NewSenior Specialist, MAST Application Penetration Tester KPMGSenior Specialist, MAST Application Penetration TesterNew York, NY$95,855–$208,265 / yearOne or more major ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert (OSWE), Offensive Security Web Assessor (OSWA). If you're looking for a firm with a strong team connection where you can be your whole self, have an impact, advance your skills, deepen your experiences, and have the flexibility and access to constantly find new areas of inspiration and expand your capabilities, then consider a career in Advisory.
NewSenior Penetration Tester Govcio LLCSenior Penetration TesterWashington, DC$124,540–$180,000This role ensures mission‑critical security assurance across enterprise systems, applications, and cloud infrastructures by applying deep technical expertise, zero‑trust principles, and attacker‑focused methodologies. Conduct deep technical analysis of vulnerabilities including buffer overflows, SQL injection, CSRF, XSS, race conditions (TOCTOU), XXE, encryption weaknesses, authentication bypass, and similar issues.
Penetration Automation Tester Donato Technologies IncPenetration Automation TesterAlbany, NY$55–$60 / hourFull timeWe are seeking a skilled Penetration Tester with a focus on Java application security is sought to identify, exploit, and fix vulnerabilities in Java applications to guard against cyber threats.
NewRed Team Cyber Operator Oak Grove Technologies LLCRed Team Cyber OperatorFort Belvoir, VARed Team Apprentice Course (RTAC), Red Team Journeyman Course (RTJC), Certified Red Team Operator (CRTO) certification, Rogue Ops- Red Team 1 (ROPS), Offensive Security Certified Professional (OSCP), Global Information Assurance Certification, (GIAC) Exploit Researcher & Advanced Penetration Tester (GXPN), GIAC Penetration Tester (GPEN), and/or GIAC Web Application Penetration Tester (GWAP) or equivalent red team / penetration testing certifications. Description: Oak Grove Technologies, LLC, a dynamic and fast-growing federal contractor, is seeking a highly skilled and motivated Red Cyber Operator to support advanced Red Cyber operations through the execution of red team assessments, offensive cyber operations, and penetration testing.
NewProduct Security Engineer (Mid-Level) BoeingProduct Security Engineer (Mid-Level)North Charleston, SC$128,350–$173,650 / yearThe Product Security Engineering (PSE) organization is looking for Product Security Engineers (Mid-Level) to join our Cybersecurity Lifecycle teams supporting Boeing Commercial Airplanes (BCA) in North Charleston, South Carolina . The Boeing Company also provides eligible employees with an opportunity to enroll in a variety of benefit programs, generally including health insurance, flexible spending accounts, health savings accounts, retirement savings plans, life and disability insurance programs, and several programs that provide for both paid and unpaid time away from work.
Cybersecurity Analyst, Advanced Naval Nuclear LaboratoryCybersecurity Analyst, AdvancedWest Mifflin, PA$86,100–$134,600 / yearNaval Nuclear Laboratory personnel are FMP employees who work at four DOE facilities: Bettis Atomic Power Laboratory, Knolls Atomic Power Laboratory, Kenneth A. Kesselring Site, and Naval Reactors Facility, and at the U.S. Department of Defense-owned Nuclear Power Training Unit-Charleston. For nearly 70 years, the Naval Nuclear Laboratory has developed advanced nuclear propulsion technology, provided technical support, and trained world-class nuclear operators to ensure the safe and reliable operation of our nation's submarine and aircraft carrier Fleets.
NewVulnerability Management Team Lead Govcio LLCVulnerability Management Team LeadBethesda, MDRemote$150,000–$180,000The VM team’s portfolio of activities includes providing vulnerability detection and remediation oversight, vulnerability research, secure baseline compliance, web application security, host-based security, network security, and acting as security subject matter experts for all of the organization. Provide Subject Matter Expert support and guidance to Information Security Systems Officers (ISSO), System Owners and others as needed through the risk management process and secure configuration baseline management, including regulatory and remediation compliance monitoring.
NewGRC Risk Management Analyst CYNET SYSTEMSGRC Risk Management AnalystSan Jose, CA$68–$72 / hourTemporaryContractorPart timeAdminister risk-based vendor questionnaires covering security governance, data protection, access control, vulnerability management, incident response, business continuity, cloud services, and subcontractor oversight; review responses and supporting evidence, clarify gaps with vendors, and translate findings into risk ratings and remediation actions. Design and use analytics, automation, and AI-assisted workflows to improve questionnaire triage, evidence extraction, control mapping, risk-statement drafting, issue classification, continuous monitoring, and reporting; measure process gains and maintain human approval, secure handling of sensitive data, output validation, auditability, and compliance with organizational AI governance requirements.
NewSpecialist Director, Managed Security Testing KPMGSpecialist Director, Managed Security TestingDenver, CO$169,005–$370,530 / yearIf you're looking for a firm with a strong team connection where you can be your whole self, have an impact, advance your skills, deepen your experiences, and have the flexibility and access to constantly find new areas of inspiration and expand your capabilities, then consider a career in Advisory. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness, and safeguard business operations and company reputation.
NewProduct Security Engineer (Lead) BoeingProduct Security Engineer (Lead)North Charleston, SC$162,350–$219,650 / yearThey will partner with the 787 PSE Capability leader, and be accountable to the Airplane Program Chief Project Engineer (CPE) and Director of Engineering (DoE) for the successful technical planning and performance of PSE for the 787 Airplane Programs, ensuring Engineering Excellence and first-time quality. The Boeing Company also provides eligible employees with an opportunity to enroll in a variety of benefit programs, generally including health insurance, flexible spending accounts, health savings accounts, retirement savings plans, life and disability insurance programs, and several programs that provide for both paid and unpaid time away from work.
NewPrincipal Cybersecurity Engineer with TS/SCI Poly LeidosPrincipal Cybersecurity Engineer with TS/SCI PolyAnnapolis Junction, MD$154,050–$278,475The selected individual will lead all security engineering efforts for a large, complex network environment with geographically distributed systems; and will manage a team of Information Systems Security Officers (ISSOs) and Information Systems Security Engineers (ISSEs), providing technical leadership and direction to meet program requirements. At least twelve years of experience with defense-in-depth principals/technology (including access control, authorization, identification and authentication, public key infrastructure, network and enterprise security architecture) and applying risk assessment methodology to system development.
NewCyber Security Analyst 2 # 26-19151 US Tech Solutions, Inc.Cyber Security Analyst 2 # 26-19151SAN JOSE, CAThe analyst will examine architectures, security controls, configurations, technical evidence, and threat scenarios to identify control gaps, determine business impact, document defensible risk decisions, and support practical remediation. The role will also apply analytics, automation, and AI responsibly to streamline evidence review, improve assessment quality, and accelerate monitoring and reporting while maintaining human validation, data protection, traceability, and appropriate governance.
Senior IT Risk and Compliance Analyst NORC at the University of ChicagoSenior IT Risk and Compliance AnalystWashington, D.C.$97,000–$120,000 / yearWith world-class benefits, a business casual environment, and an emphasis on continuous learning, NORC is a place where people join for the stellar research and analysis work for which we’re known, and stay for the relationships they form with their colleagues who take pride in the impact their work is making on a global scale. Experience conducting incident response across vendors, internal stakeholders, and program owners, including implementing, and coordinating the response plan, overseeing the technical response, and coordinating with legal, technical, and communications teams.
Application Security Architect Vaco LLCApplication Security ArchitectTampa, FLRemote$180,000–$200,000 / yearDetermining compensation for this role (and others) at Vaco by Highspring depends upon a wide array of factors including but not limited to: the individual’s skill sets, experience and training; licensure and certification requirements; office location and other geographic considerations; other business and organizational needs. Determining compensation for this role (and others) at Vaco/Highspring depends upon a wide array of factors including but not limited to the individual’s skill sets, experience and training, licensure and certifications, office location and other geographic considerations, as well as other business and organizational needs.
Security Architect Vaco LLCSecurity ArchitectAddison, TXRemote$110–$130 / hourData Risk / Protection – Assessing Data Flows / Storage / Access Patterns / Sensitive Data Controls | Recommending Improvements to Encryption / Data Masking / Access Governance / Monitoring / Databricks Security Configurations / Varonis Data Classification / Access Auditing / Insider Threat Monitoring. Network Security / Vulnerability Management – Evaluating Network Architectures / Segmentation Strategies / Perimeter Controls / Zero-Trust Controls | Partnering with Infrastructure / Operations Teams to Prioritize Vulnerability Remediation / Recommend Architectural Changes Reducing Security Exposure.
NewLead Security Engineer Dev Technology GroupLead Security EngineerSuitland, MD$120,000–$190,000 / yearAs a Washington Post Top Workplace award winner for the past THIRTEEN years in a row, the Top Workplaces USA for the past five years, and a recipient of the Companies As Responsive Employers (CARE) Award for the past six years, Dev Technology employees enjoy: Generous and flexible time-off policy. Collaborate with application developers, data engineers, systems engineers, and OIS to identify and mitigate vulnerabilities, and provide expert security consultation to development teams.
NewThreat Detection & Automation Engineer (with focus on Data Engineering) Northwestern MutualThreat Detection & Automation Engineer (with focus on Data Engineering)Milwaukee, WI$143,920–$215,880 / yearAs a member of our team, you will play a pivotal role in designing, building and maintaining continuous and sustainable automated pipelines with the goal of enhancing the efficiency, effectiveness and accuracy of cybersecurity teams’ capabilities reducing manual tasks for the IRC teams and enable data-driven cybersecurity operations. Programming Languages - Programming Languages: Demonstrates proficiency in one or more programming languages to execute activities, tasks, practices, and deliverables associated with writing and modifying programs and scripts that comprise an application system; designs, codes, tests, and installs complex computer programs and maintains detailed documentation of programming tasks.
Cloud Infrastructure Engineer II System OneCloud Infrastructure Engineer IIRogers, AR$90,000–$110,000 / yearAs a core member of the Cloud Infrastructure group, you will partner closely with the Cloud Engineering Team, Technology Services senior staff, and leadership to deliver reliable, secure, and scalable cloud solutions that keep business operations running smoothly. Collaboration & Documentation Work closely with the Cloud Engineering Team, Technology Services leadership, and cross-functional partners on new initiatives and break/fix requests.
NewCybersecurity Consultant III, Application Security (Greensboro, NC) Kaiser PermanenteCybersecurity Consultant III, Application Security (Greensboro, NC)Greensboro, NCIn addition to responsibilities listed below, this position is responsible for reviewing application source code for potential security vulnerabilities under the guidance of more senior application security consultants by performing manual and automated security testing on applications in a running state (DAST); working with DevOps teams to integrate application security services; training DevOps personnel and developers to use application security tools; working one-on-one with developers to help them understand security vulnerabilities at hand and to identify/suggest remediation plans; and recommending application security training paths. Completes work assignments by applying up-to-date knowledge in subject area to meet deadlines; following procedures and policies, and applying data and resources to support projects or initiatives; collaborating with others, often cross-functionally, to solve business problems; supporting the completion of priorities, deadlines, and expectations; communicating progress and information; identifying and recommending ways to address improvement opportunities when possible; and escalating issues or risks as appropriate.
NewSenior Cybersecurity Engineer, GRC Automation and Continuous Control Monitoring Marathon PetroleumSenior Cybersecurity Engineer, GRC Automation and Continuous Control MonitoringSan Antonio, TXCybersecurity Risk Management - The process of developing cyber risk assessment and treatment techniques that can effectively pre-empt and identify significant security loopholes and weaknesses, demonstrating the business risks associated with these loopholes and providing risk treatment and prioritization strategies to effectively address the cyber-related risks, threats and vulnerabilities, ensuring appropriate levels of protection, confidentiality, integrity and privacy in alignment with the security framework. The role collaborates closely with Cyber Fusion, Enterprise Architecture, and Cyber Engineering, to design and build deterministic control-testing logic where deterministic approaches are enough; and AI agents and LLM-backed workflows where reasoning, summarization, or judgment is required, such as evidence-to-control mapping, attestation drafting, drift detection, and audit-package assembly.