Job
- Level
- Experienced
- Job Field
- IT, Security
- Employment Type
- Full Time
- Contract Type
- Permanent employment
- Salary
- 80.000 to 128.000€ Gross/Year
- Location
- Wiesbaden
- Working Model
- Onsite
Job Summary
In this role, you conduct security assessments and penetration tests, employ OWASP methodologies to identify vulnerabilities, and support risk analysis and remediation efforts for mission-critical applications.
Job Technologies
Your role in the team
- Conduct vulnerability assessments and penetration tests against USAREUR-AF network infrastructure, endpoints, and applications in support of CSSP assessment missions (NAVs and PPTs).
- Perform web application security testing using OWASP methodology and tools including Burp Suite and OWASP ZAP, identifying and validating vulnerabilities across mission partner web services.
- Execute Active Directory and Linux security assessments to identify privilege escalation paths, credential exposure risks, and lateral movement opportunities within target environments.
- Utilize penetration testing frameworks including Metasploit and Burp Suite to safely exploit validated vulnerabilities and demonstrate risk to mission owners in a controlled manner.
- Document all assessment findings in structured reports, including vulnerability descriptions, evidence screenshots, CVSS risk ratings, and actionable remediation recommendations.
- Support mission owners and network defenders with post-assessment remediation guidance, answering technical questions and providing clarification on findings to facilitate effective risk reduction.
This text has been machine translated. Show original
Our expectations of you
Education
- Bachelors degree and a minimum of 5 years of penetration testing or vulnerability assessment experience.
- Associate's degree + 7 years of specialized experience; or 11 years of experience (no degree).
Qualifications
- DoW 8140 - Cybersecurity (Vulnerability Analyst) - Intermediate.
- Certifications - must hold active certifications (one of the following): TCM Security PNPT; HTB CPTS (Hack The Box Certified Penetration Testing Specialist); Zero Point Security RTO (Red Team Ops); OSCP (Offensive Security Certified Professional); OSCE (Offensive Security Certified Expert); GPEN (GIAC Penetration Tester); GWAPT (GIAC Web Application Penetration Tester); GAWN (GIAC Assessing and Auditing Wireless Networks); GXPN (GIAC Exploit Researcher and Advanced Penetration Tester); GWEB (GIAC Certified Web Application Defender).
- U.S. citizenship required.
- Active DoD TS/SCI clearance.
- Proficiency with Burp Suite Pro for manual and automated web application security testing.
- Vertrautheit mit OWASP ZAP für Web-Schwachstellen-Scanning und -Validierung.
- Working knowledge of BloodHound for Active Directory enumeration and attack path analysis.
- Scripting proficiency in Python, Bash, or PowerShell for custom tool development and test automation.
- Vertrautheit mit Vulnerability Scoring Frameworks (CVSS) und risikobasierten Berichterstattungsmethoden.
Experience
- Hands-on experience with Metasploit Framework for vulnerability exploitation and post-exploitation activities.
- Experience with Nmap and Nessus/OpenVAS for network discovery and vulnerability scanning.
- Experience with vulnerability management platforms (e.g., Tenable.sc, Rapid7 InsightVM).
This text has been machine translated. Show original
What we offer
- Target Salary Range: $80,000 - $128,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual's experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations.
- Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.
- Peraton offers eligible employees a variety of benefits including medical, dental, vision, life, health savings account, short/long term disability, EAP, parental leave, 401(k), paid time off (PTO) for vacation, and company paid holidays.
This text has been machine translated. Show original
Topics that you deal with on the job
Job Locations
This is your employer
Peraton
Founded in 2017, Peraton specializes in national security and technology services, offering solutions in areas such as aerospace, cybersecurity, and defense.
Description
- Company Type
- Established Company
- Working Model
- Onsite
- Industry
- Power Sector, Economy