Managers and Primary Assessors based on stakeholder responses.
- Review application stakeholder mitigation or remediation actions to address valid findings to assist IAD with determining the applicability and effectiveness of those actions.
- Provide Subject Matter Expertise for a variety of topics concerning web applications in a variety of formats (verbal or written). Includes common and emerging web and mobile technologies, languages, and frameworks to discuss the benefits and security detriments of those technologies.
- Provide support for external security audits conducted of the TSA. Such support would include items such as: providing technical insight into data calls required by external Federal entities, offering technical information to facilitate external auditors work, or validating findings identified in external audit reports.
Knowledge and Qualifications
- At least eight (8) years of technical IT security experience. Such experience can come from system or network administration, security analysis, security testing and evaluation, security incident response, security monitoring, IT project implementation, or other similar technical activities.
- At least five (5) years of experience performing security control assessments (i.e. security testing such as security auditing, primary assessor for Security Control Assessments, etc.).
- At least three (3) years of experience performing web application security testing.
- At least one (1) year of experience performing security testing of Federal IT systems.
- Experience with NIST and FIPS security controls, DISA STIGs, and CIS standards.
- Experience working in groups acting as the sole security practitioner, as well as experience working in team(s) of various sizes of security personnel reviewing the same system.
- Experience with HP WebInspect, IBM/HCL AppScan, Portswigger BurpSuite, SmartBear SoapUI, Nessus Professional, HP Fortify, Apple Developers Toolkit, Eclipse, and Wireshark.
- Excellent communication skills to be able to understand concepts being verbally presented, participate in group discussions, and to present recommendations.
- Strong organizational, analytical, and technical writing skills to be able to document findings in reports.
gTANGIBLE Corporation is an equal opportunity employer and does not discriminate against any employee or applicant because of race, age, sex, color, physical or mental disability, religion, sexual orientation, marital status, national origin, or political affiliation.
About gTANGIBLE
Sourced by ZipRecruiter
Industry
Business consulting services
Company size
11 - 50 Employees
Headquarters location
Alexandria, VA, US
Year founded
2009