Halvik Corp delivers a wide range of services to 13 executive agencies and 15 independent agencies. Halvik is a highly successful WOB business with more than 50 prime contracts and 500+ professionals delivering Digital Services, Advanced Analytics, Artificial Intelligence/Machine Learning, Cyber Security and Cutting-Edge Technology across the US Government. Be a part of something special.
Halvik is seeking an experienced Penetration Tester. This individual is responsible for evaluating the security of an organization's applications, networks, cloud environments, and supporting infrastructure by conducting authorized, scoped offensive security testing to identify, validate, and help remediate vulnerabilities. This role focuses on hands-on manual testing and controlled exploitation to demonstrate real-world impact, confirm exploitability, and provide clear, actionable remediation guidance to technical teams and leadership.
Key Responsibilities
-
Engagement scopingplanning: Partner with stakeholders to define objectives, rules of engagement, in-scope assets, testing windows, and success criteria; ensure testing is authorized and safely executed.
-
Reconnaissanceenumeration: Perform passive and active discovery of attack surface, services, endpoints, APIs, and misconfigurations; map trust boundaries and data flows.
-
Manual application testing: Conduct deep testing of web apps, mobile apps (as applicable), and application programming interfaces (APIs), aligned to OWASP Top 10 and common design/implementation flaws.
-
Network and infrastructure testing: Identify and validate weaknesses such as exposed services, weak segmentation, insecure protocols, credential issues, and misconfigurations across on-prem and cloud assets. Post-exploitation analysis (when in scope): Assess blast radius, lateral movement paths, sensitive data exposure, and persistence risks; collect evidence responsibly and minimize operational impact.
-
Reportingremediation support: Deliver clear reports including reproduction steps, risk ratings, evidence, and prioritized fixes; communicate effectively with both engineers and non-technical stakeholders; retest fixes as needed.
Preferred Qualifications
-
Experience with mobile (Android/iOS) testing, cloud penetration testing (AWS/Azure/GCP), or CI/CD and supply chain testing.
-
Relevant certifications: OSCP, GWAPT, GPEN, PNPT) or equivalent proven experience.
Required Qualifications:
-
Strong understanding of web application security, OWASP Top 10, and modern attack techniques against web apps and APIs.
-
This role is 100% on-site in Arlington, VA.
-
Demonstrated ability to distinguish false positives vs. exploitable issues, document evidence, and provide pragmatic, developer-friendly remediation guidance.
Halvik offers a competitive full benefits package including:Company-supported medical, dental, vision, life, STD, and LTD insuranceBenefits include 11 federal holidays and PTOEligible employees may receive performance-based incentives in recognition of individual and/or team achievements.401(k) with company matchingFlexible Spending Accounts for commuter, medical, and dependent care expensesTuition AssistanceCharitable Contribution matching
Halvik Corp is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status.