Dark Wolf Solutions logo

Dark Wolf Solutions

Penetration Tester at Dark Wolf Solutions

Colorado Springs, COFull-timePenetration TestingPosted 4 months ago
Apply with Pipeline

About the Role

<p data-path-to-node="2"><strong>Dark Wolf</strong> is actively seeking an experienced Penetration Tester to join our innovative team. This individual will play a critical role in assessing and enhancing the security of various products, including hardware, software, and embedded systems. This role demands a deep understanding of penetration testing methodologies and advanced exploit development, focusing on identifying and mitigating vulnerabilities across a wide range of technologies. As a Junior Product and Hardware Security Penetration Tester, you will have the chance to work on cutting-edge technologies and contribute to the enhancement of security across a wide range of products. If you possess a strong background in penetration testing and a passion for cybersecurity, we encourage you to apply for this pivotal role. This position is set to be supported in a hybrid work environment out of the DC Metro area. Key responsibilities include, but are not limited to:</p> <ul> <li data-path-to-node="4,0,0">Conducting comprehensive penetration testing on hardware, software, and network components.</li> <li data-path-to-node="4,0,0">Performing advanced vulnerability scanning and assessments on all components.</li> <li data-path-to-node="4,0,0">Performing a Cybersecurity evaluation of the product under test to identify vulnerabilities that would negatively impact the Confidentiality, Integrity, or Availability of system data or functionality.</li> <li data-path-to-node="4,0,0">Analyzing software, firmware, hardware, and/or RF components within the system.</li> <li data-path-to-node="4,0,0">Opining on the impact and level of effort required to exploit the identified vulnerabilities as well as providing information on a high-level remediation strategy.</li> <li data-path-to-node="4,0,0">Developing and executing exploits and proof-of-concept (PoC) attacks to demonstrate the impact of identified vulnerabilities.</li> <li data-path-to-node="4,0,0">Analyzing and reverse engineering firmware and embedded systems to identify security weaknesses.</li> <li data-path-to-node="4,0,0">Testing and assessing the security of secure boot processes and Trusted Execution Environments (TEE).</li> <li data-path-to-node="4,0,0">Conducting web application security assessments, focusing on OWASP Top Ten vulnerabilities and API security testing.</li> <li data-path-to-node="4,0,0">Performing manual verification of vulnerabilities, assessing their risk and exploitability.</li> <li data-path-to-node="4,0,0">Engaging in wireless and RF security testing, including penetration testing on Wi-Fi, Bluetooth, and Zigbee networks.</li> <li data-path-to-node="4,0,0">Utilizing Software Defined Radio (SDR) for protocol reverse engineering and testing.</li> <li data-path-to-node="4,0,0">Reporting detailed findings, documenting case details, and providing actionable recommendations for remediation to enhance product security based on system analysis.</li> <li data-path-to-node="4,0,0">Planning and executing full-scale, cross-domain vulnerability assessments, network penetration testing, and phishing/social engineering campaigns.</li> </ul> <h3 data-path-to-node="5">Required Qualifications:</h3> <ul> <li>Bachelor’s degree in Cybersecurity, Information Technology, Computer Engineering, or a related field</li> <li id="p-rc_890434e732eb3ccc-20" data-path-to-node="6,0,0">Minimum of 2+ years’ experience in three <span class="citation-23 citation-end-23">or more specific areas to include: intelligence analysis, network engineering, networking security, penetration testing, red team operations, hardware engineering, software engineering, exploit development, reverse engineering, vulnerability assessment, physical security assessments, or social engineering</span></li> <li data-path-to-node="6,0,0">Proficiency with cloud technology and deployments across Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP)</li> <li data-path-to-node="6,0,0">Proficiency in the testing and assessment of mobile operating systems, embedded systems, and/or IoT devices</li> <li data-path-to-node="6,0,0">Experience in drafting reports, documenting case details, and summarizing findings and recommendations based on system analysis</li> <li data-path-to-node="6,0,0">Experience performing advanced vulnerability scanning and assessments on all components</li> <li data-path-to-node="6,0,0">Experience conducting web application security assessments, focusing on OWASP Top Ten vulnerabilities and API security testing</li> <li data-path-to-node="6,0,0">Demonstrated strong written and verbal communication skills</li> <li data-path-to-node="6,0,0">Strong understanding of NIST 800-53 frameworks</li> <li style="font-weight: bold;" data-path-to-node="6,0,0"><strong>US Citizenship and an active security clearance at a minimum of the Secret Level</strong></li> </ul> <h3 data-path-to-node="7">Desired Qualifications:</h3> <ul> <li data-path-to-node="8,0,0">Proven ability to develop and execute complex exploits and PoC attacks</li> <li data-path-to-node="8,0,0">Strong analytical skills and experience in firmware, binary exploitation, and embedded systems testing</li> <li data-path-to-node="8,0,0">Advanced knowledge of Software Defined Radio (SDR) and protocol reverse engineering</li> <li data-path-to-node="8,0,0">Active professional certifications such as CEH, OSCP, PNPT, GPEN, or similar security/pen testing certifications</li> </ul> <p>The salary range for this position is $130,000.00 - $145,000.00 commensurate on experience and technical skillset.&nbsp;</p> <p>We are open to considering a variety of levels of experience for these projects and potential for 1099 hourly opportunity.&nbsp;</p> <p>We are proud to be an EEO/AA Employer Minorities/Women/Veterans/Disabled and other protected categories.&nbsp;<br><br>In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.</p>