Not SpecifiedCompensation
Senior (5 to 8 years)Experience Level
Full TimeJob Type
NoVisa
Cybersecurity, Information Technology, Security OperationsIndustries

Penetration Tester

Employment Type: Full-Time

Position Overview

UltraViolet Cyber is seeking an experienced Penetration Tester with a background in Web Applications, Network, and Cloud Security. This individual will play a key role in conducting penetration tests as one of the core capabilities of UltraViolet Cyber and our customers. The penetration tester will execute simulated attacks against client information technology systems to demonstrate susceptibility to such attacks by an adversary, similar to how an advanced persistent threat (APT) would attempt to breach into an organizations' information systems. Qualified candidates must be able to assess target systems, identify vulnerabilities, safely exploit those vulnerabilities, and effectively communicate the risk to the client.

About UltraViolet Cyber

UltraViolet Cyber is a leading platform-enabled unified security operations company providing a comprehensive suite of security operations solutions. Founded and operated by security practitioners with decades of experience, the UltraViolet Cyber security-as-code platform combines technology innovation and human expertise to make advanced real-time cybersecurity accessible for all organizations by eliminating risks of separate red and blue teams. By creating continuously optimized identification, detection, and resilience from today’s dynamic threat landscape, UltraViolet Cyber provides both managed and custom-tailored unified security operations solutions to the Fortune 500, Federal Government, and Commercial clients. UltraViolet Cyber is headquartered in McLean, Virginia, with global offices across the U.S. and in India.

Responsibilities

  • Conduct web application, Application Programming Interface (API), network, and cloud penetration tests.
  • Use common penetration testing and red-team tools, tactics, techniques, and procedures.
  • Analyze Proof of Concept (PoC) exploits to understand the underlying vulnerability and tailor the PoC to be safely used in target space.
  • Automate Red Teaming and Penetration Testing techniques, to efficiently scale offensive operations, using common scripting and programing languages (e.g. Golang, Python, JavaScript, Bash, PowerShell, etc.).
  • Conduct security assessments of cloud environments and application source code review.
  • Conduct penetration tests in accordance with standard methodologies (i.e. OWASP, NIST, PTES).
  • Utilize custom penetration testing tools, frameworks, and infrastructure.
  • Assess risk of discovered vulnerabilities based on likelihood and severity of exploitation.
  • Document and deliver technical reports on detailed findings and vulnerability remediation recommendations.
  • Collaborate with clients throughout an assessment on status and vulnerability information.
  • Evolve our capabilities and toolset.

Requirements

  • Penetration Testing in three (3) or more of the following:
    • Web Applications
    • External Networks
    • Internal Networks
    • Active Directory
    • Cloud Environments (e.g. AWS, Azure, GCP)
  • Familiarity with Security Content Automation Protocols (SCAP), Common Vulnerabilities and Exposures (CVE), Common Vulnerability Scoring System (CVSS), Common Weakness Enumeration (CWE), or Common Platform Enumeration (CPE)
  • Understanding US Government Configuration Baseline (USGCB), Security Technical Implementation Guides (STIGs), NSA Guides, National Checklist Program (NCP) or Common Secure configurations
  • Tools / Services:
    • NMAP
    • BurpSuite
    • CrackMapExec
    • BloodHound
    • Ansible
    • Terraform
    • Git
    • AWS

Minimum Requirements

  • Bachelor’s Degree in Cybersecurity or related field preferred.
  • At least 2 years of experience related to conducting penetration tests or red-team assessments.
  • Offensive Security Certified Professional (OSCP) preferred but not required: OSCP experience and knowledge is highly preferred.
  • US Citizenship required.
  • Candidates must be willing to be submitted for a US Government background investigation.

What We Offer

  • 401(k), including an employer match of 100% of the first 3% contributed and 50% of the next 3% contributed.

Application Instructions

No third-party candidates will be considered.

Skills

Penetration Testing
Web Application Security
Network Security
Cloud Security
Vulnerability Assessment
Exploitation
Risk Communication
SCAP
CVE
CVSS
CWE

UltraViolet Cyber

Unified defensive and offensive cybersecurity solutions

About UltraViolet Cyber

UltraViolet Cyber focuses on enhancing cybersecurity for organizations by integrating both defensive and offensive security operations. Their main services include Managed Detection and Response (MDR), which provides continuous monitoring and response to cyber threats, and Penetration Testing as a Service, where they simulate cyber attacks to find and fix vulnerabilities. This company stands out from competitors by combining the expertise of Red Team (offensive) and Blue Team (defensive) professionals, ensuring that security measures are both proactive and reactive. The goal of UltraViolet Cyber is to help organizations improve their resilience against cyber threats and protect their sensitive data and infrastructure effectively.

McLean, VirginiaHeadquarters
2023Year Founded
$4MTotal Funding
SERIES_ACompany Stage
CybersecurityIndustries
201-500Employees

Benefits

Health Insurance
Dental Insurance
Vision Insurance
Life Insurance
Disability Insurance
401(k) Company Match
401(k) Retirement Plan
Unlimited Paid Time Off
Paid Holidays

Risks

Increased competition from larger firms may pressure UltraViolet Cyber's market share.
Rapid evolution of AI-driven threats may outpace current capabilities, requiring investment.
Integration challenges from the merger could lead to operational inefficiencies and dissatisfaction.

Differentiation

UltraViolet Cyber unifies defensive and offensive security operations for comprehensive threat management.
The company offers Managed Detection and Response and Penetration Testing as a Service.
Security as Code platform automates threat detection, providing a unified risk picture.

Upsides

Growing demand for cloud security solutions offers expansion opportunities for UltraViolet Cyber.
Interest in AI-driven cybersecurity tools aligns with UltraViolet Cyber's automation focus.
Rising need for advanced penetration testing services due to RaaS models benefits UltraViolet Cyber.

Land your dream remote job 3x faster with AI