- Company Name
- KAYConnect LLC
- Job Title
- Multiple role -Role -1 -Security Architect , Role 2 -Vulnerability Assessment- Penetration Testing Specialist
- Job Description
-
Job Title: Security Architect / Infrastructure Security Specialist
Role Summary: Design, implement, and maintain the enterprise security architecture, ensuring secure design of networks, servers, storage, and operating systems. Lead risk assessments, vulnerability management, and alignment with industry frameworks.
Expectations: Minimum 5+ years assessing enterprise IT environments. Deep knowledge of infrastructure security, cloud platforms (AWS, Azure, GCP), and security frameworks (NIST, ISO 27001, CIS). Must communicate technical concepts to both technical and non‑technical stakeholders and possess experience in regulated or government contexts.
Key Responsibilities:
- Develop and evolve security architecture and controls for enterprise infrastructure.
- Conduct risk assessments and vulnerability management across networks, servers, storage, and OS.
- Evaluate existing security posture against industry frameworks and recommend improvements.
- Collaborate with infrastructure, development, and operations teams to embed security early in the SDLC.
- Produce and present clear, actionable security documentation and post‑mortem analysis.
Required Skills:
- Expertise in network, server, storage, and OS security.
- Hands‑on experience with vulnerability assessment and risk management processes.
- Proficiency with cloud security configurations and identity/access management.
- Knowledge of security frameworks and standards (NIST, ISO 27001, CIS).
- Strong written and verbal communication skills.
Required Education & Certifications:
- CISSP, CCSP, CISM, or equivalent.
Job Title: Vulnerability Assessment / Penetration Testing Specialist
Role Summary: Execute comprehensive vulnerability assessments and penetration tests on enterprise systems, networks, and applications to uncover security weaknesses, produce detailed findings, and guide remediation efforts.
Expectations: Minimum 3+ years performing Vulnerability Assessments or Pen Testing in enterprise environments. Must be proficient with standard tools, possess strong documentation and communication capabilities, and familiar with highly regulated or government environments.
Key Responsibilities:
- Plan and execute penetration tests using automated and manual methodologies.
- Perform vulnerability scanning, exploitation, and post‑exploitation analysis.
- Document findings in concise reports, providing remediation recommendations and risk prioritization.
- Communicate results to technical and business stakeholders, translating findings into actionable plans.
- Maintain test libraries, tools, and test case repositories.
- Stay up‑to‑date with emerging threats, OWASP Top 10, and industry best practices.
Required Skills:
- In‑depth knowledge of OWASP Top 10, common network and system vulnerabilities.
- Hands‑on experience with penetration testing tools and techniques.
- Strong documentation, report writing, and presentation abilities.
- Ability to work independently and collaborate cross‑functionally.
Required Education & Certifications:
- GIAC Web Application Penetration Tester (GWAPT)
- Certified Ethical Hacker (CEH)
- GIAC Systems and Network Auditor (GSNA)
- Certified Penetration Tester (CPT)
- Certified Expert Penetration Tester (CEPT)
- GIAC Certified Web Application Defender (GWEB)
- Offensive Security Certified Professional (OSCP)
- CREST Penetration Testing Certifications (e.g., CRTP, CRTO)
Washington, United states
Hybrid
Mid level
27-01-2026