Nelnet/CampusGuard logo
Penetration Tester / Ethical Hacker – CampusGuard - Nelnet/CampusGuard Anywhere (US) Bookmark Share Print 377 2 24

Listing Description

Overview:

The Penetration Tester/Ethical Hacker is responsible for assessing a customer’s business and operating environment risk and infrastructure vulnerability posture. This position requires a wide range of knowledge of network infrastructures, operating systems hardware platforms, networking systems and the security vulnerabilities within each category. The qualified individual in this position will scan customer networks to discover and exploit security flaws and vulnerabilities with attack simulations on multiple platforms working against a specific customer-focused scope of work. This position requires a highly technical skill level to assess the risks and vulnerabilities of a customer’s network while being able to articulate the issues to a non-IT professional audience. Excellent communication skills, both oral and written are required to provide the reporting information to the customer after the tests are completed. When not performing the specific Scanning and Penetration Testing / Ethical Hacking functions, the individual in this position will provide support to the Security Advisors with other security assessments and gap analysis functions.

***This is a remote position***

Responsibilities:

Responsible for scanning and performing in depth penetration testing and reporting customer business and operating environments and network infrastructure related to compliance and other relevant industry standards. Activities include, but are not limited to the following:

Understand the Scope of Work for each customer agreement and perform the duties and tasks required by those agreements in an organized, professional manner.

Perform vulnerability assessments and penetration testing, utilizing commercial and open source tools.

Conduct web application penetration testing in line with Open Web Application Security Project.

Exploit security flaws and vulnerabilities with attack simulations on multiple projects working against specific customer systems and networks in accordance with an agreed scope of work.

Effectively provide technical risk assessment of technologies in networks, applications, systems, wireless, and perform social engineering.

Review and analyze security vulnerability data to identify applicability and false positives.

Ability to solve complex technical problems and articulate to non-IT personnel.

Document all processes and procedures in accordance with CampusGuard standards.

Report on findings and assist customers in remediation activities as required.

Research and develop testing tools, techniques, and process improvements.

When time allows, perform security assessments and gap analysis of system infrastructures in alignment with the PCI DSS, HIPAA and other well-known information security requirements.

Assist with sales and marketing activities:

Perform or assist with sales calls

Attend conferences

Perform industry presentations and/or webcasts

Other sales/marketing duties as requested

Qualifications:

EDUCATION:

The Penetration Tester/Ethical Hacker must have sufficient information security knowledge and experience to conduct technically complex security assessments.

Bachelor’s degree, and/or 5 years’ experience in the information security industry (preferably at an institution of higher education)

Possess industry-recognized security certification(s) including one or more of the following: GIAC Certified Ethical Hacker (preferable), Certified Information System Security Professional (CISSP), Certified Information Systems Auditor (CISA)

a. Candidate must agree to prepare for and pass the PCI Qualified Security Assessor (QSA) certification and any other certifications as directed by his or her manager.

EXPERIENCE:

If a candidate does not satisfy any of the above education criteria or certificates, he or she must have a minimum of five years of relevant information security experience or proof of other recognized security certifications.

COMPETENCIES – SKILLS/KNOWLEDGE/ABILITIES:

1. Offensive Security Certified Professional (OSCP) and/or Offensive Security Web Expert (OSWE) highly preferred.

2. Strong understanding of various web technologies, and experience with application code review.

3. Experience with penetration testing of cloud hosted environments

4. Demonstrates an ability to methodically analyze problems and identify solutions and communicate to a non-technical audience.

5. Exhibits good writing and communications skills, to include the ability to render concise reports, summaries, and formal oral presentations.

6. Adequately explains, presents, demonstrates [when applicable] and documents the operational impact of a particular vulnerability/exploit. Assists customers with remediation tasks for found vulnerabilities.

7. Self-motivated and able to work both independently and with a team.

8. Understanding of Higher Education, Healthcare, and Government institutions and their structure.

9. Understanding of information processing networks and related security issues.

10. Understanding of Industry standard information security standards and their applicability.

11. Understanding of system infrastructures, vulnerabilities, exploits and remediation tasks.

12. Ability to flow from black box to gray box to white box testing methodologies dependent on customer needs

13. Understanding of the well-known security standards e.g., PCI DSS, NIST 800-53, ISO 27001-27006

14. Understanding of Health Information security standards e.g., HIPAA, HITECH.

15. Understanding of differences between security breach, data compromise, and fraud

16. Understanding of campus type environments, structures, operations, and security needs

EEO Statement:

Nelnet is an Equal Opportunity Employer, complies with Executive Order 11246, and takes affirmative action to ensure that qualified applicants are employed, and that employees are treated during employment, without regard to race, color, religion/creed, national origin, gender, or sex, marital status, age, disability, use of a guide dog or service animal, sexual orientation, military/veteran status, or any other status protected by Federal or State law or local ordinance. Qualified individuals with disabilities who require reasonable accommodations in order to apply or compete for positions at Nelnet may request such accommodations by contacting Nelnet Talent Acquisition & Recruiting.

Nelnet is a Drug Free and Tobacco Free Workplace.

Apply at the following link:

https://careers-nelnet.icims.com/jobs/intro?hashed=-435737839&mobile=false&width=910&height=500&bga=true&needsRedirect=false&jan1offset=-360&jun1offset=-300Responsible for scanning and performing in depth penetration testing and reporting customer business and operating environments and network infrastructure related to compliance and other relevant industry standards. Activities include, but are not limited to the following:

Understand the Scope of Work for each customer agreement and perform the duties and tasks required by those agreements in an organized, professional manner.

Perform vulnerability assessments and penetration testing, utilizing commercial and open source tools.

Conduct web application penetration testing in line with Open Web Application Security Project.

Exploit security flaws and vulnerabilities with attack simulations on multiple projects working against specific customer systems and networks in accordance with an agreed scope of work.

Effectively provide technical risk assessment of technologies in networks, applications, systems, wireless, and perform social engineering.

Review and analyze security vulnerability data to identify applicability and false positives.

Ability to solve complex technical problems and articulate to non-IT personnel.

Document all processes and procedures in accordance with CampusGuard standards.

Report on findings and assist customers in remediation activities as required.

Research and develop testing tools, techniques, and process improvements.

When time allows, perform security assessments and gap analysis of system infrastructures in alignment with the PCI DSS, HIPAA and other well-known information security requirements.

Assist with sales and marketing activities:

Perform or assist with sales calls

Attend conferences

Perform industry presentations and/or webcasts

Other sales/marketing duties as requested


Listing Details

  • Citizenship: Us Citizen
  • Incentives: Bonus

 

  • Education: Bachelors Degree
  • Travel: Travel 25
  • Telework: Full Telecommute


About Us

NinjaJobs is a community-run job platform developed by information security professionals. Our unique approach of focusing strictly on cybersecurity positions allows us to personalize the user experience.

Our Contacts

1765 Greensboro Station Pl.
Suite 900
Tysons Corner Va 22102

(703) 594-7765