Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Penetration Tester image - Rise Careers
Job details

Penetration Tester

Make a difference here.


UltraViolet Cyber is a leading platform-enabled unified security operations company providing a comprehensive suite of security operations solutions. Founded and operated by security practitioners with decades of experience, the UltraViolet Cyber security-as-code platform combines technology innovation and human expertise to make advanced real-time cybersecurity accessible for all organizations by eliminating risks of separate red and blue teams.


By creating continuously optimized identification, detection, and resilience from today’s dynamic threat landscape, UltraViolet Cyber provides both managed and custom-tailored unified security operations solutions to the Fortune 500, Federal Government, and Commercial clients. UltraViolet Cyber is headquartered in McLean, Virginia, with global offices across the U.S. and in India. 


UltraViolet Cyber (UV Cyber) is seeking an experienced Penetration Tester with a background in Web & Mobile Application testing, Network, and Cloud Security related security assessments. This individual will play a key role in conducting penetration tests as one of the core capabilities of UltraViolet Cyber and in support of our growing customers base. We operate as a collaborative team, unified by integrity, passion, and communication.


The Penetration Tester will execute simulated attacks against client information technology systems to demonstrate susceptibility to such attacks by an adversary, similar to how an advanced persistent threat (APT) would attempt to breach into an organizations' information systems. Qualified candidates must be able to assess target systems, identify vulnerabilities, safely exploit those vulnerabilities, and effectively communicate the risk to the client.


US Citizenship required, and candidates must be willing to be submitted for a US Government background investigation.


No third-party candidates will be considered


Familiarity with Security Content Automation Protocols (SCAP), Common Vulnerabilities and Exposures (CVE), Common Vulnerability Scoring System (CVSS), Common Weakness Enumeration (CWE), or Common Platform Enumeration (CPE)


Understanding US Government Configuration Baseline (USGCB), Security Technical Implementation Guides (STIGs), NSA Guides, National Checklist Program (NCP) or Common Secure configurations


Work You'll Do:
  • Conduct mobile application, web application, Application Programming Interface (API), network, and cloud penetration tests.
  • Use common penetration testing and red-team tools, tactics, techniques, and procedures.
  • Analyze Proof of Concept (PoC) exploits to understand the underlying vulnerability and tailor the PoC to be safely used in target space.
  • Automate Red Teaming and Penetration Testing techniques, to efficiently scale offensive operations, using common scripting and programing languages (e.g. Golang, Python, JavaScript, Bash, PowerShell, etc.).
  • Conduct security assessments of cloud environments and application source code review.
  • Conduct penetration tests in accordance with standard methodologies (i.e. OWASP, NIST, PTES).
  • Utilize custom penetration testing tools, frameworks, and infrastructure.
  • Assess risk of discovered vulnerabilities based on likelihood and severity of exploitation.
  • Document and deliver technical reports on detailed findings and vulnerability remediation recommendations.
  • Collaborate with clients throughout an assessment on status and vulnerability information.
  • Evolve our capabilities and toolset


Penetration Testing in three (3) or more of the following:
  • Web Applications
  • External Networks
  • Internal Networks
  • Active Directory
  • Cloud Environments (e.g. AWS, Azure, GCP)


Tools / Services:
  • NMAP
  • BurpSuite
  • CrackMapExec
  • BloodHound
  • Ansible
  • Terraform
  • Git
  • AWS


What You Have:
  • Bachelor’s Degree in Cybersecurity or related field preferred
  • At least 2 years of experience related to conducting penetration tests or red-team assessments .
  • Offensive Security Certified Professional (OSCP) preferred but not required: OSCP experience and knowledge is highly preferred.
  • Experience performing SAST, DAST, and code reviews


$120,000 - $130,000 a year

UltraViolet Cyber maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect our company's differing products, services, industries and lines of business. Candidates are typically placed into the range based on the preceding factors.



We sincerely thank all applicants in advance for submitting their interest in this position. We know your time is valuable.


UltraViolet Cyber welcomes and encourages diversity in the workplace regardless of race, gender, religion, age, sexual orientation, gender identity, disability, or veteran status. 


If you want to make an impact, UltraViolet Cyber is the place for you! 

Average salary estimate

$125000 / YEARLY (est.)
min
max
$120000K
$130000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Penetration Tester, UltraViolet Cyber

At UltraViolet Cyber, we are on the front lines of cybersecurity, and we’re looking for a talented Penetration Tester to join our dynamic team in a remote capacity. With our state-of-the-art security-as-code platform, we bridge the gap between technology innovation and human expertise to deliver cutting-edge cybersecurity solutions to Fortune 500 companies, the Federal Government, and commercial clients. As a Penetration Tester, you will conduct simulated cyberattacks on client systems, helping them understand vulnerabilities and prepare against real-world threats. Your role is vital, as you will assess the security posture of web and mobile applications, cloud environments, and networks, using various sophisticated tools and techniques. You'll collaborate closely with clients, turning technical findings into understandable insights while delivering comprehensive reports that outline findings and remediation recommendations. This role not only demands technical prowess but also effective communication and teamwork. If you have a background in conducting penetration tests, familiarity with relevant security protocols, and experience with scripting languages, we’d love to speak with you. This position also requires a US Citizenship and the willingness to undergo a background investigation. Join us at UltraViolet Cyber where passion meets expertise and make a meaningful impact in the world of cybersecurity!

Frequently Asked Questions (FAQs) for Penetration Tester Role at UltraViolet Cyber
What are the responsibilities of a Penetration Tester at UltraViolet Cyber?

As a Penetration Tester at UltraViolet Cyber, your primary responsibilities include conducting various types of penetration tests such as web, mobile, API, cloud, and network assessments. You will evaluate target systems for vulnerabilities, safely exploit them, and analyze Proof of Concept (PoC) exploits. Your work will inform clients of vulnerabilities and risks, and you will also automate testing techniques using various scripting languages for efficient operations.

Join Rise to see the full answer
What qualifications are required for the Penetration Tester role at UltraViolet Cyber?

To qualify for the Penetration Tester role at UltraViolet Cyber, candidates should ideally possess a Bachelor’s Degree in Cybersecurity or a related field and have at least 2 years of experience conducting penetration tests or red-team assessments. Familiarity with SCAP, CVE, CVSS, and different security configuration guides is important, and having certifications such as Offensive Security Certified Professional (OSCP) is preferred but not mandatory.

Join Rise to see the full answer
What types of tools will Penetration Testers use at UltraViolet Cyber?

At UltraViolet Cyber, Penetration Testers utilize a wide array of tools including NMAP, BurpSuite, and frameworks like BloodHound and CrackMapExec. You'll also work with automation tools like Ansible and Terraform to enhance your testing capabilities, ensuring that your penetration tests are both comprehensive and effective.

Join Rise to see the full answer
What is the work environment like for a remote Penetration Tester at UltraViolet Cyber?

Working remotely as a Penetration Tester at UltraViolet Cyber offers a collaborative and supportive environment. You'll be part of a dedicated team that values communication, integrity, and a shared passion for cybersecurity. Regular interaction with team members and clients allows for knowledge sharing and growth opportunities, all from the comfort of your home.

Join Rise to see the full answer
What is the expected salary range for a Penetration Tester at UltraViolet Cyber?

The expected salary range for a Penetration Tester at UltraViolet Cyber is between $120,000 and $130,000 a year. However, actual salary placement can vary based on multiple factors such as individual knowledge, skills, experience, and market conditions, reflecting the diverse range of products and services offered by the company.

Join Rise to see the full answer
Common Interview Questions for Penetration Tester
Can you describe your experience conducting penetration tests?

When answering this question, outline specific experiences you’ve had with both web and mobile applications, cloud environments, or network penetration tests. Discuss the methodologies you used, the tools implemented, and any significant vulnerabilities you discovered. Make sure to showcase both your technical skills and the impact of your findings.

Join Rise to see the full answer
How do you prioritize the vulnerabilities you discover during a test?

In your response, explain your approach to risk analysis such as utilizing CVSS scores to evaluate the severity and likelihood of exploitation of vulnerabilities. Emphasize the importance of understanding the business context of the client’s environment and how it informs your prioritization strategy.

Join Rise to see the full answer
What tools do you prefer for penetration testing and why?

Discuss your favorite penetration testing tools such as BurpSuite, NMAP, or any others that you are proficient with. Share what you appreciate about each tool, citing features that enhance your testing efficiency and accuracy, and highlighting your comfort level with them.

Join Rise to see the full answer
How do you stay updated with the latest cybersecurity trends and vulnerabilities?

Explain your methods for staying informed about the industry, including following cybersecurity blogs, attending webinars, participating in forums, or completing relevant certifications. This shows your commitment to continuous learning, which is essential in cybersecurity.

Join Rise to see the full answer
How have you collaborated with clients on understanding vulnerabilities?

Share a positive experience where you communicated findings to a client, detailing your approach to making complex information accessible. Highlight how you tailored your communication style based on the client’s technical expertise to ensure clarity and comprehension.

Join Rise to see the full answer
What is your experience with automating penetration testing?

Discuss any experiences you have with scripting in languages such as Python, Golang, or Bash to automate parts of your penetration testing process. Provide examples of how automation has improved your efficiency or expanded the scope of your assessments.

Join Rise to see the full answer
Can you explain a challenging vulnerability you encountered and how you addressed it?

Select a specific vulnerability that posed a challenge in your experience. Detail how you identified it, the method you used for exploitation, and how you communicated the findings effectively to stakeholders.

Join Rise to see the full answer
What methodologies do you follow during your penetration tests?

Highlight any methodologies you adhere to, like OWASP, NIST, or PTES, and explain how following structured approaches helps in maintaining thoroughness and consistency in your testing processes. This demonstrates your professionalism and adherence to best practices.

Join Rise to see the full answer
How do you assess the threats the organization may face?

In your answer, reflect on your experiences with threat modeling, risk assessments, and understanding the threat landscape. Mention any frameworks or techniques you utilize to identify potential threats relevant to the specific client’s environment.

Join Rise to see the full answer
What role does documentation play in your work, and how do you approach it?

Emphasize the importance of documentation throughout your testing process, from drawing up initial scopes to delivering final reports. Explain how thorough documentation contributes to clarity, accountability, and helps clients understand remediation steps.

Join Rise to see the full answer
Similar Jobs
Posted 13 days ago
Photo of the Rise User
Posted 9 days ago
Photo of the Rise User
ZeroFOX Remote No location specified
Posted 4 days ago
Redcare Pharmacy Remote Probsteigasse 12-18, Cologne, Germany
Posted 13 days ago
Posted 3 days ago
Photo of the Rise User
Posted 6 days ago
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
No info
LOCATION
No info
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
January 2, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!