View all jobs
Pen Tester
We are seeking Pen Testers for several opportunities in Washington, DC and Public Trust Clearance
Mapped Positions
- Penetration Tester Mid | 3+ years | CBP BI - High Trust
- Penetration Tester Senior | 5+ years | CBP BI - High Trust
- Penetration Tester Junior | 3+ years | CBP BI - High Trust
Job Description
The Contractor shall provide Penetration Testing Support to CBP information systems, including but not limited to:- Provide or assist with penetration testing as requested by Components or System Owners / ISSM / ISSO in support of Security Controls Assessment, Accreditation activities, continuous monitoring, and FISMA requirements.
- Provide penetration testing summary reports to the appropriate System Owner / ISSM / ISSO, Government lead, CBP SOC Manager and document the findings.
- Conduct penetration testing only under very well-defined written conditions, agreed to in advance by the CBP VAT Government Leads, CBP VAT Manager, and appropriate System Owner / ISSM / ISSO.
- Prepare and submit security testing Rules of Engagement (ROE) for Government managerial approval prior to conducting penetration testing.
- Ensure the ROE provides operational security controls to protect both the system and network.
- Provide a detailed report of the findings and recommendations to the System Owner / ISSM / ISSO, Government lead, CBP VAT Manager and archive the data to support remediation activities, retest, and comparative analysis.
- Propose solutions, methodologies, or alternative practices to improve CBP penetration testing capabilities.
- When requested, provide assessments and solutions to vulnerabilities discovered / disclosed by third parties.
- Conduct assessments in conjunction with SOC / CTI / CDF to discover or emulate IOCs, TTPs and Common Weakness Enumerations (CWEs) to further protect systems and networks.
- Be flexible to support penetration testing and / or validation on Information Systems that require testing during non-core hours. This does not provide a requirement to test outside of standard business hours.
- The Penetration Test Team will travel within the Continental United States (CONUS) and Outside the Continental United States (OCONUS) as needed with the costs not to exceed the funding travel line item.
- Travel to be physically on location to perform onsite security assessments of CBP facilities, systems, and applications as requested.
- Maintain a repository of past penetration tests and details of vulnerability findings and remediation.
- Track and maintain records of completed penetration tests for metrics gathering and reporting.
- Conduct wireless access point testing as required on various customer sites located throughout the United States, Puerto Rico, and Guam.
- Conduct RF testing as required on various customer sites located throughout the United States, Puerto Rico, and Guam.
- Assist the Government in performing Mobile Application assessments as requested by Components or System Owners / ISSM / ISSO in support of Security Controls Assessment, Accreditation activities, continuous monitoring, and FISMA requirements.
- Assist the Government in performing Non-Tier 1 HVA assessments as requested.
- Assist the Government in performing Adversarial Assessments (AA) as requested.
- Assist the Government in providing after action / findings reports to the CBP VAT Government Leads, CBP VAT Manager and appropriate System Owner / ISSM / ISSO applicable staff for remediation.