QED National logo

Test Engineer III

QED National
  • VA
  • Remote
    11 days ago

    Job Description

    Position Title: Test Engineer III - Penetration Tester

    Location: Remote

    Clearance Requirements: Public Trust Clearance

    Position Status: Full-Time Contract

    Position Description:

    Seneca Resources is seeking an experienced Test Engineer III - Penetration Tester to support advanced cybersecurity testing and offensive security initiatives within a large-scale enterprise environment. This role is ideal for a highly skilled security professional with strong experience in web application, API, network, red team, and purple team penetration testing. The successful candidate will identify vulnerabilities, validate attack paths, assess security controls, and work closely with security engineering and Cyber Security Operations Center (CSOC) teams to improve overall enterprise security. This position offers the opportunity to work with modern offensive security tools, emerging AI-powered security technologies, and established cybersecurity frameworks.

    Key Responsibilities:

    • Perform web application, API, network, and infrastructure penetration testing to identify vulnerabilities and exploitable attack paths.
    • Conduct penetration tests using Burp Suite Professional, DAST tools, Kali Linux, Metasploit Pro, Cobalt Strike, and other industry-standard offensive security tools.
    • Plan and execute Red Team engagements, including reconnaissance, exploitation, privilege escalation, lateral movement, and post-exploitation activities.
    • Conduct authorized phishing and social engineering simulations to evaluate user susceptibility and validate enterprise security controls.
    • Perform Purple Team exercises in collaboration with security engineering and CSOC teams to validate detection, monitoring, alerting, and response capabilities.
    • Apply AI and AI-enabled penetration testing techniques to evaluate emerging attack methods and security risks.
    • Develop scripts and automation using Python and/or PowerShell to support security testing, reconnaissance, vulnerability validation, and reporting.
    • Conduct penetration testing activities supporting PCI-DSS compliance and other applicable security requirements.
    • Analyze vulnerabilities and attack paths and communicate technical findings, business risks, and remediation recommendations to technical and non-technical stakeholders.
    • Document test plans, methodologies, findings, evidence, attack paths, and remediation recommendations through clear technical reports.
    • Apply OWASP Application Security Verification Standard (ASVS) and MITRE ATT&CK frameworks to penetration testing and adversary simulation activities.

    Required Skills/Education:

    • 8+ years of relevant cybersecurity, penetration testing, offensive security, or related experience.
    • Bachelor's degree from an accredited college or university in cybersecurity, information technology, computer science, information systems, or a related field.
    • If the degree is not in an applicable field, 4 additional years of related experience may be substituted.
    • Strong hands-on experience with web application, API, and network penetration testing.
    • Experience using Burp Suite Professional or comparable Dynamic Application Security Testing (DAST) tools.
    • Advanced knowledge of Kali Linux and commonly used penetration testing tools.
    • Experience with Metasploit Pro and Cobalt Strike in authorized red team or adversary simulation engagements.
    • Demonstrated experience planning and executing Red Team and Purple Team engagements.
    • Experience evaluating security monitoring and detection capabilities in collaboration with CSOC/SOC and security engineering teams.
    • Strong scripting and automation skills using Python and/or PowerShell.
    • Knowledge of OWASP ASVS and the MITRE ATT&CK framework.
    • Experience conducting penetration testing in environments subject to PCI-DSS requirements.
    • Strong technical writing and communication skills, including the ability to clearly explain vulnerabilities, exploitation techniques, attack paths, and remediation strategies.
    • Experience with AI security, AI-assisted penetration testing, or penetration testing of AI-enabled applications is highly desirable.
    • A penetration testing or offensive security certification is preferred, such as:
    • Offensive Security Certified Professional (OSCP)
    • GIAC Certified Penetration Tester (GPEN)
    • GIAC Web Application Penetration Tester (GWAPT)
    • GIAC Exploit Researcher and Advanced Penetration Tester (GXPN)
    • Other recognized offensive security or penetration testing certifications

    About Seneca Resources

    At Seneca Resources, we are more than just a staffing and consulting firm, we are a trusted career partner. With offices across the U.S. and clients ranging from Fortune 500 companies to government organizations, we provide opportunities that help professionals grow their careers while making an impact. When you work with Seneca, you're choosing a company that invests in your success, celebrates your achievements, and connects you to meaningful work with leading organizations nationwide. We take the time to understand your goals and match you with roles that align with your skills and career path. Our consultants and contractors enjoy competitive pay, comprehensive health, dental, and vision coverage, 401(k) retirement plans, and the support of a dedicated team who will advocate for you every step of the way. Seneca Resources is proud to be an Equal Opportunity Employer, committed to fostering a diverse and inclusive workplace where all qualified individuals are encouraged to apply.

    Numbers & Facts

    LocationVA (
    Remote
    )
    IndustryStaffing/Employment Agencies
    Company Size50 to 99 employees
    Year Founded1993
    Websitehttp://www.qednational.com/

    About Company

    QED National is a certified Women-Owned Business Enterprise with WBE certification in New York City, New York State, New Jersey and Delaware. A trusted IT advisor to both public and private sector customers, QED National is headquartered in New York City with offices in Albany, NY. Driven by 24 years of industry expertise and guided by strong, ethical practices, QED National helps clients achieve their business objectives by providing innovative IT consulting, reliable staff augmentation and scalable technology solutions that are custom tailored for their needs. Our outstanding service has earned us an extraordinary client retention rate of ninety-five percent.

    PRACTICE AREAS

    Cyber / Information Security

    • Assessments and consulting
    • Advanced security technologies and implementation support services

    IT Management Consulting

    • Data Analytics
    • Project & Program Management
    • Enterprise Architecture and Systems Engineering
    • Governance, Risk & Compliance
    • IT Strategy

    IT Staff Augmentation

    • Providing highly qualified, reliable consultants at cost-effective rates, backed by our reputation for integrity & professionalism

    Technology Solutions

    • A comprehensive portfolio of products and services including, but not limited to RSA, Checkpoint, Information Builders, Commvault, EMC and Schneider Electric/APC

    QED National is led by a strong management team, under the direction of founder and president, Colleen Molter.  Working with selected organizations, chosen for their outstanding products and support services, QED National delivers expert solutions ranging from IT assessments and governance to intelligent data storage and staff augmentation. It all adds up to comprehensive, customized IT business solutions.

    Esteemed Clients and Sustained Growth

    A New York City and New York State Certified Women-Owned Business Enterprise, QED National is a privately held company in continuous operation since 1993.  Recipient of New York City, New York State, Florida, California and Fortune 500 contracts, QED National is proud to have sustained success and growth, including “Inc. Magazine’s 5000 Fastest Growing Firms in America” for nine consecutive years —2009 through 2017. View our full roster of awards.

    QED National humbly, yet firmly, acknowledges its reputation among its clients as a partner that responds diligently—and expeditiously—to provide the highest quality services. The QED National team ambitiously looks forward to all future opportunities to provide such services.

    Skills

    • Analysis Skillsunmatched
    • Application Programming Interface (API)unmatched
    • Applications Securityunmatched
    • Artificial Intelligence (AI)unmatched
    • Automationunmatched
    • Communication Skillsunmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Consultingunmatched
    • Documentation Planunmatched
    • Enterprise Protectionunmatched
    • Fortune 500 Customersunmatched
    • GIAC - Global Information Assurance Certificationunmatched
    • GPEN - GIAC Penetration Testerunmatched
    • Government Organizationsunmatched
    • Industry Standardsunmatched
    • Information Technology & Information Systemsunmatched
    • Internet Applicationunmatched
    • Internet Securityunmatched
    • Linux Operating Systemunmatched
    • Metasploitunmatched
    • Network Securityunmatched
    • PCI-DSSunmatched
    • Penetration Testingunmatched
    • Phishingunmatched
    • Python Programming/Scripting Languageunmatched
    • Quality Assurance Methodologyunmatched
    • Scripting (Scripting Languages)unmatched
    • Security Analysisunmatched
    • Security Attacksunmatched
    • Security Complianceunmatched
    • Security Monitoringunmatched
    • Simulationunmatched
    • Social Engineeringunmatched
    • Software Testingunmatched
    • Technical Writingunmatched
    • Test Plan/Scheduleunmatched
    • Test Suiteunmatched
    • Testingunmatched
    • Windows PowerShellunmatched
    • Writing Skillsunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder