All jobs

Cyber Security Analyst III (Security Testing)

100% Remote Full-time Open now

• *Position Overview** The primary duty of the Cyber Security Analyst III (Security Testing) is the planning, execution, and documentation of authorized security assessments across the organization’s information systems, infrastructure, and applications. This includes web application testing, network penetration testing, vulnerability assessments, and adversarial simulation activities. The incumbent applies industry-standard methodologies and tools to identify, validate, and document security weaknesses, translating technical findings into actionable remediation guidance for system owners and engineering teams. The role supports the organization’s security posture at the Hanford Site and collaborates closely with GRC, IT Engineering, and Security Operations teams.

  • *Major Activities (Typical Duties/Responsibilities)**

• Plan, scope, and execute authorized penetration tests against network infrastructure, operating systems, web applications, and APIs in accordance with approved rules of engagement.

  • Conduct web application security assessments using both manual techniques and automated tooling, testing for OWASP Top 10 vulnerabilities and other application-layer risks.
  • Perform vulnerability assessments and configuration reviews across Windows and Linux environments, network devices, and cloud infrastructure.
  • Develop clear, structured assessment reports documenting methodology, findings, risk ratings (using CVSS or equivalent), and prioritized remediation recommendations for both technical and executive audiences.
  • Validate remediation efforts by conducting follow-up testing to confirm that identified vulnerabilities have been effectively mitigated or accepted.
  • Collaborate with GRC analysts to integrate security testing findings into POA&M tracking, risk assessments, and RMF authorization packages.
  • Support red team exercises and adversarial simulation activities to evaluate the effectiveness of detective and preventive controls.
  • Research and evaluate emerging attack techniques, threat actor TTPs (Tactics, Techniques, and Procedures), and offensive tooling to ensure testing methodologies remain current.
  • Assist with secure code review and DevSecOps integration activities, providing security guidance to software development and engineering teams.
  • Maintain detailed records of assessment activities, tooling configurations, and findings in accordance with federal handling requirements for sensitive assessment data.
  • Provide mentorship and technical guidance to junior analysts on security testing concepts, tool usage, and reporting standards.
  • Perform other duties as appropriate and as assigned.
  • *Knowledge/Skills/Abilities**

• Demonstrated proficiency with penetration testing methodologies and frameworks, including PTES (Penetration Testing Execution Standard), OWASP Testing Guide, and MITRE ATT&CK.

  • Hands-on experience with industry-standard security testing tools, including Burp Suite Pro, Nessus/Tenable, Metasploit Framework, Nmap, Wireshark, and equivalent tooling.
  • Strong knowledge of web application security vulnerabilities (OWASP Top 10, SANS Top 25) and application-layer attack techniques.
  • Proficiency with scripting languages (Python, Bash, or PowerShell) for tool automation, payload development, and custom testing scripts.
  • Solid understanding of networking fundamentals (TCP/IP, DNS, HTTP/S, TLS, Active Directory) and how they relate to attack surface analysis.
  • Familiarity with cloud security testing concepts across AWS, Azure, or equivalent platforms, including misconfiguration assessment and IAM privilege analysis.
  • Knowledge of CVSS scoring, vulnerability risk rating methodologies, and how to communicate risk in business terms.
  • Understanding of NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment) and relevant NIST SP 800-53 Rev. 5 control families.
  • Familiarity with DevSecOps principles and static/dynamic application security testing (SAST/DAST) integration in CI/CD pipelines.
  • Good interpersonal skills: ability to work effectively and cooperatively with all levels of management and staff, affiliated-company employees as well as outside business associates; exhibits a professional manner in dealing with others.
  • Superior organizational, follow-up, and detail-oriented skills.
  • Strong ability to analyze documents and categorize appropriately.
  • Ability to maintain accurate records.
  • Work independently, as well as on a team and with minimal supervision.
  • Make decisions, solve problems, and exercise excellent judgment.
  • Work well under pressure and independently prioritize workload, while working on multiple projects.
  • Ability to research, organize and analyze technical information with particular attention to accuracy and detail.Apply tot his job

Apply To this Job

You might also like

Senior Analyst, Cyber Security GRC (Penetration Tester)

100% Remote Full-time

SEM Coordinator (Non-Profit Clients)

100% Remote Full-time

Director/Senior Legal Counsel, Compliance

100% Remote Full-time

Sr. Accountant II, Centralized Accounting (Remote)

100% Remote Full-time

Senior Vice President, Marketing and Communications

100% Remote Full-time

Senior Program Manager - Accessibility Services job at Sound Transit in Seattle, WA

100% Remote Full-time

Region Senior Vice President, Mission Advancement

100% Remote Full-time

Senior Vice President, Program Leadership & Development

100% Remote Full-time

SEO Specialist with Webflow, SEMrush, and Yext Experience (Remote)

100% Remote Full-time

SEO Specialist job at Fortune Brands Innovations in Deerfield, IL

100% Remote Full-time

Nurse Writer (RN) - Remote Jobs – Indeed Jobs US

100% Remote Full-time

Part-Time Data Entry Jobs Remote - Work From Home Job

100% Remote Full-time

[Remote] Epic Application Analyst Level 1

100% Remote Full-time

Senior Security Software Engineer, Application Security job at Pinterest in Chicago, IL

100% Remote Full-time

Group Air Agent

100% Remote Full-time

Growth Lead, Community & Ecosystem

100% Remote Full-time

Customer Service Coordinator Full Time – Join the blithequark Family and Soar to New Heights

100% Remote Full-time

Synthetic Biology Specialist - Freelance AI Trainer Project

100% Remote Full-time

Flexible Real Estate Buyers Agent & Administrative Assistant

100% Remote Full-time

Part-Time Data Entry Specialist – Remote Opportunity at arenaflex

100% Remote Full-time