远程工作雷达

渗透测试分析师

Penetration Tester Analyst

开发工程限定地区(需当地身份)
公司Dragonfli Group
薪资未公开
工作地点United States
地域资格限定地区(需当地身份)
时区要求日间重叠约 9 小时,基本正常作息
用工类型Full Time
发布时间今天
数据来源Himalayas
前往 Himalayas 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

Dragonfli Group 是一家网络安全和IT咨询公司,为联邦机构和财富100强企业提供服务。总部位于华盛顿特区,Dragonfli 在现场、混合和完全远程环境中帮助客户保护关键任务系统。
Dragonfli Group 正在寻找一名渗透测试分析师加入一个快速增长的渗透测试工作流,支持一家大型联邦机构。在这个全远程职位中,您将为授权的渗透测试活动提供分析和支持,包括测试准备、侦察、证据收集、文档记录和报告,以实现快速验证。您将协助维护测试日程和范围记录,支持在批准的授权边界内进行受控发现和枚举,并将发现和修复建议记录到最终评估报告中。您还将协助处理面向外部的资产发现、CISA WAS 和 FAST 结果、KEV 暴露项以及漏洞披露计划(VDP)提交,并使用经批准的自动化和AI驱动工具来改进数据收集、关联和报告流程。该职位适合具有2至4年渗透测试、漏洞评估或相关网络安全领域经验的候选人。
这是一项涉及大型美国联邦机构的多年合同职位。有之前联邦承包经验的候选人优先考虑。需要美国公民身份或永久居留权。如果被录用,所有与该职位相关的工作必须在美国本土进行。
这是一个全远程职位。
主要职责:

  • 通过维护测试日程、范围记录、利益相关者协调笔记和必要的预评估文档,支持评估规划。
  • 协助在批准的授权范围内进行受控发现、枚举、测试支持和证据采集。
  • 记录发现、受影响资产、所有权、可重现性细节、修复建议和重新测试要求,以便包含在最终报告中。
  • 支持对外部资产发现、CISA WAS 和 FAST 结果、KEV 暴露项和 VDP 提交的验证和分类。
  • 协调每日状态输入、会议笔记、行动跟踪和针对指定测试活动的后续支持。
  • 使用经批准的自动化和AI驱动工具来改进数据收集、关联和报告流程。
查看英文原文

Description
Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.
Dragonfli Group is seeking a Pen Testing Analyst to join a growing Penetration Testing workstream supporting a large federal agency. In this fully remote role, you will provide analytical and hands-on support for authorized penetration testing activities, including test preparation, reconnaissance, evidence collection, documentation, and reporting for rapid validation efforts. You will help maintain test schedules and scope records, support controlled discovery and enumeration within approved authorization boundaries, and document findings and remediation recommendations for inclusion in final assessment reports. You will also assist with triage of external-facing asset findings, CISA WAS and FAST results, KEV exposure items, and Vulnerability Disclosure Program (VDP) submissions, and will use approved automation and AI-enabled tools to improve data collection, correlation, and reporting workflows. This role is well suited to a candidate with approximately 2 to 4 years of relevant experience in penetration testing, vulnerability assessment, or a closely related cybersecurity discipline.
This is a multi-year contract position involving a large US federal agency. Candidates with previous federal contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.
This is a fully remote position.
Key Responsibilities:

  • Support assessment planning by maintaining test schedules, scope records, stakeholder coordination notes, and required pre-assessment documentation.
  • Assist with controlled discovery, enumeration, testing support, and evidence capture within approved authorization boundaries.
  • Document findings, affected assets, ownership, reproducibility details, remediation recommendations, and retest requirements for inclusion in final reports.
  • Support validation and triage of external-facing asset findings, CISA WAS and FAST results, KEV exposure items, and VDP submissions.
  • Coordinate daily status inputs, meeting notes, action tracking, and after-action support for assigned testing activities.
  • Use approved automation and AI-enabled tools to improve data collection, initial correlation, draft reporting, and testing workflow efficiency.

Requirements
Must-Have

  • U.S. Citizenship or Permanent Residency (required for this federal engagement)
  • Approximately 2 to 4 years of experience in penetration testing, vulnerability assessment, or a related offensive/defensive cybersecurity role
  • Working knowledge of common penetration testing methodologies and tools (e.g., Burp Suite, Nmap, Metasploit, or equivalents)
  • Familiarity with reconnaissance, enumeration, and evidence collection within authorized testing boundaries
  • Strong written documentation skills for findings, reproducibility steps, and remediation recommendations
  • Ability to work fully remote with reliable, secure connectivity

Preferred / Nice-to-Have

  • Previous federal contracting experience
  • Exposure to CISA Web Application Scanning (WAS) and Fast Attack Surface Testing (FAST) programs
  • Familiarity with Known Exploited Vulnerabilities (KEV) catalog and Vulnerability Disclosure Program (VDP) triage
  • Relevant certifications such as Security+, CEH, GPEN, or OSCP (or actively pursuing)
  • Experience using AI-enabled or automation tools to support testing and reporting workflows

Skill(s)
Technical Skills

  • Penetration testing fundamentals and common toolsets
  • Vulnerability scanning, enumeration, and evidence capture
  • Report writing and findings documentation
  • Familiarity with CISA WAS/FAST, KEV, and VDP processes
  • Comfort with automation and AI-enabled testing support tools

Soft Skills

  • Strong written and verbal communication
  • Attention to detail and thorough documentation habits
  • Ability to work independently in a remote, distributed team
  • Collaborative coordination with stakeholders and testing leads
  • Time management across concurrent assessment activities

Benefits

  • Dragonfli Group offers a comprehensive benefits package that includes:
  • Medical, Multiple POS health plan options including an HSA-compatible plan
  • Dental, PPO coverage for preventive, basic, and major services
  • Vision, Annual exam, frames, lenses, and contact lens allowance
  • 401(k), Employer match up to 5% of eligible compensation
  • Long-Term Disability, 100% employer-paid coverage at 50% of pre-disability earnings
  • Life Insurance and AD&D, 100% employer-paid coverage valued at $10,000 each
  • PTO, 15 to 25 days annually based on tenure
  • Paid Federal Holidays, All 11 federal holidays observed

Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

← 返回全部职位