Talent.com
Principal Penetration Tester

Principal Penetration Tester

VerizonAshburn, VA, United States
4 days ago
Job type
  • Full-time
  • Part-time
Job description

When you join Verizon

You want more out of a career. A place to share your ideas freely — even if they’re daring or different. Where the true you can learn, grow, and thrive. At Verizon, we power and empower how people live, work and play by connecting them to what brings them joy. We do what we love — driving innovation, creativity, and impact in the world. Our V Team is a community of people who anticipate, lead, and believe that listening is where learning begins. In crisis and in celebration, we come together — lifting our communities and building trust in how we show up, everywhere & always. Want in? Join the #VTeamLife.

What you’ll be doing...

The Verizon Cyber Security (VCS) organization enables the business by protecting assets and information across Verizon networks, infrastructure and applications. VCS integrates cybersecurity governance, policies, technologies and operations across Verizon, and works to incorporate security into the design of technology systems and services.

Verizon Cybersecurity (VCS) is looking for an Application Penetration Tester to join our Enterprise Pen Test team. You’ll be joining a group of talented, creative thinkers who "act like the enemy" to focus on ensuring that infrastructure and applications (web, mobile, and API) are secure by performing penetration testing from both inside and outside of Verizon. This team isn’t a "copy and paste from a scan tool" reporting team, or a cookie cutter just scanning with tools team, or a team that just monitors and supports security scanning tools used by developers. This team is an Enterprise recognized and supported group of skilled, experienced and certified ethical hacking Verizon employees who are trusted to direct themselves with a lot of unknowns.

The successful candidate will possess an effective aptitude in thinking like an adversary, security of Infrastructure, Web applications, APIs and Mobile Applications, mentoring and leading junior pen testers and effectively translating highly technical information to internal customers in a way that supports VCS and broader Verizon goals.

Role responsibilities include :

Leading and performing full scope penetration testing on complex, high risk web applications, Infrastructure, APIs and Mobile applications.

Successfully working complex issues that require the analysis and in-depth evaluation of variable factors.

Interpreting broad goals with unknown variables and craft, execute plans to achieve these goals with little to no contemporary “clear and transparent” standards.

Developing resolutions that require the frequent use of creativity and out of the box thinking.

Configuring and safely utilizing attacker tools, tactics, and procedures for Verizon environments.

Developing comprehensive and accurate reports and presentations for both technical and executive audiences.

The ability to make collaborative and independent decisions on the impact of an exposure to Verizon

Acting as a SME and guide, advising on security vulnerability impact, ratings and remediation recommendations across the organization as needed.

Leading the definition of Pen Test strategy and standards to further enhance the company’s security posture, collaborating with management / exec leadership.

Effectively communicating findings and strategy to client stakeholders including technical staff, executive leadership, and legal counsel

Working closely with stakeholders and developers providing risk-appropriate and pragmatic recommendations to correct found vulnerabilities.

Translating functional plans into operational processes and guiding execution of the development of scripts, tools, or methodologies to enhance Verizon’s pen testing processes and effectiveness

Driving technical oversight and mentoring junior pen testers on pen test engagements, vulnerability impact and ratings and remediation recommendations.

Providing leadership and guidance to advance the offensive capabilities of the team and its subsequent ability to defend the Verizon Enterprise.

What we’re looking for...

You’ll need to have :

Bachelor’s degree or four or more years of work experience.

Six or more years of relevant experience required, demonstrated through one or a combination of work and / or military experience, or specialized training.

Six or more years of application / network penetration testing or security experience.

Even better if you have one or more of the following :

A degree in engineering, cyber security or computer science.

Application development experience.

Knowledge of secure software deployment methodologies, tools, and practices.

Experience with application security risk procedures, security patterns, authentication technologies and security attack pathologies.

Certifications such as : GXPN, GPEN, , eWPT, GCIH, GWAPT, OSCP, OSWA, OSCE, OSWE.

Service Delivery / Governance : ITILv2 / 3.

Deep understanding of OWASP Top 10, OWASP API Top 10, MASVS.

Strong knowledge of tools used for api, Infrastructure, web application, mobile, and network security testing, such as Kali Linux, Metasploit, Wireshark, Burp suite, Cobalt Strike, Nessus, Web Inspect, SQLMap.

Experience leading small pen test teams, driving process and strategy.

Solid understanding of common hosting environments such as containerization platforms (e.g., Docker and Kubernetes) and virtual machines running under hypervisors.

An implementation level familiarity with all common classes of modern exploitation.

Mastery of Unix / Linux / Mac / Windows operating systems, including bash and Powershell.

Programming skills preferred and encouraged, as well as the ability to read and assess applications written multiple languages, such as Python, JAVA, .NET, C#, or others.

Experience with system and application security threats and vulnerabilities and secure configuration management techniques, software debugging principles, software design tools, methods, and techniques, software development models (e.g., Waterfall Model, Spiral Model).

Knowledge of secure coding techniques.

Knowledge of application security, application security vulnerabilities and exploitation techniques.

Some experience with software related information technology (IT) security principles and methods (e.g., modularization, layering, abstraction, data hiding, and simplicity / minimization).

Knowledge of secure software deployment methodologies, tools, and practices.

Knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).

Knowledge of security architecture concepts and enterprise architecture reference models.

Knowledge in discerning the protection needs (i.e., security controls) of information systems and networks.

Strong organization skills and demonstrated ability to manage multiple, often conflicting priorities to successful completion.

Be a continuous learner; with a desire to stay current on security trends, tool, technologies and best practices.

If Verizon and this role sound like a fit for you, we encourage you to apply even if you don’t meet every “even better” qualification listed above.

Where you’ll be working

In this hybrid role, you'll have a defined work location that includes working from home and a minimum of three days per week in the office, which will be set by your manager. Employees are responsible for maintaining compliance with hybrid work policies.

Scheduled Weekly Hours

40

Equal Employment Opportunity

Verizon is an equal opportunity employer. We evaluate qualified applicants without regard to veteran status, disability or other legally protected characteristics.

Benefits and Compensation

Our benefits are designed to help you move forward in your career, and in areas of your life outside of Verizon. From health and wellness benefit options including : medical, dental, vision, short and long term disability, basic life insurance, supplemental life insurance, AD&D insurance, identity theft protection, pet insurance and group home & auto insurance. We also offer a matched 401(k) savings plan, stock incentive programs, up to 8 company paid holidays per year and up to 6 personal days per year, parental leave, adoption assistance and tuition assistance, plus other incentives, we’ve got you covered with our award-winning total rewards package. Depending on the role, employees have the opportunity to receive compensation in the form of premium pay such as overtime, shift differential, holiday pay, allowances, etc. Newly hired employees receive up to 15 days of vacation per year, which grows with additional service. For part-timers, your coverage will vary as you may be eligible for some of these benefits depending on your individual circumstances.

The salary will vary depending on your location and confirmed job-related skills and experience. This is an incentive based position with the potential to earn more. For part-time roles, your compensation will be adjusted to reflect your hours.

The annual salary range for the location(s) listed on this job requisition based on a full-time schedule is : $120,500.00 - $231,000.00.

Create a job alert for this search

Penetration Tester • Ashburn, VA, United States

Related jobs
  • Promoted
Penetration Tester

Penetration Tester

SkyePoint DecisionsArlington, VA, United States
Full-time
Contingent Upon Prime / Customer Acceptance.Cyber and Information Security.SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure and Operations, and App...Show moreLast updated: 4 days ago
  • Promoted
Penetration Tester

Penetration Tester

OrisonReston, VA, United States
Full-time
Work Mode - Hybrid role, 2 days' Work from Office (Wednesday and Thursday).Must have Skill Set - Red team pentester.Network penetration testing and experience working with network infrastructure.An...Show moreLast updated: 4 days ago
  • Promoted
Penetration Tester, Expert (Federal agency) - Tysons, VA - Full Time

Penetration Tester, Expert (Federal agency) - Tysons, VA - Full Time

iSoftTek Solutions IncMcLean, VA, United States
Full-time
Penetration Tester, Expert (Federal agency).Job Type : Full-time (40 hours per week) with benefits.Security Clearance : TS / SCI with CI of FS Polygraph. Conduct internal penetration testing and vulnera...Show moreLast updated: 30+ days ago
  • Promoted
Penetration Tester

Penetration Tester

Verite GroupSterling, VA, United States
Full-time
Why Choose VGI, a GRVTY Company.VGI, a GRVTY Company, started with a simple, American idea : we do things not because they are easy but because they are hard. VGI, a GRVTY Company, exists to answer c...Show moreLast updated: 30+ days ago
  • Promoted
Penetration Tester (Pen Tester), Level 3 (Senior)

Penetration Tester (Pen Tester), Level 3 (Senior)

ArcfieldChantilly, VA, United States
Full-time
Arcfield was purpose-built to protect the nation and its allies through innovations in digital transformation, space mission engineering and launch assurance, miniaturized sensors and satellites, a...Show moreLast updated: 4 days ago
  • Promoted
Penetration Tester (Pen Tester), Level 1 (Junior)

Penetration Tester (Pen Tester), Level 1 (Junior)

ArcfieldChantilly, VA, United States
Full-time
Arcfield was purpose-built to protect the nation and its allies through innovations in digital transformation, space mission engineering and launch assurance, miniaturized sensors and satellites, a...Show moreLast updated: 4 days ago
  • Promoted
Penetration Tester

Penetration Tester

LeidosAshburn, VA, United States
Full-time
We empower our teams, contribute to our communities, and operate sustainable.Everything we do is built on a commitment to do the right thing for our customers, our people, and our community.Our Mis...Show moreLast updated: 4 days ago
  • Promoted
Penetration Tester (Pen Tester), Level 4 / Subject Matter Expert (SME)

Penetration Tester (Pen Tester), Level 4 / Subject Matter Expert (SME)

ArcfieldChantilly, VA, United States
Full-time
Arcfield was purpose-built to protect the nation and its allies through innovations in digital transformation, space mission engineering and launch assurance, miniaturized sensors and satellites, a...Show moreLast updated: 4 days ago
  • Promoted
Penetration Tester

Penetration Tester

VTG DefenseChantilly, VA, United States
Full-time
VTG is looking for multiple levels (Level 2, 3 & 4) of a Penetration Tester in Chantilly VA and Aurora CO.Note : position is contingent upon program award and the postions are located in Chantilly V...Show moreLast updated: 4 days ago
  • Promoted
Penetration Tester

Penetration Tester

CymertekReston, VA, United States
Full-time
TS / SCI Full Poly (Please note this position requires full U.We are seeking a highly skilled and proactive Penetration Tester to join our cybersecurity team. In this role, you will identify vulnerabi...Show moreLast updated: 4 days ago
  • Promoted
Penetration Tester

Penetration Tester

Marathon TSManassas, VA, United States
Full-time
As a penetration tester in the Swift Red Team, you will assess security from an offensive perspective with the intent to improve the global security posture of the company.Your key responsibilities...Show moreLast updated: 4 days ago
  • Promoted
Penetration Tester

Penetration Tester

Leidos IncAshburn, VA, United States
Full-time
We empower our teams, contribute to our communities, and operate sustainable.Everything we do is built on a commitment to do the right thing for our customers, our people, and our community.Our Mis...Show moreLast updated: 22 days ago
  • Promoted
Penetration Tester

Penetration Tester

Booz Allen HamiltonHerndon, VA, United States
Full-time +1
Conduct testing and analysis to identify vulnerabilities and potential threat vectors into systems and networks, develop exploits, and engineer attack methodologies. Apply advanced advising skills, ...Show moreLast updated: 4 days ago
  • Promoted
Penetration Tester

Penetration Tester

VTGChantilly, VA, United States
Full-time
VTG is looking for multiple levels (Level 2, 3 & 4) of a Penetration Tester in Chantilly VA and Aurora CO.Note : position is contingent upon program award and the postions are located in Chantilly V...Show moreLast updated: 4 days ago
  • Promoted
Penetration Tester

Penetration Tester

CACI InternationalChantilly, VA, United States
Full-time
Minimum Clearance Required to Start : TS / SCI with Polygraph.Percentage of Travel Required : None.Perform computer network evaluations to include penetration security assessments in a cybersecurity re...Show moreLast updated: 4 days ago
  • Promoted
Senior Penetration Tester

Senior Penetration Tester

HumanaWashington, DC, United States
Full-time
Become a part of our caring community and help us put health first.Join a 100% remote, highly specialized offensive security team where collaboration and continuous learning drive our success.We fo...Show moreLast updated: 4 days ago
  • Promoted
Penetration Testers - Senior (Lead)

Penetration Testers - Senior (Lead)

eTelligent GroupWashington, DC, United States
Full-time
Over the past 15 years, eTel has delivered essential solutions for the federal government by securing and managing data, providing scalable identity access, modernizing legacy systems, and building...Show moreLast updated: 4 days ago
  • Promoted
Penetration Tester OR Pen Tester

Penetration Tester OR Pen Tester

Pyramid ConsultingMcLean, VA, United States
Temporary
Penetration Tester OR Pen Tester.Please review the job description below and contact me ASAP if you are interested.Employee benefits include, but are not limited to, health insurance (medical, dent...Show moreLast updated: 30+ days ago