Find Jobs
Find Jobs Near You – Available Work in Your Location
Vulnerability Assessment Analyst and Penetration Tester (CA)
Career Insights for Vulnerability Analyst / Penetration Tester
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on California data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Vulnerability Analyst or Penetration Tester probes for and exploits security vulnerabilities in web-based applications, networks and systems. Penetration Tests are designed to achieve a specific, attacker-simulated goal and should be requested by customers who are already at their desired security posture. A typical goal could be to access the contents of the prized customer database on the internal network, or to modify a record in an HR system. Vulnerability Assessments are designed to yield a prioritized list of vulnerabilities and are generally for clients who already understand they are not where they want to be in terms of security. The customer already knows they have issues and simply need help identifying and prioritizing them.
$125,034 / year median in California
+2% projected growth
Job Description
Responsibilities:
- Perform manual assessment of systems, services, and software; specializing in security issues beyond those identified by static analysis tools.
- Ensures services, applications, and websites are designed and implemented to the highest security standards.
- Responsible for application and hardware penetration testing, automating repetitive tasks using various scripting languages, mentoring, and leading other engineers to deliver complex penetration tests and vulnerability assessments.
- Drive automation, tooling, efficiency, and advance the teams penetration testing capabilities.
- Create threat mitigation plans. Required Skills
- Must be US Citizen due to government requirement
- Must have an active DoD Secret
- Five years of hands-on penetration testing experience with operating systems, web applications, and network infrastructure.
- Administrator-level knowledge of Windows and Linux Server operating systems
- preferred.
- Experience with operating system security.
- Competent with testing frameworks and tools, such as Burp Suite, Metasploit, Cobalt Strike, Kali Linux, Nessus, PowerShell Empire.
- Knowledge of the functionality and capabilities of computer network defense technologies, including router Access Control Lists (ACLs), firewalls, Intrusion Detection System (IDS)/Intrusion Prevention System (IPS), antivirus/Endpoint Detection and Response (EDR), and web content filtering.
- Strong written and verbal communication skills, including the ability to explain complex technical topics to non-technical audiences.
- Possess one of the following certifications upon onboarding: o Offensive Security Certified Professional (OSCP) o Offensive Security Web Assessor (OSWA) o GIAC Web Application Penetration Tester (GWAPT) o GIAC Penetration Tester (GPEN)
- Obtain one of the following certifications within 9 months of onboarding: o GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) o Offsec Experienced Penetration Tester (OSEP) o Offsec Web Expert (OSWE)