Mid Security Engineer / Internal Penetration Tester

Engineering · United States · Remote possible

Job description

EMPLOYER IS A CONTRACTOR FOR THE U.S. GOVERNMENT. THIS POSITION WILL REQUIRE U.S. CITIZENSHIP.

Role Description:

We are seeking a talented and experienced Mid Security Engineer / Internal Penetration Tester to join our dynamic team and play a crucial role in assessing and validating the security posture of IT systems and internally developed software.  In this role, you will be responsible for conducting comprehensive security assessments and penetration tests to identify vulnerabilities and weaknesses in IT systems, applications, and software. You will leverage your technical expertise and industry knowledge to evaluate security controls and provide actionable recommendations to enhance our security posture.

The listed responsibilities are not exhaustive and additional responsibilities may be assigned based on the evolving needs of the organization. We are seeking a dynamic individual who is able to adapt and take on new responsibilities as they arise.

Responsibilities:

  • Conduct in-depth security assessments and penetration tests of IT systems, applications, and software to identify vulnerabilities, misconfigurations, and weaknesses. Evaluate security posture of AWS and Azure Cloud configurations, public-facing company websites, and open-source projects.
  • Utilize industry-standard methodologies and tools to perform reconnaissance, vulnerability scanning, exploitation, and post-exploitation activities.
  • Analyze assessment findings and prioritize risks based on severity and potential impact to business operations.
  • Develop detailed and well-written assessment reports outlining identified vulnerabilities, exploitation techniques, and recommended remediation strategies.
  • Collaborate with internal stakeholders to review assessment results, discuss findings, and provide guidance on remediation efforts.
  • Work closely with development and IT teams to integrate security best practices into the software development lifecycle (SDLC) and infrastructure design.
  • Stay updated on emerging security threats, attack techniques, and security trends to enhance testing methodologies and approaches.
  • Contribute to security awareness knowledge sharing and professional development initiatives within the company, potentially including training initiatives such as Lunch & Learns and internal blog posts.

Preferred Experience and Qualifications:

  • 3+ years of experience in cybersecurity roles, with a focus on penetration testing.
  • Deep understanding of Kubernetes clusters and hosting containerized applications, common security vulnerabilities, attack vectors, and exploitation techniques.
  • Experience with web application security testing, including OWASP Top 10 vulnerabilities and secure coding practices.
  • Knowledge of network security principles, protocols, and technologies (e.g., TCP/IP, VPN, IDS/IPS).
  • Proficiency in conducting security assessments and penetration tests using tools such as Metasploit, Burp Suite, Nmap, Nessus, and Wireshark.
  • Excellent analytical and problem-solving skills, with the ability to assess complex security issues and recommend effective solutions.
  • Strong communication and interpersonal skills, with the ability to interact with clients and stakeholders at all levels.
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field.
  • Relevant certifications (e.g., OSCP, CEH, CISSP, GPEN, Kubernetes-relevant certs) are highly desirable.

Must Haves:  (based on government contract requirements, privileged access, CUI & export-controlled data access):

  • Must be a US citizen
  • Eligible to apply for a security clearance

Travel Expectations/Requirements: 5-10% - This is a remote US based position. Travel would consist of company retreats and team building events/conference attendance.

Full compensation packages are based on candidate experience. Compensation ranges are established using national benchmarking data and apply across all geographic locations within the United States. 

Remote - USA
$167,050$195,000 USD

Who We Are

Defense Unicorns delivers mission value by streamlining software delivery so our customers can focus on the most important challenges. We share a vision of freedom and security for the advancement of progress and innovation. Our commitment to this vision, and to our mission-driven customers, means a commitment to speed, user experience and optionality, without compromising security. Our team is composed of innovators, software engineers, and veterans with decades of experience delivering technology programs across the federal market.

What We Do

We create and deliver secure solutions for continuous software integration and delivery. Defense Unicorns consolidates the best practices for security pipelines, testing, and deployment automation in order to meet the high security requirements valued by mission owners. Our solutions are agnostic by design and we believe that growing a robust ecosystem of secure, cloud-native software solutions can help enterprise customers inside and outside the federal market buy and integrate software more easily.

Who We Serve

Defense Unicorns’ customers are mission-focused leaders across public and private enterprises. We proudly support defense and civil agencies across the U.S. government and we work closely with the creators of leading-edge software solutions to deliver value to the mission-owner by improving the security and consumability of commercial software products.

What We Work On

  • Kubernetes
  • Cloud Environments (AWS/GCP and Azure)
  • Infrastructure-as-code (like Terraform/Pulumi)
  • Continuous Delivery and automation tooling
  • GitOps
  • Containers
  • CNCF projects and open source products and packages
  • Helm/Kustomize-Value Stream Mapping
  • Building and improving security delivery
  • Building Kubernetes and cloud native applications

Benefits Our Unicorns Enjoy

Health:

  • Medical/Dental/Vision
  • Premiums are 100% Company Paid
  • Health Reimbursement Account
  • Life Insurance
  • Disability Insurance

Financial:

  • 401k with Employer Contribution (Regardless of Employee Contribution)
  • Company Stock Options
  • Home Office Setup Budget

Leave:

  • Unlimited paid time off, with a mandatory 10 days off on top of 11 federal government holidays, week of Thanksgiving, last two weeks of December (including New Year’s Day)
  • Paid Parental Leave

Learning:

  • Reimbursement for approved trainings/subscriptions
  • Conferences (travel, lodging, and fees)

Don’t have all the preferred experience or qualifications? Studies show that underrepresented groups like women and people of color are less likely to apply to jobs if they don't meet every requirement listed. 

At Defense Unicorns, we're committed to diversity. If you're enthusiastic about the role but don't match every criteria, we encourage you to apply. You could be the perfect fit for this or another role! Defense Unicorns is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law.

CCPA DISCLOSURE