NewSenior Specialist, MAST Application Penetration Tester KPMGSenior Specialist, MAST Application Penetration TesterChicago, IL$95,855–$208,265 / yearOne or more major ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert (OSWE), Offensive Security Web Assessor (OSWA). If you're looking for a firm with a strong team connection where you can be your whole self, have an impact, advance your skills, deepen your experiences, and have the flexibility and access to constantly find new areas of inspiration and expand your capabilities, then consider a career in Advisory.
Penetration Automation Tester Donato Technologies IncPenetration Automation TesterAlbany, NY$55–$60 / hourFull timeWe are seeking a skilled Penetration Tester with a focus on Java application security is sought to identify, exploit, and fix vulnerabilities in Java applications to guard against cyber threats.
Cybersecurity Analyst, Advanced Naval Nuclear LaboratoryCybersecurity Analyst, AdvancedWest Mifflin, PA$86,100–$134,600 / yearNaval Nuclear Laboratory personnel are FMP employees who work at four DOE facilities: Bettis Atomic Power Laboratory, Knolls Atomic Power Laboratory, Kenneth A. Kesselring Site, and Naval Reactors Facility, and at the U.S. Department of Defense-owned Nuclear Power Training Unit-Charleston. For nearly 70 years, the Naval Nuclear Laboratory has developed advanced nuclear propulsion technology, provided technical support, and trained world-class nuclear operators to ensure the safe and reliable operation of our nation's submarine and aircraft carrier Fleets.
NewVulnerability Management Team Lead Govcio LLCVulnerability Management Team LeadBethesda, MDRemote$150,000–$180,000The VM team’s portfolio of activities includes providing vulnerability detection and remediation oversight, vulnerability research, secure baseline compliance, web application security, host-based security, network security, and acting as security subject matter experts for all of the organization. Provide Subject Matter Expert support and guidance to Information Security Systems Officers (ISSO), System Owners and others as needed through the risk management process and secure configuration baseline management, including regulatory and remediation compliance monitoring.
Security Architect Vaco LLCSecurity ArchitectAddison, TXRemote$110–$130 / hourData Risk / Protection – Assessing Data Flows / Storage / Access Patterns / Sensitive Data Controls | Recommending Improvements to Encryption / Data Masking / Access Governance / Monitoring / Databricks Security Configurations / Varonis Data Classification / Access Auditing / Insider Threat Monitoring. Network Security / Vulnerability Management – Evaluating Network Architectures / Segmentation Strategies / Perimeter Controls / Zero-Trust Controls | Partnering with Infrastructure / Operations Teams to Prioritize Vulnerability Remediation / Recommend Architectural Changes Reducing Security Exposure.
NewSpecialist Director, Managed Security Testing KPMGSpecialist Director, Managed Security TestingSan Francisco, CA$169,005–$370,530 / yearIf you're looking for a firm with a strong team connection where you can be your whole self, have an impact, advance your skills, deepen your experiences, and have the flexibility and access to constantly find new areas of inspiration and expand your capabilities, then consider a career in Advisory. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness, and safeguard business operations and company reputation.
NewGRC Risk Management Analyst CYNET SYSTEMSGRC Risk Management AnalystSan Jose, CA$68–$72 / hourTemporaryContractorPart timeAdminister risk-based vendor questionnaires covering security governance, data protection, access control, vulnerability management, incident response, business continuity, cloud services, and subcontractor oversight; review responses and supporting evidence, clarify gaps with vendors, and translate findings into risk ratings and remediation actions. Design and use analytics, automation, and AI-assisted workflows to improve questionnaire triage, evidence extraction, control mapping, risk-statement drafting, issue classification, continuous monitoring, and reporting; measure process gains and maintain human approval, secure handling of sensitive data, output validation, auditability, and compliance with organizational AI governance requirements.
Application Security Architect Vaco LLCApplication Security ArchitectTampa, FLRemote$180,000–$200,000 / yearDetermining compensation for this role (and others) at Vaco by Highspring depends upon a wide array of factors including but not limited to: the individual’s skill sets, experience and training; licensure and certification requirements; office location and other geographic considerations; other business and organizational needs. Determining compensation for this role (and others) at Vaco/Highspring depends upon a wide array of factors including but not limited to the individual’s skill sets, experience and training, licensure and certifications, office location and other geographic considerations, as well as other business and organizational needs.
Senior IT Risk and Compliance Analyst NORC at the University of ChicagoSenior IT Risk and Compliance AnalystChicago, Illinois$97,000–$120,000 / yearWith world-class benefits, a business casual environment, and an emphasis on continuous learning, NORC is a place where people join for the stellar research and analysis work for which we’re known, and stay for the relationships they form with their colleagues who take pride in the impact their work is making on a global scale. Experience conducting incident response across vendors, internal stakeholders, and program owners, including implementing, and coordinating the response plan, overseeing the technical response, and coordinating with legal, technical, and communications teams.
NewPrincipal Cybersecurity Engineer with TS/SCI Poly LeidosPrincipal Cybersecurity Engineer with TS/SCI PolyAnnapolis Junction, MD$154,050–$278,475The selected individual will lead all security engineering efforts for a large, complex network environment with geographically distributed systems; and will manage a team of Information Systems Security Officers (ISSOs) and Information Systems Security Engineers (ISSEs), providing technical leadership and direction to meet program requirements. At least twelve years of experience with defense-in-depth principals/technology (including access control, authorization, identification and authentication, public key infrastructure, network and enterprise security architecture) and applying risk assessment methodology to system development.
NewLead Security Engineer Dev Technology GroupLead Security EngineerSuitland, MD$120,000–$190,000 / yearAs a Washington Post Top Workplace award winner for the past THIRTEEN years in a row, the Top Workplaces USA for the past five years, and a recipient of the Companies As Responsive Employers (CARE) Award for the past six years, Dev Technology employees enjoy: Generous and flexible time-off policy. Collaborate with application developers, data engineers, systems engineers, and OIS to identify and mitigate vulnerabilities, and provide expert security consultation to development teams.
Cloud Infrastructure Engineer II System OneCloud Infrastructure Engineer IIRogers, AR$90,000–$110,000 / yearAs a core member of the Cloud Infrastructure group, you will partner closely with the Cloud Engineering Team, Technology Services senior staff, and leadership to deliver reliable, secure, and scalable cloud solutions that keep business operations running smoothly. Collaboration & Documentation Work closely with the Cloud Engineering Team, Technology Services leadership, and cross-functional partners on new initiatives and break/fix requests.
NewCybersecurity Consultant IV, Application Security (Greensboro, NC) Kaiser PermanenteCybersecurity Consultant IV, Application Security (Greensboro, NC)Greensboro, NC$121,000Essential Responsibilities: Completes work assignments and supports business-specific projects by applying expertise in subject area; supporting the development of work plans to meet business priorities and deadlines; ensuring team follows all procedures and policies; coordinating and assigning resources to accomplish priorities and deadlines; collaborating cross-functionally to make effective business decisions; solving complex problems; escalating high priority issues or risks, as appropriate; and recognizing and capitalizing on improvement opportunities. Job Summary: In addition to responsibilities listed below, this position is responsible for reviewing application source code for potential security vulnerabilities by performing manual and automated security testing on applications in a running state (DAST); working with DevOps teams to integrate application security services; training DevOps personnel and developers to use application security tools; working one-on-one with developers to help them understand security vulnerabilities at hand and to identify/suggest remediation plans; and recommending application security training paths.
Application Security Engineer JobotApplication Security EngineerSan Francisco, CA$50–$80 / hourInformation collected and processed as part of your Jobot candidate profile, and any job applications, resumes, or other information you choose to submit is subject to Jobot's Privacy Policy, as well as the Jobot California Worker Privacy Notice and Jobot Notice Regarding Automated Employment Decision Tools which are available at jobot.com/legal. Integrate security tooling (Semgrep, Snyk, CodeQL, GitHub Advanced Security, Burp Suite) into CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins) with minimal developer friction.
Product Security Engineer/Penetration Tester/ Hardware Engineer Pyramid Consulting, IncProduct Security Engineer/Penetration Tester/ Hardware EngineerDuluth, GA$60–$70 / hourBy applying to our jobs you agree to receive calls, AI-generated calls, text messages, or emails from Pyramid Consulting, Inc. and its affiliates, and contracted partners. Collaborate with engineering and product teams to integrate security throughout the Secure Development Lifecycle (SDLC).
Senior Penetration Tester Goldbelt IncorporatedSenior Penetration TesterNY$90,000–$150,000 / yearMinimum Qualifications: • Minimum six (6) years proven proficiency in performing extensive vulnerability assessment and penetration testing • Minimum three (3) years of experience with testing tools, including NESSUS, METASPLOIT, CANVAS, NMAP, Burp Suite, and Kismet • Minimum three (3) years of experience with network vulnerability assessments and penetration testing methods • Minimum three (3) years of experience with writing testing assessment reports • Minimum two (2) years of experience with using, administering, and troubleshooting a WINDOWS Server, IIS • Minimum two (2) years of experience with using, administering, and troubleshooting a major version of Linux • Minimum two (2) years of experience PCI DSS testing • Possess a certification in penetration testing, such as: • Licensed Penetration Tester (LPT) • Certified Expert Penetration Tester (CEPT) • Certified Ethical Hacker (CEH) • Global Information Assurance Certification Penetration Tester (GPEN) • Experience scripting in Perl, Python, Ruby, Bash, or Java • Experience with wireless LAN security testing. • Reports the nature of identified cybersecurity risks and recommends risk mitigation measures to improve the cybersecurity posture of the enterprise.
Senior Penetration Tester, Vice President MUFG Americas Holdings CorpSenior Penetration Tester, Vice PresidentJersey City, NJ$158,000–$194,000 / yearAdditionally, our Total Rewards program provides colleagues with a competitive benefits package (in accordance with the eligibility requirements and respective terms of each) that includes comprehensive health and wellness benefits, retirement plans, educational assistance and training programs, income replacement for qualified employees with disabilities, paid maternity and parental bonding leave, and paid vacation, sick days, and holidays. This position evaluates the security posture of traditional enterprise systems in a highly regulated environment, focusing on identifying exploitable vulnerabilities, validating controls, and delivering clear, actionable remediation guidance to reduce enterprise risk.
Penetration Tester GD Information TechnologyPenetration TesterRemoteTo ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. Working within Agile DevSecOps teams, the Penetration Tester performs hands‑on exploitation, validates security controls, identifies weaknesses, and collaborates with engineering teams to remediate findings.
Penetration Tester Peraton IncPenetration TesterArlington, VA$86,000–$138,000 / yearAs the worlds leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Common application vulnerabilities and exploits such as outdated components, permissions mis-configurations, lack of input validation, logging/monitoring failures, etc.
Penetration Tester / Active Secret Peraton IncPenetration Tester / Active SecretArlington, VA$86,000–$138,000 / yearPossess one of the following certifications, OR be able to obtain before start date: CCNA Cyber Ops, CCNA-Security, CEH, CFR, Cloud+, CySA+, GCIA, GCIH, GICSP, SCYBER, Security+ CE, SSCP. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies.