Job Closed
This listing is no longer active.
CDT is committed to hiring and retaining a diverse workforce. We are an Equal Opportunity employer making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. Apply Now If you are a proactive Penetration Tester and thrive in dynamic environments, we encourage you to apply and join the CDT team!
Junior Penetration Tester
Location
United States
Posted
87 days ago
Salary
0
Seniority
Junior
No structured requirement data.
Job Description
Junior Penetration Tester
Cyber Defense Technologies
Role Description Cyber Defense Technologies (CDT) is seeking a Junior Penetration Tester to support cybersecurity operations across multiple enterprise and government environments. The selected candidate will assist senior penetration testers and security engineers in identifying vulnerabilities across networks, systems, and applications through authorized penetration testing and vulnerability assessment activities. This role provides an opportunity to work alongside experienced cybersecurity professionals performing offensive security assessments, vulnerability validation, and adversary emulation activities. The Junior Penetration Tester will participate in engagements that help organizations strengthen their security posture by identifying exploitable weaknesses and providing actionable remediation recommendations. The ideal candidate is passionate about cybersecurity, eager to learn advanced penetration testing techniques, and comfortable working in both Linux and Windows environments while leveraging industry-standard tools and frameworks. Qualifications - 0–2 years of cybersecurity or IT security experience related to vulnerability assessment, security operations, or penetration testing - Foundational knowledge of penetration testing methodologies and attack techniques - Experience working in Linux environments (Kali Linux, Ubuntu, or similar distributions) - Familiarity with Windows environments and Active Directory fundamentals - Understanding of network protocols (TCP/IP, DNS, HTTP, SMB, LDAP) - Basic scripting ability using Python, Bash, or PowerShell - Familiarity with common security testing tools such as: - Nmap - Burp Suite Community or Professional - Metasploit Framework - Wireshark - Nessus / OpenVAS - SQLmap - Nikto / OWASP Zap - Hydra - Gobuster / Dirbuster - BloodHound - Basic understanding of web application vulnerabilities such as SQL Injection, XSS, authentication bypass, and misconfigurations - Strong written communication skills for technical documentation and report writing Requirements - Assist senior penetration testers with internal and external penetration testing engagements against enterprise systems and networks - Conduct web application penetration testing using industry-standard tools and methodologies - Perform vulnerability identification, validation, and risk analysis to determine exploitability and impact - Support network reconnaissance, enumeration, and exploitation activities during authorized testing engagements - Assist in conducting wireless security assessments and password security testing - Document testing procedures, findings, and remediation recommendations for inclusion in professional penetration testing reports - Utilize tools such as Nmap, Burp Suite, Metasploit, Nessus, and Wireshark during testing activities - Participate in security research and exploit development labs to improve testing methodologies - Assist with post-exploitation analysis and privilege escalation testing - Support incident response investigations when malicious activity or compromise is suspected - Maintain familiarity with common attack frameworks such as MITRE ATT&CK, OWASP Top 10, and PTES - Collaborate with security engineers and system administrators to validate remediation efforts and conduct retesting Preferred Qualifications - Candidates possessing or actively pursuing one or more of the following entry-level penetration testing or cybersecurity certifications are strongly encouraged to apply: - TCM Security - PNPT – Practical Network Penetration Tester - PJPT – Practical Junior Penetration Tester - PWPT – Practical Web Penetration Tester - INE / eLearnSecurity - eJPT – eLearnSecurity Junior Penetration Tester - eWPT – eLearnSecurity Web Application Penetration Tester - CompTIA - Security+ - PenTest+ - CySA+ Desired Skills - Experience participating in Capture-the-Flag (CTF) competitions or security labs (TryHackMe, HackTheBox, PortSwigger Labs, etc.) - Familiarity with Active Directory attack fundamentals - Experience using Kali Linux penetration testing toolsets - Understanding of basic privilege escalation techniques on Linux and Windows systems - Experience working in team-based cybersecurity environments Work Environment - Remote or hybrid work environment depending on program requirements - Collaboration with CDT security engineers, red team members, and incident response personnel - Opportunity to participate in advanced penetration testing engagements and cyber research initiatives Benefits - Competitive salary based on experience - Comprehensive benefits package, including health, dental, and retirement plans - Opportunities for professional development and career advancement Company Description CDT is committed to hiring and retaining a diverse workforce. We are an Equal Opportunity employer making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. Apply Now If you are a proactive Penetration Tester and thrive in dynamic environments, we encourage you to apply and join the CDT team!
Job Requirements
- 0–2 years of cybersecurity or IT security experience related to vulnerability assessment, security operations, or penetration testing
- Foundational knowledge of penetration testing methodologies and attack techniques
- Experience working in Linux environments (Kali Linux, Ubuntu, or similar distributions)
- Familiarity with Windows environments and Active Directory fundamentals
- Understanding of network protocols (TCP/IP, DNS, HTTP, SMB, LDAP)
- Basic scripting ability using Python, Bash, or PowerShell
- Familiarity with common security testing tools such as: Nmap
- Burp Suite Community or Professional
- Metasploit Framework
- Wireshark
- Nessus / OpenVAS
- SQLmap
- Nikto / OWASP Zap
- Hydra
- Gobuster / Dirbuster
- BloodHound
- Basic understanding of web application vulnerabilities such as SQL Injection, XSS, authentication bypass, and misconfigurations
- Strong written communication skills for technical documentation and report writing
- Assist senior penetration testers with internal and external penetration testing engagements against enterprise systems and networks
- Conduct web application penetration testing using industry-standard tools and methodologies
- Perform vulnerability identification, validation, and risk analysis to determine exploitability and impact
- Support network reconnaissance, enumeration, and exploitation activities during authorized testing engagements
- Assist in conducting wireless security assessments and password security testing
- Document testing procedures, findings, and remediation recommendations for inclusion in professional penetration testing reports
- Utilize tools such as Nmap, Burp Suite, Metasploit, Nessus, and Wireshark during testing activities
- Participate in security research and exploit development labs to improve testing methodologies
- Assist with post-exploitation analysis and privilege escalation testing
- Support incident response investigations when malicious activity or compromise is suspected
- Maintain familiarity with common attack frameworks such as MITRE ATT&CK, OWASP Top 10, and PTES
- Collaborate with security engineers and system administrators to validate remediation efforts and conduct retesting
- Preferred Qualifications
- Candidates possessing or actively pursuing one or more of the following entry-level penetration testing or cybersecurity certifications are strongly encouraged to apply: TCM Security PNPT – Practical Network Penetration Tester
- PJPT – Practical Junior Penetration Tester
- PWPT – Practical Web Penetration Tester
- INE / eLearnSecurity eJPT – eLearnSecurity Junior Penetration Tester
- eWPT – eLearnSecurity Web Application Penetration Tester
- CompTIA Security+
- PenTest+
- CySA+
- Desired Skills
- Experience participating in Capture-the-Flag (CTF) competitions or security labs (TryHackMe, HackTheBox, PortSwigger Labs, etc.)
- Familiarity with Active Directory attack fundamentals
- Experience using Kali Linux penetration testing toolsets
- Understanding of basic privilege escalation techniques on Linux and Windows systems
- Experience working in team-based cybersecurity environments
- Work Environment
- Remote or hybrid work environment depending on program requirements
- Collaboration with CDT security engineers, red team members, and incident response personnel
- Opportunity to participate in advanced penetration testing engagements and cyber research initiatives
Benefits
- Competitive salary based on experience
- Comprehensive benefits package, including health, dental, and retirement plans
- Opportunities for professional development and career advancement
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
• Provides advanced analysis of systems from a security perspective, and ensures systems are designed with appropriate security requirements "baked-in", and that these systems maintain proper security postures throughout their life cycle. • Maintains a thorough understanding of risk management frameworks, including the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF), and NIST Cybersecurity Framework (CSF). • Moves fluidly between nuts-and-bolts, tactical security implementations, to high-level strategic policy, standards, and guidelines that facilitate effective security operations. • Develops and maintains an in-depth knowledge of governing Defense, Federal, and Industry security regulations, standards, and best practices, including those defined in NIST 800-53, DISA Security Technical Implementation Guides (STIGs), Center for Internet Security (CIS), and vender security best practices.
Middle RAF Operations Specialist
GR8 TechLaunch, grow, or upgrade your iGaming business with GR8 Tech high-performance Sportsbook and iGaming platform.
Role Description This role exists to protect our sportsbook ecosystem from financial leaks and sophisticated fraud. You’ll help us maintain platform integrity and profitability by analyzing real-time betting data, neutralizing risks, and catching vulnerabilities before they scale. What you’ll drive: - Real-Time Detection & Monitoring: - Validate live and pre-match sports betting activity using Fairplay Monitor and internal alert systems. - Detect and intercept suspicious betting patterns, including arbitrage, value exploitation, latency abuse, and abnormal winnings. - Analyze player behavior across multiple accounts to uncover organized fraud rings and bonus abuse. - Risk Decisions & Execution: - Apply immediate risk mitigation actions, independently triggering account segmentation, betting limits, and market restrictions. - Drive verification requests for suspicious accounts to strictly validate player identities and block bad actors. - Resolve complex customer cases and internal JSM tickets related to fraud suspicions without compromising operational SLAs. - Cross-team Collaboration & Process Improvement: - Partner with Trading, Payments, Risk, and Integrity teams to conduct deep-dive investigations into betting anomalies. - Document audit-ready case notes and maintain accurate internal tracking tables for all antifraud actions. - Optimize our workflows by reporting bugs, clarifying rule logic, and suggesting improvements to our detection systems. Qualifications - 1+ year of hands-on experience in sports betting operations, fraud detection, or risk monitoring. - Strong understanding of sports betting mechanics, odds logic, and common fraud schemes (e.g., arbitrage, value betting). - Proven ability to make fast, autonomous decisions under time pressure with high operational accuracy. - Readiness to work in a 24/7 environment on a structured 4/2 rotating shift schedule (morning, evening, and night shifts). - Intermediate (B1+) English level to communicate clearly with cross-functional teams and maintain documentation. Requirements - Experience working with BI tools (like Tableau) or handling large operational datasets. - Familiarity with alert-based fraud detection systems (e.g., Fairplay Monitor). - Basic understanding of SQL for independent data validation. Benefits - Benefits Cafeteria — annual budget you allocate to: - Sports - Medical - Mental health - Home office - Languages - Paid maternity/paternity leave + monthly childcare allowance. - 20+ vacation days, unlimited sick leave, emergency time off. - Remote-first + tech support + coworking compensation. - Team events (online/offline/offsite). - Learning culture with internal courses + growth programs. Company Description GR8 Tech builds B2B iGaming platforms for operators who play to lead. We deliver full-cycle, high-impact tech designed to scale — from seamless integrations and expert consulting to long-term operational support. Our platform powers millions of active players and drives real business growth. Call it what it is: the iGaming Platform for Champions. With 1000+ GR8 people across locations and time zones, we don’t just ship technology — we help operators build success stories across brands, markets, and geos. Our ambition drives us. Our people make it real.
Senior Information Assurance and Security Advisor
Peraton CorporationPeraton Corporation, a national security company headquartered in Herndon, Virginia, supplies solutions for mission-critical programs and systems. Founded in 20
Role Description Peraton is seeking an Information Systems Security Officer (ISSO) to join our team. The Information System Security Officer (ISSO) is part of the PERATON DHS’ Security team and plays a Cybersecurity operational compliance role within the Citizen Security and Public Services Sector (CS&PS). The position is responsible for performing as a named ISSO for a Government System and assisting other ISSOs with end-to-end Governance Risk and Compliance (GRC) functions that entails security control implementation, continuous monitoring, and federal Assessment and Authorization (A&A) activities. Day to Day Work Responsibilities: - Works closely under the supervision of Cybersecurity Manager and with other security personnel within Peraton CS&PS Sector to ensure operational security measures are implemented. - Assesses and mitigates system security risks; determines and analyzes security requirements for implementation and testing. - Reviews and continuously monitors implemented security controls. - Creates and maintains security checklists, templates, and other tools to aid in the A&A process. - Performs security control assessment using Agency guidelines/NIST guidance and as per continuous monitoring requirements. - Performs risk analyses to determine and recommend essential safeguards. - Proactively reviews Vulnerability Scans (Nessus, ACAS, We-App, etc.) and recommends compensating controls. - Prepares supporting materials for the security authorization package in accordance with the client contractual requirements. - Develops core documents such as System Security Plan, Contingency Plan, Incident Response Plan, Standard Operating Procedures, Plan of Actions and Milestones, Remediation Plans, Configuration Management Plan, etc. - Maintains client-specific Plan of Action and Milestones (POA&Ms) and supports remediation activities using Information Assurance (IA) and Risk Management tools such as CSAM, eMASS, etc. - Maintains an inventory of hardware and software for the information system. - Develops, tests and trains on Contingency and Incident Response planning. - Experience working with the National Institute of Standards and Technology (NIST) and Federal Information Security Management Act (FISMA) requirements and reporting. - Experience in managing security Assessment and Authorization activities utilizing common control frameworks. - Experience with risk mitigation and selecting or designing appropriate security controls for implementation. - Experience applying cloud security concepts, requirements, design development, implementation, and integration for existing and new technology product offerings. - Experience with performing security risk and compliance activities in FedRAMP cloud-enabled environment (e.g., Microsoft Azure, Amazon AWS). - Experience in coordinating, monitoring and tracking security activities across multiple organizations. - Experience in managing security posture of General Support Systems (GSS) and Major Application system(s), working with engineering/Operation teams to remediate, and communicating system-level risks to the stakeholders. The ISSO operates as a trusted advisor in the organization, working with senior management and helps to understand operational issues and plans the next steps in collaboration with Cybersecurity Manager from an information security viewpoint. The candidate will be able to demonstrate industry expertise and thorough understanding of security governance, risk and compliance domain. This position requires the ability to interact and influence at an organizational level to carry out governance, risk and compliance activities. Qualifications - US Citizenship required - Must be able to pass US Government Clearance processes – DHS Public Trust with EOD and Secret or higher clearance - Bachelor’s degree in a technical field and 12 years experience or high school diploma/equivalent and 16 years experience - Good understanding of computer network security technologies used in the industry and related security configurations (e.g., DISA STIGs, CIS Benchmarks and settings) - Knowledge of the security countermeasures and overall RMF and NIST compliance guidelines - Must have the ability to influence system stakeholders in the execution of security and compliance requirements Requirements - Experience with industrial, contract, personnel security and security training - Excellent communication skills - Ability to work effectively in diverse, multi-national and virtual environments - Self-motivated and tenacious and demonstrates sound judgment and integrity - Experience of working with Federal Information Processing (FIPS), FISMA, FedRAMP and other Cyber Security related laws, regulations and directives - Experience of presenting at client meetings - Experience of translating contractual security requirements to deliverables - Knowledge of Federal Government Security, industry and market trends and CS&PS business and offerings - Understands federal security and regulations and DHS’ Security Policy and has in-depth knowledge of DHS’ Security Policy 4300a Company Description Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can’t be done by solving the most daunting challenges facing our customers. Target Salary Range $112,000 - $179,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual’s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay. EEO EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.
Insurance Criminal Investigations Supervisor
State of North CarolinaThe State of North Carolina is a southeastern state with 100 counties and is the ninth most populous state in the U.S. North Carolina's moderate climate, rich c
Title: Insurance Criminal Investigations Supv Location: Wake County, NC Full time job requisition id JR-110044 Job Description: Agency Dept of Insurance Division Fraud Control Group Position Number 60013459 Grade SW08 About Us The mission of the North Carolina Department of Insurance is to promote a stable insurance market through unbiased regulation and to protect the lives and property of every citizen in all 100 counties while fostering superior, user-friendly service, courtesy, and respect. Our agency licenses insurance agents, adjusters, bail bondsmen and more, along with investigating fraud matters involving insurance consumers and any entity or individual regulated by the Department. In an ever-changing environment, it is the vision of the Department of Insurance to maintain the stabilization of the insurance industry in order to provide more products, competitive prices and consumer protection. Description of Work - This is a repost. Previous applicants need not reapply.* - This posting is open to current Department of Insurance employees only.* Recruitment Range: $61,275 - $86,569 Salary Grade: SW08 This recruitment is for two positions: Position # 60013459 - Currently Vacant Position # 60013456 - Anticipated Vacancy (Effective June 1, 2026) This position currently qualifies for a hybrid telework option with routine office and remote workday. The NC Department of Insurance trusts our employees to be self-motivated and successful in hybrid/remote roles. Telework options are subject to change at the discretion of management. Mission of the Department of Insurance: The North Carolina Department of Insurance's mission is to promote a stable insurance market through unbiased regulation and to protect the lives and property of every citizen in all 100 counties while fostering superior, user-friendly service, courtesy, and respect. North Carolina Department of Insurance offers rewarding careers in a number of different fields that helps us protect consumers and regulate the insurance industry in North Carolina. But that's not all that we do! NCDOI also investigates insurance fraud. We set standards for and inspect fire stations, regulate engineering codes and work with building inspectors in every corner of North Carolina. If you're interested in a career that will help make North Carolina a safer and better place to live while working with some of the best professionals in the industry. Apply today! Primary Purpose of the Position: District Supervisors conduct investigations of criminal activity reported by private citizens, other governmental entities, law enforcement and industry. District Supervisors routinely work with industry Special Investigative Units (SIU), the National Insurance Crime Bureau (NICB), the National Association of Insurance Commissioners (NAIC), other NCDOI regulatory divisions, and other non-law enforcement state government agencies, commissions and boards. District Supervisors provide coordinated high level technical assistance and resources to federal, state, and local law enforcement in the area of insurance fraud criminal investigations. The primary investigative focus is directed at the detection, apprehension and criminal prosecution of persons, companies and/or other entities identified during criminal investigations. Furthermore, a secondary purpose of the District Supervisor is to provide deterrent effects in the prevention of insurance related crimes that affect our state's economy. This includes constant training, seminars and presentations to diverse and related groups. Knowledge Skills and Abilities/Management Preferences Effective July 1, 2025, candidates now meet the minimum qualifications of a position if they have the minimum education and experience listed from the class specification. The knowledge, skills, and abilities listed in the vacancy announcement should be used as management preferences and be used to screen for the most qualified pool of applicants. Management Preferences: - District Commanders must possess advanced knowledge of the methods and procedures and practices available to solve a wide variety of complex financial insurance related crimes. - District Commanders must have considerable knowledge of the principles of securing and identifying a wide variety of physical and financial related evidence. - District Commanders must possess the ability to apply specialized complex principles and techniques of modern criminal investigative work. - District Commanders are required to communicate directly and indirectly with various groups including citizen, business and law enforcement communities. This contact can include interviews and other methods of gathering information such as technology sources. This communication also includes contact with suspects of criminal investigations. This communication also includes the presentation of a criminal investigation case to prosecutors for adjudication. Necessary Special Qualifications: Job posting is open statewide. - Applicants must have served for at least two full time years as a Special Agent with NCDOI CID to be eligible to apply. Description of Work: This position supervises field investigations of insurance related crimes including fraud, embezzlement, and forgery in the District, one of the four geographic districts. District Commanders must have a strong knowledge of managerial theories and applications. District Commanders must have considerable knowledge to determine, detect, interpret and apply state criminal statutes of North Carolina to criminal investigations, evidence gathering, legal process, arrest, and courtroom procedures and practices. District Commanders must possess the ability to prepare comprehensive, organized and detailed written reports pertaining to investigative cases based on these procedures and practices. Work typically requires leading and coordinating virtually all elements of an investigation utilizing various techniques, equipment, and methodologies. District Commanders must have a considerable knowledge of NCDOI-CID rules, regulations, policies and procedures. Furthermore, District Commanders must have an advanced knowledge of all insurance business practices; including those related to accounting, auditing and regulatory review. The successful applicant will possess personnel management skills required for the administration, evaluation, and review of subordinate staff in accordance with policies, procedures and work performance evaluations. This position requires leadership skills to develop and lead special agents in executing the NCDOI-CID mission and accomplishing Division goals. Strong communication skills both oral and in writing are necessary for this position. Minimum Education and Experience Some state job postings say you can qualify by an "equivalent combination of education and experience." If that language appears below, then you may qualify through EITHER years of education OR years of directly related experience, OR a combination of both. See the Education and Experience Equivalency Guide for details. Bachelor's degree in Criminal Justice or related field from an appropriately accredited institution and four years of experience in law enforcement or investigative work, including two years in insurance investigative work; or an equivalent combination of education and experience; and certification as a sworn law enforcement officer in accordance with the provisions of the North Carolina Criminal Justice Training and Standards Commission. Benefits of NC State Employment: We value our employees and offer a wide variety of competitive and family-friendly benefits. Benefits to include: - 12 Annual paid Holidays - North Carolina State Health Plan administered by AETNA - Supplemental Benefits including: Flexible Spending Accounts, Accident Insurance, Cancer & Specified Disease, Critical Illness, Dental and Vision - NC State Retirement (TSERS) - WeSave Employee Discounts Learn more about employee perks/benefits: - Why Work For NC? - NC OSHR: Benefits Supplemental and Contact Information: For consideration for this vacancy, all applicants must complete an online application using the "APPLY" button above. To receive credit for your work history and credentials, you must list the information on the State Application. Any information omitted from your application cannot be considered for qualifying credit. - Applications with "see attached" or resumes in lieu of completed education and work experience on the formal application will be deemed incomplete and will not be eligible for consideration for the vacancy* Applications for positions requiring specific coursework must be accompanied by a copy of the applicant's transcript. The Department of Insurance/Industrial Commission may conduct criminal history checks of all job applicants recommended for employment. Failure to accurately acknowledge information on criminal convictions on the state application form will be grounds for non-consideration of applications, disciplinary action, and possible criminal prosecution. The Department of Insurance/Industrial Commission is an Equal Employment Opportunity employer and uses the merit-based recruitment and selection plan to fill positions subject to the State Personnel Act with the most qualified individuals. - Academic Degrees must be from appropriately accredited institutions and will be verified. If you are selected for a position at DOI/IC, your academic credentials will be verified. - Applicants requesting and receiving an accommodation under the Americans with Disabilities Act (ADA) are eligible to submit paper applications via mail or by fax. - Applicants seeking Veteran's Preference under N.C.G.S .126 must submit a DD Form 214, Certificate of Release or Discharge from Active Duty. This information may be attached to the online application or be faxed on or before the closing date. Applicants may check the status of their application for a vacancy at any time by logging in to the government jobs system. Once the applicant has logged in, the status of each submitted application is documented next to each vacancy for which they have applied. EEO Statement The State of North Carolina is an Equal Employment Opportunity Employer and dedicated to providing employees with a work environment free from all forms of unlawful employment discrimination, harassment, or retaliation. The state provides reasonable accommodation to employees and applicants with disabilities; known limitations related to pregnancy, childbirth, or related medical conditions; and for religious beliefs, observances, and practices.



