See all roles

Vulnerability Assessment Analysts

Work from home Full-time role Hiring

Vulnerability Assessment / Penetration Testing Specialist - Contingent at ARETUM Holdings LLC Vulnerability Assessment / Penetration Testing Specialist - Contingent at ARETUM Holdings LLC in Bethesda, Maryland Posted in 21 days ago. Job Description: ARETUM Holdings LLC Description Public Trust Eligibility Required This is a contingent position, meaning employment is dependent upon the successful award of the associated contract to Aretum and completion of any required background investigation or security clearance verification. About Aretum Aretum is a mission-driven organization committed to delivering innovative, technology-enabled solutions to our customers across defense, civilian, and homeland security sectors. Our teams work at the intersection of strategy, technology, and transformation, helping agencies solve their most critical challenges. We believe in investing in our people and creating a culture where collaboration, inclusion, and professional growth are at the forefront. Job Summary The Vulnerability Assessment / Penetration Testing Specialist performs security testing of government systems to identify vulnerabilities, validate exploitability/impact, and provide clear remediation guidance. This role supports planned, rules-based security testing and examination activities aligned to recognized practices for technical security testing and assessment, with a strong focus on producing defensible, actionable results. Due to the nature of our work as a federal consulting organization, employees may be expected to handle Controlled Unclassified Information (CUI) and must adhere to applicable safeguarding and compliance requirements.

Responsibilities

Perform vulnerability assessments and penetration testing of government systems and applications in accordance with approved rules of engagement and testing plans Execute technical testing activities (e.g., reconnaissance, scanning, enumeration, validation/exploitation where authorized) and document evidence, risk, and impact Assess systems and networks to identify deviations from acceptable configurations and security policy, and translate findings into prioritized remediation actions Support secure network design reviews by analyzing network architecture, trust boundaries, segmentation, and exposed services to identify risk and attack paths Contribute to project delivery by estimating effort, tracking tasks, communicating blockers, and supporting status reporting and deliverable timelines Produce high-quality technical write-ups and executive-ready summaries, including reproduction steps, affected assets, severity rationale, and remediation recommendations Retest/validate remediation and provide closure evidence for resolved vulnerabilities as required by the engagement and client process Maintain careful handling of sensitive information and ensure testing remains ethical, authorized, and auditable Requirements Minimum 3 years of experience performing vulnerability assessments and/or penetration testing Demonstrated experience in project management, network design, and testing the security of government systems to identify vulnerabilities Working knowledge of common testing methodologies and security testing lifecycle concepts (planning, execution, analysis, and mitigation support) Ability to clearly document findings with strong technical writing and evidence-based reporting Familiarity with Windows/Linux fundamentals, TCP/IP networking, and common enterprise services (AD, DNS, web apps, APIs, VPNs) Web application security testing experience aligned to OWASP testing practices Experience working in federal or similarly regulated environments with strict authorization, documentation, and evidence requirements Preferred Qualifications Bachelor's degree in information systems, Computer Science, Engineering or related field Preferred Certifications: GIAC Web Application Penetration Tester (GWAPT) Certified Ethical Hacker (CEH) GIAC Systems and Network Auditor (GSNA) Certified Penetration Tester (CPT) Certified Expert Penetration Tester (CEPT) GIAC Certified Web Application Defender (GWEB) Offensive Security Certified Professional (OSCP) CREST Penetration Testing Certifications Travel Requirements This is a hybrid position, with work performed both remotely and at designated client or corporate locations, as needed. Travel requirements may vary depending on project assignments, client meetings, or internal collaboration and will be communicated in advance whenever possible. EEO Statement Aretum is committed to fostering a workplace rooted in excellence, integrity, and equal opportunity for all. We adhere to merit-based hiring practices, ensuring that all employment decisions are made based on qualifications, skills, and ability to perform the job, without preference or consideration of factors unrelated to job performance. As an Equal Opportunity Employer, Aretum complies with all applicable federal, state, and local employment laws. We are proud to support our nation's veterans and military families, providing career opportunities that honor their service and experience. If you require reasonable accommodation during the hiring process due to a disability, please contact [email protected] for assistance. Equal Opportunity Employer/Veterans/Disabled U.S. Work Authorization Due to federal contract requirements, only U.S. citizens are eligible for this position. This position supports a federal government contract and requires the ability to obtain and maintain a Public Trust or Suitability Determination, depending on the agency's background investigation requirements.

Benefits

Health Care Plan (Medical, Dental & Vision) Retirement Plan (401k) Life Insurance (Basic, Voluntary & AD&D) Paid Time Off Family Leave (Maternity, Paternity) Short Term & Long-Term Disability Training & Development ARETUM is an equal opportunity employer, committed to diversity and inclusion. All qualified candidates will receive equal consideration for employment without regard to disability, race, color, religious creed, national origin, sexual orientation/gender identity, or age. ARETUM utilizes e-Verify to check employment authorization. EEO/AA/F/M/Vet/Disabled. Equal employment opportunity, including veterans and individuals with disabilities. PI281369215 Apply tot his job Apply To this Job

You might like

FIPS 140 Security Engineer-REMOTE

Work from home Full-time role

QA Analyst, Browser Extension

Work from home Full-time role

Applications Security Engineer

Work from home Full-time role

Physical Security Program Manager

Work from home Full-time role

Program Manager, Third Party Security

Work from home Full-time role

Senior Consultant (PRN) – GxP Vendor & Supplier Auditor (Part-Time)

Work from home Full-time role

Senior SEO Specialist, US

Work from home Full-time role

Senior Talent Acquisition Partner, Remote Job

Work from home Full-time role

Software Engineer or Senior Software Engineer

Work from home Full-time role

Architect, Web (Remote, CA, US, USA_506360)

Work from home Full-time role

[Work From Home] American Airlines Job Security $27/Hour

Work from home Full-time role

School Certifying Official (Part-Time)

Work from home Full-time role

Experienced Data Entry Specialist – Work From Home Opportunity at arenaflex

Work from home Full-time role

Remote Customer Service Agent – Passenger Experience & Support Specialist at arenaflex Aviation

Work from home Full-time role

Field Sales Representative - Miami/Fort Lauderdale

Work from home Full-time role

Experienced Data Entry Specialist – Entry Level, Part-Time, Remote Work Opportunity with Flexible Hours and Competitive Compensation

Work from home Full-time role

Experienced Data Entry Specialist – Remote Work Opportunity with blithequark

Work from home Full-time role

Registered Nurse

Work from home Full-time role

Experienced Remote Data Entry Specialist – Join arenaflex's Global Team and Shape the Future of Logistics

Work from home Full-time role

Amazon Virtual Assistant (Full-time and Part-time)

Work from home Full-time role