Penetration Tester
Job Description
Job Description
Halvik Corp delivers a wide range of services to 13 executive agencies and 15 independent agencies. Halvik is a highly successful WOB business with more than 50 prime contracts and 500+ professionals delivering Digital Services, Advanced Analytics, Artificial Intelligence/Machine Learning, Cyber Security and Cutting-Edge Technology across the US Government. Be a part of something special.
Halvik is seeking an experienced Penetration Tester. This individual is responsible for evaluating the security of an organization's applications, networks, cloud environments, and supporting infrastructure by conducting authorized, scoped offensive security testing to identify, validate, and help remediate vulnerabilities. This role focuses on hands-on manual testing and controlled exploitation to demonstrate real-world impact, confirm exploitability, and provide clear, actionable remediation guidance to technical teams and leadership.
Key Responsibilities
- Engagement scoping & planning: Partner with stakeholders to define objectives, rules of engagement, in-scope assets, testing windows, and success criteria; ensure testing is authorized and safely executed.
- Reconnaissance & enumeration: Perform passive and active discovery of attack surface, services, endpoints, APIs, and misconfigurations; map trust boundaries and data flows.
- Manual application testing: Conduct deep testing of web apps, mobile apps (as applicable), and application programming interfaces (APIs), aligned to OWASP Top 10 and common design/implementation flaws.
- Network and infrastructure testing: Identify and validate weaknesses such as exposed services, weak segmentation, insecure protocols, credential issues, and misconfigurations across on-prem and cloud assets. Post-exploitation analysis (when in scope): Assess blast radius, lateral movement paths, sensitive data exposure, and persistence risks; collect evidence responsibly and minimize operational impact.
- Reporting & remediation support: Deliver clear reports including reproduction steps, risk ratings, evidence, and prioritized fixes; communicate effectively with both engineers and non-technical stakeholders; retest fixes as needed.
Preferred Qualifications
- Experience with mobile (Android/iOS) testing, cloud penetration testing (AWS/Azure/GCP), or CI/CD and supply chain testing.
- Relevant certifications: OSCP, GWAPT, GPEN, PNPT) or equivalent proven experience.
Required Qualifications:
- Strong understanding of web application security, OWASP Top 10, and modern attack techniques against web apps and APIs.
- This role is 100% on-site in Arlington, VA.
- Demonstrated ability to distinguish false positives vs. exploitable issues, document evidence, and provide pragmatic, developer-friendly remediation guidance.
Halvik offers a competitive full benefits package including:
Company-supported medical, dental, vision, life, STD, and LTD insurance
Benefits include 11 federal holidays and PTO
Eligible employees may receive performance-based incentives in recognition of individual and/or team achievements.
401(k) with company matching
Flexible Spending Accounts for commuter, medical, and dependent care expenses
Tuition Assistance
Charitable Contribution matching
Halvik Corp is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status.
Halvik's pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
Recommended Jobs
Office Director
The Company Founded by two University of Pennsylvania graduates in 1998, Georgetown Learning Centers is an educational company committed to helping kids of all ages and abilities succeed in their aca…
Diesel Mechanic - Fleet Technician A
Job Description Job Description Responsibilities Reyes Fleet Management, 1 of the largest privately held fleets in the U.S., is looking to hire a Diesel Mechanic / Fleet Technician A to per…
Landscape Account Manager
Job Description Job Description The Account Manager (AM) will serve as the primary contact for clients, ensuring that RSG has sustained long-term, loyal relationships. This individual achieves cl…
NCIS Help Desk Manager | Active TS/SCI clearance
Public Trust: None Requisition Type: Pipeline Your Impact Own your opportunity to support our nation's defense. Make an impact by connecting and securing critical operations across the glo…
Senior Manager, Data Science - AI Foundations
Overview Senior Manager, Data Science - AI Foundations Data is at the center of everything we do. As a startup, we disrupted the credit card industry by individually personalizing every credit…
Sr Data Analyst :: Richmond, VA (Onsite hybrid) (Richmond, VA)
Sr Data Analyst - 3 Positions Location: Richmond, VA (Onsite hybrid) Duration: 11 Months+ Top Skills: 3+ Yrs exp is a must SQL exp is a must Python & Pandas exp is a must AWS (EC2,…
Buzz Franchise Brands Marketing Intern
Buzz Franchise Brands Marketing Intern Buzz Franchise Brands (BFB) is a multi-brand franchise company focused on being the best provider of services to homes and people across the country. Our brand …
Cardiac Device Specialist
Location: Falls Church, Fairfax, VA (Heart and Rhythm Center) Status: Exempt/Full-Time/Part-Time Salary: $40 - $43/hr. + $10,000 Sign-On Bonus + Relocation Assistance Are you looking for new c…
Counter Team Members & Baristas - Tatte Old Town
Job Description Job Description Our front of house team members welcome and care for guests in our cafes. Counter team members will have a working knowledge of all Tatte products, delivering deli…
Senior Full Stack Engineer-Mobile Applications
Job Description Job Description Trademasters, an award-winning contractor with over 30 years of industry experience, offers complete facility operations management, maintenance, and repairs to mi…