Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Penetration Test Engineer - Senior (R-00048) image - Rise Careers
Job details

Penetration Test Engineer - Senior (R-00048)

True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes. True Zero recognizes that said outcomes begin and end with our people, and that is what we have built, a community of like-minded, driven, and passionate individuals and innovators who are aligned in a common goal of delivering top tier services to our customers. In 2023, True Zero was recognized as a “Best Places to Work” in two categories ("Prosperous and Thriving" ($5MM – $50MM in gross revenue) and "Mid-Atlantic Region" (DC, DE, MD, NC, VA, WV)) and in 2022, was recognized as one of Inc. Magazine’s Top 5000 Fastest Growing Companies.


True Zero Technologies is looking for qualified candidates to fulfill the role of Senior Penetration Test Engineer 

 

Job Description 

 

As a Senior Penetration Testing Engineer, you will possess solid industry experience in the public sector and/or commercial spaces; relevant technical certifications; and, proven experience designing, configuring, and conducting a variety of penetration testing situations and scenarios focused on cybersecurity and technology assets and networks. You will have experience packaging, presenting, remediating, and escalating penetration testing results, plans, and actions to appropriate related teams and stakeholders. This position requires strong technical, communications, and problem-solving skills, and the ability to engage and interact with numerous teams. The ideal candidate will have a passion for cybersecurity, the ability to think outside of the box, and be attentive to detail.  Candidates should possess the following qualifications and be able to demonstrate deep competency in most of the requirements listed below: 


Qualifications / Requirements
  • Minimum 5+ years’ experience in a cybersecurity, technology, and/or network penetration testing role, conducting penetration tests or red-team assessments 
  • US citizenship required, and candidates must be willing to be submitted for a US Government background investigation 
  • Experience using common penetration testing tools such as Metasploit Framework and Burp Suite Pro  
  • Experience using and exploiting operating systems including Windows and Linux  
  • Experience with advanced exploitation methods or exploitation development  
  • Experience conducting cyber operations and exploitation  
  • Understanding of common scripting languages  
  • Familiarity with Security Content Automation Protocols (SCAP), Common Vulnerabilities and Exposures (CVE), Common Vulnerability Scoring System (CVSS), Common Weakness Enumeration (CWE), or Common Platform Enumeration (CPE)  
  • Understanding of US Government Configuration Baseline (USGCB), Security Technical Implementation Guides (STIGs), NSA Guides, National Checklist Program (NCP) or Common Secure configurations  
  • Excellent written and verbal communication skills, demonstrating the ability to effectively convey technical information to both technical and non-technical audiences 
  • Experience with a variety of testing use cases including, but not limited to external, internal, social media, cloud providers environments, application toolkits and development, SCADA environments, operational environments, wired and wireless networks, etc. 
  • Education: Bachelor’s Degree in Cybersecurity or related field preferred 

Possess three or more of the following: 
  • Offensive Security Certified Professional (OSCP) 
  • Offensive Security Certified Expert (OSCE)  
  • Offensive Security Wireless Professional (OSWP)  
  • Offensive Security Web Expert (OSWE)  
  • Certified Ethical Hacker (CEH)  
  • EC-Council Certified Security Analyst (ECSA)  
  • Certified Ethical Hacker (CEH) Practical  
  • EC-Council Certified Security Analyst (ECSA) Practical  
  • Licensed Penetration Tester (LPT) Master  
  • Certified Information Systems Security Professional (CISSP)
  • CompTIA PenTest+  
  • GIAC Certified Incident Handler (GCIH)  
  • GIAC Penetration Tester (GPEN)  
  • GIAC Web Application Penetration Tester (GWAPT)  
  • GIAC Exploit Researcher and Advanced Penetration Tester (GXPN)  
  • GIAC Assessing and Auditing Wireless Networks (GAWN)


Responsibilities
  • Conduct web application, mobile application, phishing, network, wireless, and operational technology penetration tests 
  • Conduct security assessments of cloud environments and application source code review 
  • Conduct penetration tests in accordance with standard methodologies (i.e. OWASP, NIST, PTES) 
  • Use common penetration testing and red-team tools, tactics, techniques, and procedures 
  • Utilize custom penetration testing tools, frameworks, and infrastructure 
  • Assess risk of discovered vulnerabilities based on likelihood and severity of exploitation 
  • Deliver technical reports on detailed findings and vulnerability remediation recommendations 
  • Collaborate with clients throughout an assessment on status and vulnerability information 
  • Coach and mentor penetration testing team experts 
  • Provide professional development and human resources management of the team 
  • Participate in business financial management of the penetration team  


We’re actively searching for talented security and technology practitioners who are ready to experience the True Zero difference. As a True Zero team member, you'll enjoy:


- Competitive salary, paid twice per month

- Best in class medical coverage

- 100% of medical premiums covered by True Zero

- Company wide new business incentive programs

- Contribution Incentives (i.e. white papers, blog posts, internal webinars, etc.)

- 3 weeks of PTO starting + 11 Paid Holidays Annually

- 401k Program with 100% company match on the first 4%

- Monthly reimbursement of Cell Phone and Home Internet costs

- Paternity/Maternity Leave

- Investment in training and certifications to broaden and deepen your technical skills

True Zero Technologies Glassdoor Company Review
5.0 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
True Zero Technologies DE&I Review
5.0 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of True Zero Technologies
True Zero Technologies CEO photo
Unknown name
Approve of CEO

Average salary estimate

$110000 / YEARLY (est.)
min
max
$90000K
$130000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Penetration Test Engineer - Senior (R-00048), True Zero Technologies

Join True Zero Technologies as a Senior Penetration Test Engineer, where your expertise will be crucial in enhancing our cybersecurity measures. Located in the D.C./MD/VA area, we are a veteran-owned small business committed to achieving exceptional results through our talented team. As a member of True Zero, you'll take charge of conducting various penetration tests, from web applications to operational technologies, ensuring that our security defenses stay one step ahead of potential threats. Your role will involve designing and executing tests, utilizing cutting-edge tools like Metasploit and Burp Suite Pro, and communicating your findings effectively to both technical and non-technical stakeholders. With a minimum of 5 years' experience and a range of respected certifications under your belt, you’ll thrive in our culture that values innovation, collaboration, and ongoing professional development. You'll benefit from competitive compensation, comprehensive medical coverage, generous PTO, and the chance to grow your skills through continued learning and certification opportunities. Make your mark at True Zero Technologies, where we empower our people to secure digital futures.

Frequently Asked Questions (FAQs) for Penetration Test Engineer - Senior (R-00048) Role at True Zero Technologies
What are the primary responsibilities of the Senior Penetration Test Engineer at True Zero Technologies?

As a Senior Penetration Test Engineer at True Zero Technologies, you'll be responsible for conducting penetration tests across various environments including web applications, mobile apps, and cloud platforms. Your duties will also involve assessing the risks of discovered vulnerabilities, delivering detailed technical reports, and coaching junior team members on best practices in cybersecurity. With a solid focus on effective communications, you'll collaborate with clients and stakeholders to ensure that everyone is informed about vulnerabilities and remediation strategies.

Join Rise to see the full answer
What qualifications are required for the Senior Penetration Test Engineer position at True Zero Technologies?

To qualify for the Senior Penetration Test Engineer role at True Zero Technologies, candidates should have at least 5 years of experience in cybersecurity and penetration testing, along with relevant technical certifications such as OSCP, CEH, or GPEN. A Bachelor’s Degree in Cybersecurity or a related field is preferred. Additionally, candidates must possess strong problem-solving abilities and excellent communication skills to convey technical information effectively to diverse audiences.

Join Rise to see the full answer
What tools and methodologies does the Senior Penetration Test Engineer use at True Zero Technologies?

Senior Penetration Test Engineers at True Zero Technologies leverage a variety of tools and methodologies for their assessments. Common penetration testing tools include Metasploit Framework and Burp Suite Pro, alongside custom frameworks and scripts. You'll also conduct tests following established methodologies such as OWASP, NIST, and PTES, ensuring compliance with security standards and best practices.

Join Rise to see the full answer
How does True Zero Technologies support professional development for Senior Penetration Test Engineers?

True Zero Technologies is dedicated to supporting the growth and development of its team members. As a Senior Penetration Test Engineer, you’ll have access to funding and resources for advanced training and certifications. The company also encourages participation in knowledge-sharing activities, such as writing white papers or hosting internal webinars, so you can stay at the forefront of cybersecurity trends and enhance your technical skills.

Join Rise to see the full answer
What benefits does True Zero Technologies offer to its Senior Penetration Test Engineers?

True Zero Technologies offers a competitive benefits package for its Senior Penetration Test Engineers, including comprehensive medical coverage with premiums fully covered, generous PTO, and 401k matching. Additionally, you'll enjoy monthly reimbursements for cell phone and home internet costs, paternity and maternity leave, and financial incentives for contributing to business development, making it an attractive place to advance your career.

Join Rise to see the full answer
Common Interview Questions for Penetration Test Engineer - Senior (R-00048)
How do you prioritize vulnerabilities discovered during penetration testing?

When prioritizing vulnerabilities, I assess each based on factors like likelihood of exploitation, potential impact, and the specific context of the system. I use frameworks such as CVSS to gauge severity and provide detailed reports to clients, focusing on the most critical issues first to ensure effective remediation.

Join Rise to see the full answer
Can you describe your experience with penetration testing tools?

I have extensive experience using a range of penetration testing tools including Metasploit, Burp Suite, and various command-line utilities in Linux. I believe in utilizing the right tool for the specific use case and have developed custom scripts to automate processes for efficiency.

Join Rise to see the full answer
What steps do you take to ensure thoroughness in a penetration test?

To ensure thoroughness, I follow a systematic approach starting with reconnaissance, scanning, exploitation, and reporting. I use established methodologies like OWASP and PTES and make sure to cover various aspects of the environment, including networks, applications, and cloud services.

Join Rise to see the full answer
How do you communicate your findings to teams or clients?

I follow a structured communication approach where I prepare detailed reports tailored to the technical proficiency of the audience. I emphasize clear and actionable recommendations in my presentations to engage both technical teams and management effectively.

Join Rise to see the full answer
How do you stay updated with the latest cybersecurity threats?

I actively engage with the cybersecurity community through forums, webinars, and conferences. Additionally, I subscribe to industry newsletters and follow influential blogs to stay ahead of emerging threats and tactics used by attackers.

Join Rise to see the full answer
Have you ever had to mentor junior team members? How did you approach this?

Yes, mentoring is a crucial part of my role. I focus on building a supportive environment where I can share my knowledge and experiences. I often conduct training sessions, encourage questions, and provide constructive feedback on their assessments.

Join Rise to see the full answer
What do you consider when testing cloud environments?

When testing cloud environments, I consider shared responsibility models and the unique configurations specific to service providers. Understanding access controls, API security, and potential misconfigurations are critical areas of focus.

Join Rise to see the full answer
Can you explain a challenging penetration test you conducted?

One challenging penetration test involved a complex network environment with multiple layers of security. It required extensive reconnaissance and creative exploitation techniques. I successfully identified critical vulnerabilities and collaborated closely with the client's IT team to ensure effective remediation.

Join Rise to see the full answer
How do you manage your time effectively during a penetration test?

I manage my time by creating a clear schedule with milestones and deliverables. Setting specific priorities helps me focus on critical areas while maintaining flexibility to adapt to any unexpected findings during the assessments.

Join Rise to see the full answer
What role does documentation play in your penetration testing process?

Documentation is essential in my penetration testing process. It ensures traceability of actions taken, maintains a clear record of findings, and facilitates accurate reporting. Well-structured documentation also aids in knowledge transfer for future assessments.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 4 days ago
Photo of the Rise User
Pepperstone Remote No location specified
Posted 5 days ago
Photo of the Rise User
Postscript Remote Remote, Anywhere in North America
Posted 11 days ago
Mission Driven
Customer-Centric
Rapid Growth
Dare to be Different
Fast-Paced
Startup Mindset
Collaboration over Competition
Reward & Recognition
Maternity Leave
Paternity Leave
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Paid Sick Days
Paid Time-Off
Photo of the Rise User
Control Risks Remote No location specified
Posted 14 days ago
Photo of the Rise User
TensorWave Hybrid Silver Springs, MD
Posted 3 days ago
Photo of the Rise User
Sennder Remote Wroclaw, Poland
Posted 13 days ago
Weee! Inc Hybrid Fremont, California, United States
Posted 2 days ago
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
March 11, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
50 people applied to Jr SOC Analyst at IBM
Photo of the Rise User
Someone from OH, North Royalton just viewed Researcher-NBC Sports at NBCUniversal
Photo of the Rise User
Someone from OH, Cleveland just viewed UI Product Designer at Insight Global
Photo of the Rise User
Someone from OH, Cleveland just viewed Getinge is hiring: UI/UX Developer in Streetsboro at Getinge
Photo of the Rise User
Someone from OH, Kent just viewed Graphic Designer, Direct Response at Visa
Photo of the Rise User
12 people applied to IT Intern at USAA
Photo of the Rise User
31 people applied to Cyber Crime Analyst at TEKsystems
Photo of the Rise User
Someone from OH, Columbus just viewed General Application - I want to work at Kiddom! at Kiddom
Photo of the Rise User
37 people applied to SOC Analyst I at Epsilon
Photo of the Rise User
6 people applied to DevOps SRE Engineer at Weekday
G
Someone from OH, Cincinnati just viewed Calling All Stay-at-Home Parents at Global Elite Texas
Photo of the Rise User
Someone from OH, Cincinnati just viewed Proposal Manager – Energy & Power Americas (REMOTE) at Jacobs
S
Someone from OH, Columbus just viewed Senior Project Manager, Learning at Studion
Photo of the Rise User
Someone from OH, Pickerington just viewed Marketing Data Analyst - Contract (10hrs/wk) at Skylight
Photo of the Rise User
Someone from OH, Pickerington just viewed Americas Sales Manager, Kuiper Mobility Business Unit at Amazon
Photo of the Rise User
Someone from OH, Maple Heights just viewed Medical Receptionist at LifeStance Health
Photo of the Rise User
Someone from OH, Cleveland just viewed Support Specialist, Live Ops at DoorDash USA
Photo of the Rise User
Someone from OH, Cleveland just viewed Customer Advocate (Final Dashination) at DoorDash USA
Photo of the Rise User
Someone from OH, Reynoldsburg just viewed Data Analyst (Work From Home / Dayshift) at Twoconnect
S
Someone from OH, Painesville just viewed Senior Project Manager/Delivery Manager at Soname Solutions
Photo of the Rise User
Someone from OH, Zanesville just viewed Account Manager - Loan Agency Services at Alter Domus
Photo of the Rise User
Someone from OH, Springfield just viewed Sr. Coordinator, Talent Acquisition at Cardinal Health
Photo of the Rise User
Someone from OH, Columbus just viewed People ops at Alan
Photo of the Rise User
Someone from OH, Milford just viewed Content Marketing Analyst at Eurofins
Photo of the Rise User
Someone from OH, Columbus just viewed DV - Hotline Specialist On Call at Shelter House
Photo of the Rise User
Someone from OH, Euclid just viewed Behavioral Health Program Director at Altarum
Photo of the Rise User
Someone from OH, Cincinnati just viewed Technical Support Engineer - Developer Support at Motive