RFO, so Pay rate & Bill rate need to be compettive.
C MAS – DMV IT CMAS RFO -
SECURITY SPECIALIST 3SECURITY SPECIALIST 3 - Senior Web Application Security / Penetration Testing SpecialistClient: California Department of Motor Vehicles (DMV)
Department: Information Security Services Branch (ISSB)
RFO: ISD26-4861
Project: Information Security Testing and Web Application Assessment
Location: Sacramento, California / Remote within Continental United States with DMV approval
DMV Site: 2415 First Avenue, Sacramento, CA 95818
Anticipated Start: November 10, 2026
Contract: 1-year base term with optional extensions
Role Overview
The California Department of Motor Vehicles is seeking an exceptionally experienced
Security Specialist 3 to support the DMV Information Security Services Branch in protecting high-profile, public-facing web applications and the sensitive information handled by DMV systems.
This is a
senior hands-on application security and penetration testing position, not a general cybersecurity analyst or security operations role.
The Security Specialist 3 will perform security assessments and penetration testing against current DMV public-facing web applications and major application changes, identify and validate vulnerabilities, assign risk ratings, recommend remediation, verify mitigation effectiveness, assess security/privacy controls, and help establish standardized application-security assessment methodologies.
The consultant will work closely with the
DMV Chief Information Security Officer (CISO) and Information Security Office personnel. The individual will also help ensure DMV secure-coding standards align with California and federal security requirements, including
SAM, SIMM, NIST and PCI, and will provide knowledge transfer and mentoring to DMV personnel.
This role requires someone who can move comfortably between
offensive security testing, regulatory compliance, risk assessment, secure software development, remediation validation, executive-quality reporting, and training.
What This Person Will Actually Do
The Security Specialist 3 will:
- Conduct comprehensive security assessments of current public-facing DMV web applications.
- Perform security assessments when major changes are made to public-facing DMV applications.
- Develop and execute web application penetration tests.
- Identify exploitable application vulnerabilities and security weaknesses.
- Validate findings to distinguish meaningful security risks from false positives.
- Assign appropriate risk ratings to identified vulnerabilities.
- Develop clear, actionable mitigation and remediation recommendations.
- Prepare formal assessment reports for the DMV CISO.
- Work with the DMV CISO and technical teams to validate vulnerabilities and proposed mitigation strategies.
- Retest vulnerabilities following remediation to determine whether risk has been reduced to an acceptable level.
- Develop a standardized methodology for assessing DMV web applications for vulnerabilities and risk.
- Review closed Plan of Action and Milestones (POAM) Security and Privacy control items and determine whether remediation is sufficient and effective.
- Develop standardized security and privacy control-assessment methodologies that satisfy State of California and NIST requirements.
- Review DMV secure-coding standards and related security documentation.
- Map SAM, SIMM, NIST and PCI security controls to secure-coding standards.
- Identify gaps between application-development practices and applicable security/control requirements.
- Develop and deliver in-person and self-paced training on secure coding and web-application-security best practices.
- Conduct knowledge-sharing and mentoring sessions with DMV personnel.
- Produce clear technical documentation and knowledge-transfer materials.
These responsibilities are directly tied to Tasks 1-3 of the SOW and repeat under the optional extension as Tasks 4-6.
MANDATORY REQUIREMENTS - DO NOT SUBMIT WITHOUT THESEMandatory Certifications
The candidate must possess
ALL THREE of the following certifications, and each must have been held valid for a
minimum of five years:
- CISSP - Certified Information Systems Security Professional
- PCI QSA - Payment Card Industry Qualified Security Assessor
- GWAPT - GIAC Web Application Penetration Tester
The RFP explicitly requires copies of all three valid certifications.
Recruiter warning: A candidate with CISSP and GWAPT but no PCI QSA does
not meet the stated requirement. A candidate who just earned one of these certifications also does not satisfy the stated five-year certification requirement.
Mandatory Experience5+ years - NIST and FIPS
Minimum five years of professional experience working with:
- National Institute of Standards and Technology ( NIST)
- Federal Information Processing Standards ( FIPS)
5+ years - California SAM and SIMM
Minimum five years working with:
- California State Administrative Manual ( SAM)
- California Statewide Information Management Manual ( SIMM)
This makes prior
California State Government cybersecurity experience extremely valuable and significantly narrows the target candidate population.
10+ years - Web Application Security
Minimum ten years developing and executing:
- Web Application Assessments
- Web Application Penetration Testing
This should be genuine hands-on experience, not simply oversight of penetration-testing vendors.
5+ years - Regulatory/Data Protection
Minimum five years of experience with one or a combination of:
- PCI DSS
- IRS Publication 1075
- State/local government financial-data protection
- ISO/IEC 27000 series
3+ years - Security Training
Minimum three years developing
both in-person and self-paced training covering:
- Secure coding standards
- Web application security best practices
T
hese are explicit mandatory qualifications in the DMV SOW.
HIGHLY DESIRABLE CERTIFICATIONS- GCPN - GIAC Cloud Penetration Tester
- GMOB - GIAC Mobile Device Security
- This matters because DMV can award up to 100 desirable-qualification points for Security Specialist 3 based on these certifications. Copies of the certifications must be supplied.
- Therefore, between two otherwise qualified candidates, the candidate with GCPN or GMOB should receive significant recruiting priority.
Technical Skills Recruiters Should Target; Strong candidates should demonstrate substantial hands-on knowledge in:
- Web Application Penetration Testing
- Application Security Testing
- Vulnerability Assessment
- Vulnerability Validation
- Secure Coding
- Application Security
- OWASP methodologies
- OWASP Top 10
- Authentication and Authorization Testing
- Session Management
- Input Validation
- Injection vulnerabilities
- SQL Injection
- Cross-Site Scripting
- Access-control vulnerabilities
- API Security Testing
- Web/API penetration testing
- Burp Suite
- Metasploit
- Manual penetration-testing techniques
- Vulnerability scanners
- Risk Rating / Risk Assessment
- Remediation Validation
- Security Control Assessment
- POA&M / POAM validation
- NIST
- FIPS
- California SAM
- California SIMM
- PCI DSS
- PCI QSA assessments
- ISO 27000 / ISO 27001
- IRS Publication 1075
- Secure SDLC
- Secure Coding Standards
- Security documentation
- Security/privacy controls
Some of these specific tools and attack categories are recruiter search terms I recommend based on the required penetration-testing work; where DMV names technologies explicitly, I have kept those distinctions above.
Ideal Candidate Background; The strongest candidate will likely come from one or more of these environments:
- California State Government Information Security
- State or Local Government Application Security
- PCI Qualified Security Assessor / QSA organization
- Enterprise Application Security / AppSec
- Web Application Penetration Testing
- Cybersecurity Consulting
- Financial Services Security / PCI environments
- Government security assessment
- A candidate who has previously performed penetration testing for a California State department would be particularly attractive because the five-year SAM/SIMM requirement is unusually specific.
Soft Skills Required- Executive communication: Findings ultimately need to be presented in reports to the DMV CISO.
- Technical writing: Must turn highly technical vulnerabilities into clear findings, risk ratings, remediation recommendations and formal assessment documentation.
- Consultative ability: Must be able to work with application developers and security personnel to explain vulnerabilities without simply issuing findings.
- Teaching and mentoring: Knowledge transfer is a formal contractual task.
- Analytical judgment: Must determine whether remediation and closed POAM items are actually sufficient and effective.
- Professional discretion: Candidate may be working with highly sensitive security information and PII.
- Standards orientation: Must be comfortable operating in a highly controlled State-government environment where documentation and compliance matter.
- Collaboration: Will interact with DMV security personnel, developers, analysts, programmers, management and subject-matter experts.