Spectrum San Diego Logo

Spectrum San Diego

Penetration Tester

Posted 2 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in TX, USA
Expert/Leader
Remote
Hiring Remotely in TX, USA
Expert/Leader
Conduct web, network, mobile, and red-team penetration tests for government clients. Manage engagements from scoping through reporting, identify and exploit vulnerabilities, provide remediation guidance, and present findings to technical and executive stakeholders. Support cloud security architecture, digital forensics, malware reverse engineering, enterprise security engineering, tool evaluation, and methodology development. The role also contributes to strategic cybersecurity planning and advises clients and senior management on advanced security initiatives.
The summary above was generated by AI

Science Applications International Corporation (SAIC) is seeking a Penetration Tester to join our offensive security practice supporting a major state & local government customer. This role sits at the intersection of hands-on technical execution and cybersecurity leadership and it's built around delivering real impact for clients who depend on us to find what others miss.

Web application & Network penetration testing is the core of what you'll do every day, and we're looking for someone who brings both technical depth and genuine curiosity to every engagement. Beyond web and network pentesting you'll contribute to our mobile application testing practice (iOS and Android), support ethical hacking operations, and provide strategic guidance on enterprise cyber architecture and cloud security. This position reports to the Security Assessments Manager.

This is a role where your contributions are visible, your growth is intentional, and your voice matters to the team and to the clients we serve.

Essential duties of this position include:

  • Deliver high-quality penetration tests across a range of client environments, applying black box, white box, web app or mobile methodologies as needed and aligned to NIST standards
  • Independently manage engagement workloads from scoping through reporting, with a consistent focus on quality
  • Produce clear, well-structured technical reports that communicate findings, risk context, and actionable remediation guidance to both technical teams and executive stakeholders and translate complex technical documentation into terms any stakeholder can act on
  • Support and contribute to mobile application security assessments (iOS and Android) using the OWASP MASVS/MSTG framework, with the expectation of growing mobile capabilities over time
  • Perform strategic planning and management in cybersecurity and digital forensics in alignment with the National Initiative for Cybersecurity Education (NICE) Framework
  • Address a wide range of security issues including architectures, firewalls, electronic data traffic, and network access
  • Research, evaluate, and recommend new security tools, techniques, and technologies; utilize COTS/GOTS and custom tools to scan, identify, contain, mitigate, and remediate vulnerabilities and intrusions
  • Apply expert engineering knowledge to design, develop, and implement security solutions across enterprise engagements
  • Confidently present findings to clients whether it is walking a developer through a vulnerability chain or  explaining business risk to a CISO in the same afternoon
  • Act as a spokesperson and advisor on advanced technical projects and research; participate with senior management to establish strategic plans and objectives
  • Actively share knowledge with teammates, contribute to internal tooling and methodology improvements, and help close skill gaps across the practice
  • Stay current on emerging vulnerabilities, attack techniques, and industry developments and bring that knowledge back to the team
Qualifications

Typical Education and Experience:

  • Bachelors and nine (9) years or more experience; Masters and seven (7) years or more experience; PhD or JD and four (4) years or more related experience. Additional experience considered in lieu of degree
  • Candidates must be a US Citizen and able to pass a CJIS Criminal Justice background investigation and maintain CJIS clearance throughout employment term

Required Experience:

  • Advanced technical knowledge in cybersecurity and digital forensics
  • Strong working knowledge of the OWASP WSTG and OWASP Top 10 — not just the list, but how to find and exploit the vulnerabilities
  • Proficiency with standard web application testing tools (e.g., Burp Suite Pro, FFUF, SQLMap, Nuclei)
  • Working familiarity with mobile application testing concepts and tooling (e.g., Frida, Objection, MobSF, ADB)
  • Proven experience in red-teaming, ethical hacking, and cloud security architecture
  • Proficiency in malware reverse engineering and enterprise cyber architecture
  • Strong background in addressing security issues related to architectures, firewalls, electronic data traffic, and network access
  • Experience researching, evaluating, and recommending new security tools and technologies
  • Proficiency utilizing COTS/GOTS and custom tools for vulnerability management
  • Demonstrated ability to write professional, client-ready penetration test reports with minimal revision
  • GWAPT certification required or strongly preferred; candidates holding OSCP, OSWE, or GWEB will also be considered

Preferred Experience:

  • Hands-on experience conducting iOS and/or Android application assessments
  • Familiarity with API security testing (REST, GraphQL, SOAP)
  • Exposure to source code review as part of white box engagements
  • Experience presenting findings directly to client stakeholders, including senior leadership
  • Participation with senior management to establish strategic plans and objectives
  • Experience working on unusually complex technical problems and providing innovative solutions
  • Proven ability to work under consultative direction toward long-range goals and objectives
  • Experience serving as an organizational spokesperson and advisor on advanced technical projects
  • Knowledge of applying advanced technical principles, theories, and concepts to develop new principles and concepts
  • Experience making decisions on administrative or project work matters to achieve program or organizational objectives
  • Strong background in developing advanced technological ideas and guiding them to final product development
  • Experience influencing organizational image and technological capability through decision-making and recommendations
About UsSAIC® is a premier mission integrator focused on advancing the power of technology and innovation to serve and protect our world. Our robust portfolio of offerings across the defense, space, intelligence, and civilian markets includes secure high-end solutions in mission IT, enterprise IT, engineering services, and professional services. We integrate emerging technology, rapidly and securely, into mission critical operations that modernize and enable critical national imperatives.

We are approximately 23,000 strong; driven by mission, united by purpose, and inspired by opportunities. SAIC is an Equal Opportunity Employer. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $7.3 billion. For more information, visit saic.com. For ongoing news, please visit our newsroom.

Similar Jobs

6 Days Ago
Remote or Hybrid
17 Locations
130K-165K Annually
Senior level
130K-165K Annually
Senior level
Information Technology • Productivity • Software • Infrastructure as a Service (IaaS)
Perform penetration testing across applications, APIs, cloud environments, infrastructure, and client-side components. Identify, validate, score, and document vulnerabilities; support remediation and secure design with Engineering; triage bug bounty submissions; develop testing tools and scripts; and communicate findings to researchers, technical teams, and executives. The role also applies threat modeling, security frameworks, and emerging threat intelligence to improve organizational security.
Top Skills: AuthenticationAuthorizationBsimmBurp SuiteC++CaidoCisCloud Security ArchitectureCryptographyCsaCvssDreadGoJavaKotlinLinuxNistOwaspPythonStrideTcp/IpUdpWindows
13 Days Ago
In-Office or Remote
United States
120-160 Hourly
Mid level
120-160 Hourly
Mid level
Information Technology • Professional Services • Consulting • Cybersecurity
Conduct web, mobile, API, network, and social engineering penetration tests; identify vulnerabilities, develop technical reports, recommend mitigations, and present findings to clients. Ensure assessments align with GDPR, PCI-DSS, SOC 2, and other standards while tracking emerging threats. The role is remote and contract-based, with cloud security, certifications, mobile testing, API security, and scripting experience preferred.
Top Skills: AWSBashBurp SuiteGCPJavaScriptMetasploitAzureMitre Att&CkNessusNmapOauthOwasp Mobile Security Testing GuideOwasp Top 10PythonWireshark
19 Days Ago
Remote
2 Locations
90K-130K Annually
Mid level
90K-130K Annually
Mid level
Information Technology • Cybersecurity
Conduct infrastructure penetration tests, cloud security assessments, Active Directory reviews, red team operations, adversary simulations, and purple team exercises across on-premises, hybrid, and cloud environments. Identify and validate vulnerabilities, execute attack scenarios, prepare technical reports, present findings, advise clients on remediation, and improve offensive security methodologies, tooling, documentation, and service offerings. The role also requires managing engagement timelines, collaborating with consultants, and maintaining expertise in emerging attack techniques.
Top Skills: Active DirectoryAWSCi/Cd PipelinesCloud-Native TechnologiesEnterprise NetworkingGoogle Cloud PlatformKubernetesLinuxAzureMicrosoft Entra IdVirtualization PlatformsWindowsWireless Networks

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account