Company

SAICSee more

addressAddressBeltsville, MD
type Form of workFull-Time
CategoryInformation Technology

Job description

Job ID: 2315690

Location: BELTSVILLE, MD, US

Date Posted: 2023-11-17

Category: Cyber

Subcategory: Cyber Engineer

Schedule: Full-time

Shift: Day Job

Travel: Yes, 10 % of the Time

Minimum Clearance Required: Secret

Clearance Level Must Be Able to Obtain: Top Secret

Potential for Remote Work: No


Description

SAIC is seeking a highly motivated Penetration Tester. The successful candidate will provide support to the Cybersecurity Integrity Center (CIC) in the Department of State Bureau of Information Resource Management (IRM). Duties are in the Washington, D.C. metropolitan area (30% in downtown D.C; 70% in Beltsville, MD). The CIC supports cybersecurity monitoring, threat analysis, incident response, and infrastructure remediation within and across all of the State Department’s information technology (IT) infrastructure. The CIC coordinates and collaborates with other State Department bureaus as well as other organizations within the Federal Government, and commercial partners.

The position may allow temporary hybrid remote work due to Covid-19.  Position may be called back onsite at any time at the customer's request.  Team is currently reporting onsite 3 days per week or more as needed.

Description of Duties

The Penetration Tester will provide support for HVA Assessments using methodology by Cybersecurity and Infrastructure Security Agency (CISA) Assessment Evaluation and Standardization (AES) program with broad and in-depth knowledge to conduct offensive cyber operations across the organization globally. In this role, you will conduct offensive security operations to emulate adversary tactics and procedures to test preventative, detective, and response controls across the global technology landscape. The Penetration Tester will:

  • Conduct highly complex offensive security operations testing consistent with known adversary tactics techniques and procedures and contribute to the development of objectives and approaches taken to remediate risk.
  • Apply sound technical and management principles to identify and remediate cybersecurity --vulnerabilities across the State Department global IT enterprise infrastructure.
  • Apply organizational and process change principals.
  • Evaluate system performance results, perform risk assessments, and evaluate performance metrics.

Responsibilities include:

  • Provide ad-hoc penetration testing and assessment services on Department of State systems identified by the leadership.
  • Develop, Identify and resolve security vulnerabilities related to deployment and testing processes.
  • Streamline and optimize processes and procedures in order to rapidly remediate vulnerabilities from cybersecurity threats.
  • Collaborate with Department and external cyber stakeholders on cybersecurity technology implementations to meet specific operational needs.
  • Perform technical evaluations of recommended vulnerability mitigation actions and make recommendations based on impact and/or other countermeasures.
  • Develop strategies for CIC cyber defense technologies, ensuring integration and alignment for continued operation.
  • Conduct assessments of threats and vulnerabilities; determine deviations from acceptable configurations, enterprise, or local policy; assess the level of risk; and develop and/or recommend appropriate mitigation countermeasures in operational and non-operational situations.
  • Network Mapping include but are not limited to a network map of the organization’s system that includes a visual representation of the organization's physical devices and digital network.
  • Perform operation and maintenance activities in support of existing CIC cyber tools and technologies (MSV, Qualys, Tenable Nessus and others).
  • Identify, diagnose, and prioritize anomalies in cyber defense infrastructure and resources.
  • Perform cybersecurity testing of developed applications and/or systems.  Identify and direct the remediation of technical problems encountered during testing and implementation of new systems.
  • Document security issues and impacts identified through offensive operations in a clear and concise manner to facilitate reporting to impacted stakeholders.
  • Provide guidance and recommendations to stakeholders responsible for security remediation actions to close identified gaps and remediation validation testing.
  • Independently handle complex issues with minimal supervision, while escalating only the most complex issues to appropriate staff.

Qualifications

Required Education & Experience

  • Bachelor’s and five (5) years or more experience; Master’s and three (3) years or more experience.
  • A degree in Cybersecurity or related field.
  • 4-6+ years penetration testing experience.
  • Web application penetration testing, LPT, Source code vulnerability analysis, serious problem-solving skills experience.
  • All Penetration Testers/operators must be DHS/CISA AES qualified within 90 days of onboarding.

Required Clearance

  • US Citizenship.
  • Active TS is highly preferred.
  • Active Secret Clearance may be accepted with ability to obtain a Top Secret Clearance within 90 days.

Desired

  • 4 years Microsoft Operating Systems (OS) engineering and support experience focusing on Active Directory (AD), System Center Configuration Manager (SCCM), System Center Operations Manager (SCOM).
  • 4-6 years Network penetration testing experience.
  • In-depth experience in planning, implementing, and managing large/global enterprise infrastructures.
  • Familiarity of various analytical tools (Splunk, USBDeview, Netwitness, MimiKatz).
  • Understanding of Security Information and Event Management (SIEM) tools (Splunk, McAfee).
  • Familiarity of Cobalt Strike, Nessus, Kali Linux, Burp Suite, Nmap and OpenVAS for databases.
  • Knowledge of general attack stages.
  • Skill in the use of social engineering techniques and using penetration testing tools.
  • Familiarity with OMB, NIST, DHS, and related security guidelines and directives.
  • Interpersonal skills including the ability to collaborate effectively, and excellent written and oral communications.
  • Network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
  • Server/endpoint OS (Microsoft, Linux, IOS) along with mobile and cloud technologies.
  • Cloud application security, Vulnerability Management and Security Information, and Event Management capabilities.
  • Countermeasures / mitigations to identified cybersecurity risks.
  • Knowledge of network protocols such as TCP/IP, Dynamic Host Configuration Protocol (DHCP), domain name system, and directory services.

Covid Policy: SAIC does not require COVID-19 vaccinations or boosters. Customer site vaccination requirements must be followed when work is performed at a customer site.
Refer code: 7134998. SAIC - The previous day - 2023-12-16 19:51

SAIC

Beltsville, MD
Jobs feed

MEDICATION AIDE CERTIFIED

Campbell County Health

Gillette, WY

CATERING COORDINATOR

Compass Group

Roanoke, TX

EXECUTIVE CHEF -LYON COLLEGE -BATESVILLE, AR

Compass Group

Batesville, AR

DISHWASHER (FULL TIME)

Compass Group

Norfolk, VA

CASHIER/FOOD SERVICE WORKER (PART TIME)

Compass Group

Wyoming, MN

Manager, Corporate Tax

Nordson Corporation

Westlake, OH

United States, Ohio, Westlake

CLEANROOM TECHNICIAN (FULL TIME)

Compass Group

Frederick, MD

Share jobs with friends

Related jobs

Penetration Tester

Penetration Tester

Jasint

$99.9K - $127K a year

Annapolis Junction, MD

a month ago - seen

Penetration Tester

Realmone

$112K - $142K a year

Columbia, MD

a month ago - seen

Lead Sr. Penetration Tester with active TS/SCI Poly

Leidos

Annapolis, MD

a month ago - seen

Penetration Tester

Boozallen

Annapolis Junction, MD

a month ago - seen

Penetration Tester, Senior

Booz Allen Hamilton, Inc.

Annapolis, MD

a month ago - seen

Lead Sr. Penetration Tester with active TS/SCI Poly

Leidos

$101,400 - $183,300 a year

Annapolis Junction, MD

2 months ago - seen

Penetration Tester

Synergy Ecp Llc

$96.2K - $122K a year

Columbia, MD

3 months ago - seen

Penetration Tester Skill, Level 3 (2023-0202)

Acclaim Technical Services

$107K - $136K a year

Annapolis Junction, MD

3 months ago - seen

Penetration Tester (Red Team Operator)

Systems Application & Technologies Inc

$88.6K - $112K a year

Patuxent River, MD

3 months ago - seen

Lead Penetration Tester - Top Secret w/ FS Polygraph

Sunayu, LLC

Annapolis Junction, MD

4 months ago - seen

Penetration Tester

Leidos

Annapolis, MD

4 months ago - seen

Penetration Tester

Belay Technologies

Annapolis Junction, MD

4 months ago - seen

Lead Penetration Tester

WOOD Consulting Services

Annapolis Junction, MD

4 months ago - seen

Penetration Tester

Belay Technologies

Annapolis, MD

4 months ago - seen

Penetration Tester, Lead

Booz Allen Hamilton, Inc.

Annapolis, MD

5 months ago - seen

IT Security Specialist - Penetration Tester

IBSS Corporation

Silver Spring, MD

5 months ago - seen