Senior Cyber Security Engineer / CSET
Scientific Research Corporation3 months ago
Orlando, FL, USASenior
Responsibilities
- Execute offensive security, red-team, penetration-testing, and adversarial-emulation engagements from conception through report delivery.
- Develop security testing strategies, programs, accelerators, tools, mechanisms, and processes to improve team velocity and scale.
- Perform open-source intelligence gathering, vulnerability scanning, exploitation, lateral movement, persistence, command-and-control management, and EDR evasion.
- Analyze applications through source-code review and reverse engineering to identify exploitable programming flaws.
- Develop payloads, scripts, and tools for exploitation, evasion, lateral movement, and proof-of-concept weaponization.
- Document exploitation activities, vulnerabilities, remediation recommendations, risks, and mitigation techniques.
- Demonstrate vulnerabilities and support network defenders in improving detection capabilities.
- Lead and coordinate with CSET personnel, range leadership, users, and other event stakeholders.
- Provide security engineering consulting, control-design recommendations, technical briefings, and stakeholder communications.
- Maintain awareness of red-team policies, rules, regulations, compliance documents, and current offensive-security techniques.
Requirements
- Bachelor's degree focused on computer science, computer information systems, engineering, mathematics, management information systems, cybersecurity, cyber operations, or a related discipline, with corresponding experience and demonstrated mastery of relevant computer science topics.
- At least 5 years of cyber adversarial-emulation experience, including penetration testing of modern Windows and Linux operating systems, IP-based networks and protocols, 802.11 networks, web applications, hardware, software-defined networks, or RF.
- At least 10 years of experience leading complex and technically diverse cyber-professional teams.
- Intermediate knowledge of Advanced Persistent Threat tactics, techniques, and procedures and MITRE ATT&CK terminology.
- Intermediate knowledge of exploit development, software debugging, application fuzzing, incident response, reverse engineering, and digital forensics tools and techniques.
- Superior oral communication and technical writing skills, including presentations, technical briefings, requirements gathering, documentation, and communication with non-cyber-specialist audiences.
- Ability to work independently and collaborate with range and event leadership, CSET members, users, and stakeholders.
- Must maintain IAT Level III or IAM Level III certification, including an accepted certification such as CASP+ CE, CCNP Security, CISA, GCIH, GCED, CISM, GSLC, CCISO, or CISSP.
- Must meet applicable DoD 8570 or SECNAV 5239.2 cybersecurity workforce requirements and obtain an accepted vendor certification such as OSCE, OSCP, GXPN, or OSCE3 within six months of hire.
- Preferred qualifications include a master's degree, 10+ years supporting DoD offensive or defensive cyber operations, operational training experience, relevant military or national-security cyber-team experience, and OT, IoT, or XIoT experience.
- U.S. citizenship and a U.S. government Top Secret/SCI security clearance are required.
Benefits
- Medical, dental, and vision plans.
- 401(k) with company match and life insurance.
- Vacation and sick paid time off accruals, with amounts increasing based on role and years of service.
- Eleven paid holidays.
- Tuition reimbursement.
- Work environment encouraging excellence.
- Security-clearance applicants are subject to a government security investigation and eligibility requirements.