National Security Programs * Professional, Administrative, and Management Support * Mission and ... Infrastructure Testing Team Lead Location: Arlington, VA Clearance: Secret Duties and ...
National Security Programs * Professional, Administrative, and Management Support * Mission and ... Infrastructure Testing Team Lead Location: Arlington, VA Clearance: Secret Duties and ...
Conduct security testing of systems and networks to ensure appropriate security hygiene * Simulate real-world attacks to identify vulnerabilities and potential attack vectors * Communicate complex ...
Conduct security testing of systems and networks to ensure appropriate security hygiene * Simulate real-world attacks to identify vulnerabilities and potential attack vectors * Communicate complex ...
Conduct security testing of systems and networks to ensure appropriate security hygiene * Simulate real-world attacks to identify vulnerabilities and potential attack vectors * Communicate complex ...
Conduct security testing of systems and networks to ensure appropriate security hygiene * Simulate real-world attacks to identify vulnerabilities and potential attack vectors * Communicate complex ...
ProSidian Seeks a Security Testing Safety and Work Planning Specialist (SCA Code: -) in CONUS - Mid Atlantic Washington Metropolitan Area (Northern Virginia | Washington DC | Maryland) to support an ...
ProSidian Seeks a Security Testing Safety and Work Planning Specialist (SCA Code: -) in CONUS - Mid Atlantic Washington Metropolitan Area (Northern Virginia | Washington DC | Maryland) to support an ...
National Security Programs * Professional, Administrative, and Management Support * Mission and ... Infrastructure Testing Team Lead Location: National Capital Region Clearance: Secret Duties and ...
National Security Programs * Professional, Administrative, and Management Support * Mission and ... Infrastructure Testing Team Lead Location: National Capital Region Clearance: Secret Duties and ...
IT Security Control Assessor
Columbia, MD · On-site
Responsibilities : • Conducting thorough risk assessments, performing security testing, and analyzing security controls to identify and mitigate vulnerabilities. • Developing and maintaining ...
IT Security Control Assessor
Columbia, MD · On-site
Responsibilities : • Conducting thorough risk assessments, performing security testing, and analyzing security controls to identify and mitigate vulnerabilities. • Developing and maintaining ...
Direct Static and Dynamic Application Security Testing (SAST/DAST), vulnerability assessments, and penetration testing to identify, triage, and remediate security weaknesses * Lead threat modeling ...
Direct Static and Dynamic Application Security Testing (SAST/DAST), vulnerability assessments, and penetration testing to identify, triage, and remediate security weaknesses * Lead threat modeling ...
IT Security Control Assessor
Columbia, MD · On-site
Responsibilities : • conducting thorough risk assessments, performing security testing, and analyzing security controls to identify and mitigate vulnerabilities. • developing and maintaining ...
IT Security Control Assessor
Columbia, MD · On-site
Responsibilities : • conducting thorough risk assessments, performing security testing, and analyzing security controls to identify and mitigate vulnerabilities. • developing and maintaining ...
Lead Security Engineer
Suitland, MD · On-site
Direct Static and Dynamic Application Security Testing (SAST/DAST) , vulnerability assessments, and penetration testing to identify, triage, and remediate security weaknesses * Lead threat modeling ...
Lead Security Engineer
Suitland, MD · On-site
Direct Static and Dynamic Application Security Testing (SAST/DAST) , vulnerability assessments, and penetration testing to identify, triage, and remediate security weaknesses * Lead threat modeling ...
National Security Programs * Professional, Administrative, and Management Support * Mission and ... Review of mobile application code and conduct testing using both Information Assurance ...
National Security Programs * Professional, Administrative, and Management Support * Mission and ... Review of mobile application code and conduct testing using both Information Assurance ...
Direct Static and Dynamic Application Security Testing (SAST/DAST) , vulnerability assessments, and penetration testing to identify, triage, and remediate security weaknesses * Lead threat modeling ...
Direct Static and Dynamic Application Security Testing (SAST/DAST) , vulnerability assessments, and penetration testing to identify, triage, and remediate security weaknesses * Lead threat modeling ...
Lead Security Engineer
Suitland, MD · On-site
Direct Static and Dynamic Application Security Testing (SAST/DAST) , vulnerability assessments, and penetration testing to identify, triage, and remediate security weaknesses * Lead threat modeling ...
Quick apply
Lead Security Engineer
Suitland, MD · On-site
Direct Static and Dynamic Application Security Testing (SAST/DAST) , vulnerability assessments, and penetration testing to identify, triage, and remediate security weaknesses * Lead threat modeling ...
Application Security Engineer
Herndon, VA · Remote
$60.50 - $80.75/hr
Experience in security testing, CI/CD, and DevSecOps; strong knowledge of SAST/DAST/SCA and OWASP Top 10; BS in CS/engineering or related field. Education: Bachelors Role: Individual Contributor ...
Application Security Engineer
Herndon, VA · Remote
$60.50 - $80.75/hr
Experience in security testing, CI/CD, and DevSecOps; strong knowledge of SAST/DAST/SCA and OWASP Top 10; BS in CS/engineering or related field. Education: Bachelors Role: Individual Contributor ...
Penetration Tester
Herndon, VA · Hybrid
$130K - $145K/yr
Testing and assessing the security of secure boot processes and Trusted Execution Environments (TEE). * Conducting web application security assessments, focusing on OWASP Top Ten vulnerabilities and ...
Quick apply
Penetration Tester
Herndon, VA · Hybrid
$130K - $145K/yr
Testing and assessing the security of secure boot processes and Trusted Execution Environments (TEE). * Conducting web application security assessments, focusing on OWASP Top Ten vulnerabilities and ...
Lead Security Engineer
Suitland, MD · On-site
The ideal candidate will architect and enforce Zero Trust principles, drive Authorization to Operate (ATO) activities, and direct application security testing, threat modeling, and vulnerability ...
Quick apply
Lead Security Engineer
Suitland, MD · On-site
The ideal candidate will architect and enforce Zero Trust principles, drive Authorization to Operate (ATO) activities, and direct application security testing, threat modeling, and vulnerability ...
Penetration Tester
Washington, DC · Hybrid
$130K - $145K/yr
Testing and assessing the security of secure boot processes and Trusted Execution Environments (TEE). * Conducting web application security assessments, focusing on OWASP Top Ten vulnerabilities and ...
Penetration Tester
Washington, DC · Hybrid
$130K - $145K/yr
Testing and assessing the security of secure boot processes and Trusted Execution Environments (TEE). * Conducting web application security assessments, focusing on OWASP Top Ten vulnerabilities and ...
Penetration Tester
Washington, DC · On-site
$130K - $145K/yr
Testing and assessing the security of secure boot processes and Trusted Execution Environments (TEE). * Conducting web application security assessments, focusing on OWASP Top Ten vulnerabilities and ...
Penetration Tester
Washington, DC · On-site
$130K - $145K/yr
Testing and assessing the security of secure boot processes and Trusted Execution Environments (TEE). * Conducting web application security assessments, focusing on OWASP Top Ten vulnerabilities and ...
Lead Security Engineer
Suitland, MD · On-site
The ideal candidate will architect and enforce Zero Trust principles, drive Authorization to Operate (ATO) activities, and direct application security testing, threat modeling, and vulnerability ...
Lead Security Engineer
Suitland, MD · On-site
The ideal candidate will architect and enforce Zero Trust principles, drive Authorization to Operate (ATO) activities, and direct application security testing, threat modeling, and vulnerability ...
Software Tester with Security Clearance
Chantilly, VA · On-site
$100K - $145K/yr
With a wide range of knowledge, the ST defines and develops test standards for the testing of ... Automated testing • Security testing • MS TFS • Zap (security testing) • Good ...
Software Tester with Security Clearance
Chantilly, VA · On-site
$100K - $145K/yr
With a wide range of knowledge, the ST defines and develops test standards for the testing of ... Automated testing • Security testing • MS TFS • Zap (security testing) • Good ...
IT DevSecOps Engineer [onsite]- W2 Role
Washington, DC · On-site
$66.50 - $89/hr
... Security Testing (DAST) · Interactive Application Security Testing (IAST) · Software Composition Analysis (SCA) · Container scanning tooling (Trivy, Prisma/Twistlock, Neuvector, etc ...
Quick apply
IT DevSecOps Engineer [onsite]- W2 Role
Washington, DC · On-site
$66.50 - $89/hr
... Security Testing (DAST) · Interactive Application Security Testing (IAST) · Software Composition Analysis (SCA) · Container scanning tooling (Trivy, Prisma/Twistlock, Neuvector, etc ...
Security Testing information
See Washington, DC salary details
$19.60 - $26.42
8% of jobs
$26.42 - $33.25
7% of jobs
$33.25 - $40.08
8% of jobs
$40.08 - $46.91
0% of jobs
$47.42 is the 25th percentile. Wages below this are outliers.
$46.91 - $53.74
11% of jobs
The median wage is $58.24 / hr.
$53.74 - $60.57
23% of jobs
$66.41 is the 75th percentile. Wages above this are outliers.
$60.57 - $67.40
20% of jobs
$67.40 - $74.22
5% of jobs
$74.22 - $81.05
12% of jobs
$81.05 - $87.88
2% of jobs
$87.88 - $94.71
3% of jobs
$19
$57
$94
How much do security testing jobs pay per hour?
What is the difference between Security Testing vs Penetration Testing?
| Aspect | Security Testing | Penetration Testing |
|---|---|---|
| Purpose | Identify security flaws and vulnerabilities in systems and applications | Simulate cyberattacks to exploit vulnerabilities and assess security defenses |
| Scope | Broad, including security policies, configurations, and overall security posture | Focused on exploiting specific vulnerabilities to test defenses |
| Certifications | Security+ (CompTIA), CEH, CISSP (common but not exclusive) | OSCP, CEH, GPEN |
| Work Environment | Security teams, testing labs, development environments | Security consultants, ethical hackers, penetration testers |
Security Testing and Penetration Testing are related but distinct roles. Security Testing provides a comprehensive assessment of security weaknesses, while Penetration Testing focuses on actively exploiting vulnerabilities to evaluate defenses. Both are essential for maintaining robust security but serve different purposes within cybersecurity strategies.
What does a security tester do?
What is security testing?
How does a security testing professional typically collaborate with development and IT teams during a project?
Is security testing in demand?
Is 40 too old for cyber security?
What are the key skills and qualifications needed to thrive as a Security Tester, and why are they important?
Can you make $500,000 a year in cyber security?
Job description
gTANGIBLE Corporation (gTC), www.gtangible.com, is a C corporation and a registered Government contractor that provides services and solutions in:
- National Security Programs
- Professional, Administrative, and Management Support
- Mission and Warfighter Support
We are a Service Disabled Veteran Owned Small Business (SDVOSB) and the founder has years of successful experience in the Government contracting arena. Our leadership team is an exceptional group of Government contracting professionals. gTANGIBLE is in the process of identifying candidates for the following position.
Requisition Type: Full Time
Position Status: Contingent
Position Title: Infrastructure Testing Team Lead
Location: Arlington, VA
Clearance: Secret
Duties and ResponsibilitiesThe Infrastructure Testing Team Lead supports this Transportation Security Administration Information Technology (TSA IT) Task Order (TO) by overseeing operating system testing, database testing, network fabric asset testing, and wireless communication testing. Off hours testing conducted on a as needed basis. Periodic travel required.
Team duties include the following operating system testing, database testing, network fabric asset testing, and wireless communication testing:
- Become, and remain, familiar with TSA and DHS security policies and Technical Standards relating to the configuration and operation of operating systems to facilitate effective security assessments.
- Engage with testing engagement stakeholders to gather all required information needed to create detailed test plans.
- Conduct security testing of operating systems using IAD-provided automated testing tools in conjunction with manual configuration validation techniques.
- Troubleshoot any technical issues preventing successful completion of testing engagements within the scheduled time allotted for the engagement (i.e. insufficient credentials, whitelisting not implemented, no network access, etc.).
- Validate and enrich results generated by automated testing tools. Example activities include identification of false positive findings generated by testing tools, adjustment of finding severities based on specific considerations within, or associated with, the affected target.
- Review application stakeholder response to operating system security findings identified during security testing engagements.
- Provide Subject Matter Expertise for a variety of topics concerning operating systems in a variety of formats (verbal or written).
- Provide support for external security audits conducted of the TSA. Such support would include items such as: providing technical insight into datacalls required by external Federal entities, offering technical information to facilitate external auditor's work, or validating findings identified in external audit reports.
Knowledge and Qualifications
- At least ten (10) years of technical IT security experience. Such experience can come from system or network administration, security analysis, security testing and evaluation, security incident response, security monitoring, IT project implementation, or other similar technical activities.
- At least five (5) years of experience performing security assessments.
- At least three (3) years of experience performing security assessments of Windows and Linux operating systems.
- At least one (1) year of experience performing security assessments for Federal IT systems.
- Fluent knowledge of NIST and FIPS security controls, DISA STIGs, and CIS standards.
- The ability to work effectively in groups acting as the sole security practitioner, as well as be able to participate in a small team of security personnel reviewing the same system.
- Excellent communication skills to be able to understand concepts being verbally presented, participate in group discussions, and to present recommendations which may provide better security for the systems being reviewed.
- Strong organizational, analytical, and technical writing skills to be able to document findings in reports that can be understood by individuals with less security technical knowledge.
gTANGIBLE Corporation is an equal opportunity employer and does not discriminate against any employee or applicant because of race, age, sex, color, physical or mental disability, religion, sexual orientation, marital status, national origin, or political affiliation.
About gTANGIBLE
Sourced by ZipRecruiter
Industry
Business consulting services
Company size
11 - 50 Employees
Headquarters location
Alexandria, VA, US
Year founded
2009