Task statements

  • Test the security of systems by attempting to gain access to networks, Web-based applications, or computers.
  • Document penetration test findings.
  • Identify security system weaknesses, using penetration tests.
  • Write audit reports to communicate technical and procedural findings and recommend solutions.
  • Gather cyber intelligence to identify vulnerabilities.
  • Maintain up-to-date knowledge of hacking trends.
  • Keep up with new penetration testing tools and methods.
  • Identify new threat tactics, techniques, or procedures used by cyber threat actors.
  • Conduct network and security system audits, using established criteria.
  • Develop security penetration testing processes, such as wireless, data networks, and telecommunication security tests.
  • Evaluate vulnerability assessments of local computing environments, networks, infrastructures, or enclave boundaries.
  • Prepare and submit reports describing the results of security fixes.
  • Develop and execute tests that simulate the techniques of known cyber threat actors.
  • Discuss security solutions with information technology teams or management.
  • Collect stakeholder data to evaluate risk and to develop mitigation strategies.
  • Update corporate policies to improve cyber security.
  • Assess the physical security of servers, systems, or network devices to identify vulnerability to temperature, vandalism, or natural disasters.
  • Investigate security incidents, using computer forensics, network forensics, root cause analysis, or malware analysis.
  • Develop infiltration tests that exploit device vulnerabilities.
  • Design security solutions to address known device vulnerabilities.
  • Configure information systems to incorporate principles of least functionality and least access.
  • Develop presentations on threat intelligence.

Career and skills data: O*NET 31.0 (onetcenter.org). Figures are published survey estimates, not real-time market data.