Perform vulnerability assessments and penetration testing following the customer’s prescribed scope statement with authorities. The ideal candidate must display familiarity with Windows and Linux operating systems and be able to conduct network and application security vulnerability analysis. Specifically, the candidate will analyze mission systems to help identify potential vulnerabilities and help to provide remediation strategies to customers for these issues. The successful candidate must have prior experience with multiple facets of penetration testing, using both open source and proprietary tools. Conducts open source research on clients and their infrastructure to help identify data leakage to could lead to vulnerabilities. Correlates threat data from various sources. Leverages programming knowledge to develop custom exploits for unique client systems. Travels to client sites on a semi-regular basis to conduct onsite assessments and tests. Prepares assessments and presentations of analyses and findings. Develops and maintains analytical procedures to meet changing requirements and ensure maximum operations.
Duties/Responsibilities:
The position will primarily require the candidate to work with a team of penetration testers, helping to conduct varied testing efforts against applications and networks both for commercial entities and the federal government. Candidates will be expected to integrate into ongoing testing efforts, requiring subject matter expertise in multiple disciplines of vulnerability testing and assessment, the ability to interact and liaison directly with clients and a strong ability to write and document findings. Travel is required on occasional basis for clients requiring onsite testing.
Required Qualifications:
- 6+ years’ experience in three or more specific areas to include: analysis, network engineering, networking security, penetration testing tool, red teaming, hardware engineering, software engineering, vulnerability assessment tools (OS, web, database) etc.
- Familiarity of various operating systems: Windows, iOS, Android, or Linux
- Proficiency with at least three (3) or more of the following: mobile security, telecom protocols, operating systems, reverse engineering, forensics, network analysis, vulnerability assessment or malware.
- Scripting or coding experience
- Working knowledge of software development
- Experience in network analysis methodologies
- Experience in drafting reports, documenting case details, and able to summarize findings and recommendations based on system analysis.
- Demonstrated strong written and verbal communication skills
- BS (or equivalent) in Cyber security, Information Security, IT, EE, Network Engineering, Computer Science, or related field
- US Citizenship and an active TS/SCI with Polygraph clearance required
Additional Qualifications:
- Security Certification: CEH, GIAC or equivalent pen testing cert.
- Familiarity with Wireshark, Fiddler, EnCase, Sleuthkit and similar tools
- Experience employing advanced forensic tools and techniques for attack reconstruction, including dead system analysis and volatile data collection and analysis
- Desired security certification: examples include OSCP, CEH, CISSP, or Security+
- Law Enforcement/Cyber Forensics experience
- Experience in performing post-incident computer forensics without destruction of critical data.
- Experience in Malware Analysis and Reverse Engineering.
- Experience with Splunk, ArcSight, HP Openview, FireEye, Solar Winds, Wed Sense
- Desired experience ensuring quality assurance and the spreading of best practices
- Experience with operational communications
- MS degree in technical field
We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories.
In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.