Relomote
Remote JobsRelocation Jobs
Add companySaved
Relomote

Relomote is a job board for remote, hybrid, and relocation jobs — every listing AI-classified for the countries it actually hires from, or the visa and relocation support it offers.

LinkedInCrunchbase

Remote jobs by category

  • Remote Engineering & Development jobs
  • Remote Customer Support jobs
  • Remote Design jobs
  • Remote Marketing jobs
  • Remote Sales jobs
  • Remote Product jobs
  • Remote Data & Analytics jobs
  • Remote People & Talent jobs
  • Remote Writing & Content Creation jobs
  • Remote Finance jobs
  • Remote Legal & Compliance jobs
  • Remote Operations & Admin jobs
  • Remote Data Entry jobs
  • Remote Virtual Assistant jobs
  • Remote Education/Training jobs
  • Remote Healthcare/Clinical jobs
  • Remote Other jobs

Remote jobs by location

  • Work from anywhere jobs
  • Remote jobs in Africa
  • Remote jobs in Asia
  • Remote jobs in Europe
  • Remote jobs in Latin America
  • Remote jobs in Middle East
  • Remote jobs in North America
  • Remote jobs in Oceania
  • All remote jobs →

Relocation & visa sponsorship

  • Visa sponsorship jobs
  • Relocation package jobs
  • Relocate to Europe
  • Relocate to Germany
  • Relocate to Netherlands
  • Relocate to Spain
  • Relocate to Portugal
  • Relocate to Greece
  • Relocate to United Kingdom
  • Relocate to Canada
  • Relocate to Australia
  • Relocate to Sweden
  • Relocate to Switzerland
  • Relocate to Japan
  • Relocate to United Arab Emirates
  • All relocation jobs →

© 2026 RelomoteAboutPrivacyTerms

Contact [email protected] · Built by Mahmoud

Relomote
Remote JobsRelocation Jobs
Add companySaved
Datalockcg logo

Security Penetration Tester

Datalockcg
Posted May 28, 2026, 9:59 AM UTC
🇺🇸United States🏠Remote📁Engineering & Development
Is this job info correct?

Job Description This is a remote position. Job Description – Security Penetration Tester 1. POSITION TITLE Penetration Tester 2. REPORTS TO Lead Security Assessor\Technical Manager 3. DELEGATION OF DUTIES DURING ABSENCE Lead Security Assessor\Technical Manager 4. SUMMARY The Penetration Tester can be a full-time position, or a duty as assigned additional function. The Penetration Tester will be familiar with Security Assessor Functions also. The Security Assessor will conduct security control assessments of the security and privacy controls implemented by an information system to determine the overall effectiveness of the controls and the vulnerability state of components, applications and databases residing within the system boundary. Following the NIST Cybersecurity Framework, Risk Management Framework and using NIST 800-53A, verifies the security status of existing information systems with an Authority to Operate (ATO) by performing appropriate assessments on any new system developed or deployed by the customer, and conducts audits of security controls to ensure continuous monitoring of systems assigned. Assesses systems that have previously been assessed and received an ATO and systems that have not yet been assessed and do not have an ATO. 5. RESPONSIBILITES · Develop, document and review System Rules of Engagement (ROE), Security Assessment Plans (SAPs) and Security Assessment Reports (SARs). · Have a working knowledge of the FedRAMP Penetration Guidance and Requirements · Develop associated schedules and resource plans to complete the assessments. · Perform quality control on the assessment and associated deliverables. · Participate as an individual contributor for complex system assessments. · Develop practical and risk-based approaches for security control implementation and vulnerability remediation. · Work closely with ISSOs (contractors and Government) and the technical team and ensure all appropriate A&A supporting documentation is provided prior to conducting the assessment. · Review and provide feedback system boundaries, common controls, the security categorization of information systems, applicable security control baseline based on system categorization. · Review and provide feedback system boundaries, common controls, the security categorization of information systems, applicable security control baseline based on system categorization. · Conduct/participate in Security Assessment Kickoff briefings and SAR briefings. · Review cyber/system/network security body of evidence and documentation for accuracy and completeness. · Conduct security controls assessment of applicable security controls and privacy controls; assess implemented security controls and provide assurance that they are operating as intended. · Analyze security control findings for information systems and applications to convey weaknesses. · Document security assessment results accurately; read, understand, and convey vulnerabilities found during the assessments. · Create security assessment results and document recommendations in a SAR for remediations and security control measures. · Perform audits of each system and provide an authorization recommendation based on determination of risk to the customer. · Audits will include unprivileged and privileged scans against each applicable system. · Audits will include unprivileged and privileged database scans against each applicable database management system (DBMS). · Perform quality control on the assessment and associated deliverables. · Conduct Post Assessment Meetings with the customer. · Provide Plan of Action and Milestones (POA&M) support to ensure mitigations are completed or the teams are working to mitigate all vulnerabilities in a timely fashion and within customer policy timelines. · Develop and maintain a schedule for conducting reoccurring Continuous Monitoring and ongoing CDM efforts once the initial assessments are complete. · Perform continuous monitoring to ensure implemented security controls remain functional throughout the lifecycle of the information system. Requirements 6. MINIMUM EXPERIENCE AND SKILLS · 2+ years’ experience as a lead penetration tester · 4+ years’ experience performing security testing and/or security control assessments. · 4+ years’ experience with developing and documenting the ROEs, SAPs, and SARs. · 4+ years’ experience and expert knowledge of the NIST Cybersecurity Framework, Risk Management Framework, FIPS, and other NIST A&A publications. · 4+ years' of experience utilizing NIST 800-53 and 800-53A. · Experience conducting Penetration Tests in a commercial and or federal environment. · Experience assessing and providing recommendation on the following: Privacy Impact Assessment, Risk Assessment, System Security Plan, Disaster Recovery / Contingency Plan, and Incident Response Plan. · Knowledge of the Systems Development Life Cycle (SDLC) and its application in the development of technology solutions. · Knowledge and skills to perform and document the assessment. · Experience with tools such as Nessus, Web Inspect, Db Protect and Splunk. · Technical background with Windows, Unix, legacy systems, databases, web servers/applications, cloud and virtualization environments. · Familiar with the cloud environments (services/security) and FedRAMP A&A process. · Familiar with FedRAMP Penetration Testing Guidance. · Effective verbal and written communication skills with ability to effectively communicate with all levels of users and teammates both written and verbally. · Effective technical writing and documentation processing skills. 7. MINIMUM EDUCATION · BS/BA degree in Information Technology or related cyber/cyber-security field. · Experience may be substituted for education on a case-by-case basis. 8. CERTIFICATIONS Must possess one of the following certifications: · Cisco Certified Network Professional CCNP / Security · CompTIA Advanced Security Practitioner (CASP+) · Certified Information Systems Security Professional (CISSP) · Certified Secure Software Lifecycle Professional (CSSLP) · CISSP-Information Systems Security Engineering Professional (CISSP-ISSEP) · SANS GIAC Penetration Tester (GPEN) · Open Web Application Security Project Penetration Tester (OWASP) · GIAC Certified Enterprise Defender (GCED) · Certified Ethical Hacker (CEH) · Cisco Certified Network Associate-Cyber-Ops (CCNA Cyber Ops) · Computer Hacking Forensics Investigator (CHFI) · GIAC Certified Forensic Analyst (GCFA) · CompTIA PenTest+ · OffSec Certified Professional (OSCP) · OffSec Web Expert (OSWE) · OffSec Experienced Pentester (OSEP) · OffSec Web Assessor (OSWA) · Certified Professional Penetration Tester (eCPPT) · Web Application Penetration Tester (eWPT) · Web Application Penetration Tester eXtreme (eWPTX) · Hack the Box Certified Penetration Testing Specialist (HTB CPTS) · Burp Suite Certified Practitioner

Similar jobs

Similar jobs

Humana logo

Lead, Penetration Tester

Humana

🇺🇸United States3 hours ago
Humana logo

Lead, Penetration Tester

Humana

🇺🇸United States20 hours ago
Fortreum logo

Penetration Tester

Fortreum

🇺🇸United States22 hours ago
Bmo logo

Senior Network and Cloud Penetration Tester

Bmo

🌍Canada, United StatesYesterday
OCH Technologies LLC logo

Penetration Tester

OCH Technologies LLC

🇺🇸United States5 days ago
Agile Defense logo

Penetration Tester III

Agile Defense

🇺🇸United States5 days ago