Jobs
>
Orlando

    Cyber Security Evaluation - Orlando, United States - Scientific Research

    Default job background
    Description

    MINIMUM SKILLS & REQUIREMENTS:

    • Bachelor's degree in: computer science; engineering; mathematics, management of information systems; cybersecurity; or a related field of study
    • 5+ years' of cyber adversarial emulation experience to include penetration testing of modern Windows and Linux operating systems, IP-based networks and protocols, networks, and/or web applications
    • 10+ years' experience in leading complex and technically diverse teams of cyber personnel (software developers, system admins, pen testers, incident responders, etc.)
    • Intermediate knowledge of known Advanced Persistent Threat (APT) actor Techniques, Tactics, and Procedures (TTPs), to include familiarity with terminology from Mitre ATT&CK used to describe TTPs used in cyberattacks
    • Intermediate knowledge of techniques and tools used for exploit development of common operating systems, software debugging, and application fuzzing
    • Intermediate knowledge of tools and techniques used for incident response, reverse engineering, and digital forensics
    • Strong oral communication skills, ability to project confidence and enthusiasm, in the following core areas: formal presentations; soliciting goals and requirements from range users; explaining adversarial emulation in the context of testing and training events; effectively communicating event and environment requirements to CSET members; explaining cost estimates based on estimated levels of CSET effort; managing expectations as relevant to CSET TTPs; and explaining technical nuances and significant attributes of advanced cyberattacks to non-cyber-savvy audiences
    • Superior technical writing skills, including the ability to author, review, and provide clear input/feedback to documents drafted by CSET personnel
    • Ability to create convincing technical briefing materials relevant to range training and test events
    • Be able to work independently and to collaborate with cyber range and event leadership, CSET team members, users, and other event stakeholders
    • Required/Maintain IAT Level III or IAM Level III 8570 certifications include one or more of the following:
      • CASP+ CE
      • CCNP Security
      • CISA
      • GIAC Incident Handler (GCIH)
      • GIAC Certified Enterprise Defender (GCED)
      • CISM
      • GSLC
      • CCISO
    • Certified Information Systems Security Professional (CISSP)
    • In addition to meeting the applicable cyber security workforce (CSWF) requirements for Computer Network Defenders (CND) Auditors (DoD 8570) or Vulnerability Assessment Analysts (SECNAV , CSET members must obtain one or more of the following vendor certifications within 6 months of being hired:
      • Offensive Security Certified Engineer (OSCE)
      • Offensive Security Certified Professional (OSCP)
      • GIAC Certified Exploit Researcher and Advanced Penetration Testers (GXPN)
      • Offensive Security Certified Engineer (OSCE3)

    DESIRED SKILLS & REQUIREMENTS:

    • Master's degree with a focus in computer science, cybersecurity, or cybersecurity
    • 10+ years of experience supporting the execution of Department of Defense (DoD) offensive cyber operations (OCO) or defensive cyber operations (DCO) as a civilian, contractor, or uniformed personnel
    • Experience with operational training programs and qualification standards
    • Red Team, Computer Operator or Exploitation Analyst experience with Transportation Systems Management and Operations (TSMO), US Air Force, US Navy or National Security Agency (NSA) / Cyber Mission Force teams
    • Experience with OT, IoT, XIoT is a plus

    SRC IS A CONTRACTOR FOR THE U.S. GOVERNMENT, THIS POSITION WILL REQUIRE U.S. CITIZENSHIP AS WELL AS A U.S. GOVERNMENT SECURITY CLEARANCE AT THETOP SECRET / SCI LEVEL

    DUAL CITIZENSHIP NOT ALLOWED

    ABOUT US

    Scientific Research Corporation is an advanced information technology and engineering company that provides innovative products and services to government and private industry, as well as independent institutions. At the core of our capabilities is a seasoned team of highly skilled engineers and scientists with multidisciplinary backgrounds. This team is challenged daily to provide cutting edge technology solutions to our clients.

    Scientific Research Corporation offers a competitive salary, an extensive benefits package and a work environment that encourages excellence. For positions requiring a security clearance, selected applicants will be subject to a government security investigation and must meet eligibility requirements for access to classified information.

    DIVERSITY & INCLUSION

    We strongly believe in the abundance of differences among individuals. We value different points of view and appreciate diverse perspectives. We truly believe this is what makes our organization inclusive and more responsive to the needs of our diverse customers.

    EQUAL OPPORTUNITY EMPLOYER

    Scientific Research Corporation is an equal opportunity and affirmative action employer that does not discriminate in employment.

    All qualified applicants will receive consideration for employment without regard to their race, color, religion, sex, age, sexual orientation, gender identity, or national origin, disability or protected veteran status.

    Scientific Research Corporation endeavors to make accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact for assistance. This contact information is for accommodation requests only and cannot be used to inquire about the status of applications.

    [#CJ #LI-HK1]

    PRIMARY DUTIES & RESPONSIBILITIES:

    • Oversee CSET Team operators and provide guidance and subject matter expertise to government personnel
    • Support offensive security/red team/adversarial emulation testing
    • Execute Red Team engagements in a variety of networks using real-world adversarial Tactics, Techniques, and Procedures (TTPs) from conception to report delivery
    • Develop comprehensive security testing strategies and programs across NCRC-U to provide assurance that security controls are designed and operating effectively
    • Develop innovative accelerators, tools, mechanisms, and processes to enhance the security team's velocity and scale to customer needs
    • Facilitate multiple stakeholders to agree on appropriate solutions and verify that risks are mitigated appropriately. Demonstrate creativity, insight, intellectual flexibility, and sound business judgment throughout the process
    • Work independently but collaborate with cross-functional to provide security engineering consulting and control design recommendations to reduce risk
    • Conduct open-source intelligence gathering, network vulnerability scanning, exploitation of vulnerable services, lateral movement, install persistence in a target network(s), and manage C2 infrastructure
    • Systematically analyze each component of an application with the intent of locating programming flaws that could be leveraged to compromise the software through source code review or reverse engineering
    • Develop payloads, scripts and tools that weaponize new proof-of-concepts for exploitation, evasion, and lateral movement
    • Safely utilize attacker tools, tactics, and procedures when in sensitive environments/devices
    • Evade EDR devices such as Windows Defender and Carbon Black to avoid detection by Defenders/behavioral based alerting in order to further the engagement objectives
    • Demonstrate expertise in one of the following: Active Directory, Software Development, Incident Response, or Cloud Infrastructure
    • Carefully document and log all exploitation activities
    • Continually exercise situational awareness in order quickly identify any instances of cohabitation
    • Document identified vulnerabilities and research corrective/remediation actions in order to recommend a risk mitigation technique(s)
    • Demonstrate new vulnerabilities and assist Network Defenders (Blue Team) with the refinement of detection capabilities
    • Maintain knowledge of applicable Red Team policies, Standing Ground Rules, regulations, and compliance documents
    • Communicate effectively with team members and during an engagement
    • Ability to think unconventionally in order to develop adversarial TTPs
    • Keep current with TTPs and the latest offensive security techniques


  • Scientific Research Corporation Orlando, United States

    Job Description PRIMARY DUTIES & RESPONSIBILITIES: · * Oversee CSET Team operators and provide guidance and subject matter expertise to government personnel · * Support offensive security/red team/adversarial emulation testing · * Execute Red Team engagements in a variety of netw ...


  • Scientific Research Orlando, United States

    Job Description · PRIMARY DUTIES RESPONSIBILITIES:Oversee CSET Team operators and provide guidance and subject matter expertise to government personnel · Support offensive security/red team/adversarial emulation testing · Execute Red Team engagements in a variety of networks usin ...


  • COLSA Orlando, United States

    **General Summary**: · Performs system monitoring and analysis support for the detection of cyber incidents and provides recommendations on how to correct findings. · **Principal Duties and Responsibilities (*Essential Functions)**: · - Develops Risk Management Framework (RMF) Ce ...


  • COLSA Orlando, United States

    **General Summary**: · Performs system monitoring and analysis support for the detection of cyber incidents and provides recommendations on how to correct findings. · **Principal Duties and Responsibilities (*Essential Functions)**: · - Monitors the network and supporting systems ...


  • NSA Orlando, United States

    **NATION SECURITY** · **About Nation Security**: · Nation Security employer dynamic is like none-other in many aspects. We provide on-the-job training, position advancements, and learning a wide variety of skills. Each employee has growth opportunities that would not only allow e ...


  • Melnik Legal PLLC Orlando, United States

    Want to work on challenging and innovative legal issues that require strategic and creative thinking, for a law firm that cares about improving health care delivery, privacy, security, and technology? You'll be responsible for negotiating and drafting information technology and h ...


  • Council For Logistics Research Inc Orlando, United States

    **Cybersecurity Analyst** · **Council for Logistics Research, Inc.** · **Benefits Offered: Medical, Life Insurance, 401k, Dental** · **Employment Type Full-Time** · **Location: Orlando, FL / Remote Authorized** · **Supervises: No** · **Must be a US Citizen and have a current Secr ...


  • Brambles Group Orlando, United States

    CHEP helps move more goods to more people, in more places than any other organization on earth via our 300 million pallets, crates and containers. We employ 11,000 people and operate in more than 55 countries. Through our pioneering and sustainable share-and-reuse business model, ...


  • Lockheed Martin Orlando, United States

    **Job ID**: 663909BR · **Date posted**: Apr. 01, 2024 · **Program**: LRASM · Responsibilities include, but are not limited to: · - Oversee day-to-day information system security operations including assisting the ISSM on all technical security matters. · - Carry out technical adm ...


  • Sam's Club Orlando, United States

    **Position Summary...** · **What you'll do...** · Assists management with the supervision of associates in assigned area of responsibility by assigning duties to associates; communicating goals and · feedback; training associates on processes and procedures; providing direction a ...


  • Hilton Grand Vacations Orlando, United States

    **WORK FOR A WINNING TEAM THAT NOW OFFERS BENEFITS FROM DAY ONE, PLUS DAILY PAY** · At Hilton Grand Vacations, you will become a part of a culture that encourages and motivates you toward achieving your goals. · **Here's why you will love it here**: · - Recognition Programs and R ...

  • Soar Technology

    Ui/ux Designer

    1 week ago


    Soar Technology Orlando, United States

    **About Us** · At SoarTech, our focus is on the development of artificial intelligence (AI) that reasons like humans do to automate complex tasks, simplify human-machine interactions, or model human behaviors. Our philosophy is three-fold: to be an augmentation to, not a replacem ...


  • Disney Experiences Orlando, United States

    "We Power the Magic" That's our motto at Disney Parks, Experiences and Products Technology & Digital. Our team creates world-class immersive digital experiences for the Company's premier vacation brands including Disney's Parks & Resorts worldwide, Disney Cruise Line, Aulani, A D ...

  • Conti Federal Services

    Project Executive

    4 days ago


    Conti Federal Services Orlando, United States

    Conti Federal Services is a leading global construction and engineering company that has delivered some of the most demanding projects for the U.S. federal government. With roots dating back more than 115 years, Conti Federal specializes in military construction, critical infrast ...


  • JetBlue Airways Corporation Orlando, United States

    **Position Summary** · The Instructional Designer analyzes, designs, and develops educational programs that will address the needs of JetBlue corporate and operational Crewmembers, while fulfilling Federal Aviation Administration (FAA) requirements for regulatory and non-regulato ...

  • Soar Technology

    Proposal Manager

    1 day ago


    Soar Technology Orlando, United States

    **About Us** · At SoarTech, our focus is in the development of artificial intelligence (AI) that reasons like humans do, to automate complex tasks, simplify human-machine interactions, or model human behaviors. Our philosophy is three-fold: to be an augmentation to, not a replace ...

  • CKS Packaging, Inc.

    Parts Purchasing

    3 days ago


    CKS Packaging, Inc. Orlando, United States

    **Parts Purchasing and Receiving · - Orlando, FL** · **What's In it for You?** · - Competitive pay based on experience and qualifications · - Paid vacation, sick days and bonus after eligibility period met · - Excellent medical/dental benefits at modest employee contributions · - ...

  • Marriott Vacations Worldwide

    Corporate Counsel

    1 week ago


    Marriott Vacations Worldwide Orlando, United States

    **Business Title**: Corporate Counsel - Litigation, Compliance, & Privacy · **Leadership Role**:Manager of Others · **Position Summary** · The attorney in this position will work in the Law Department's Litigation, Compliance, and Privacy Group reporting to the Senior Vice Presid ...


  • US United States Army Futures Command Orlando, United States

    **Duties**: · - Serving as the Subject Matter Expert regarding the capability's development process for the Synthetic Training Environment Cross Functional Team. · - Advocating for the evolution of new or substantially new training equipment, augmented reality, artificial intelli ...


  • F.I.R.S.T. Institute Orlando, United States

    **Program Director of Recording Arts and Show Production** · **Why F.I.R.S.T. Institute?** · A Program Director at F.I.R.S.T. Institute in Orlando, FL offers a fun, challenging work environment that supports teamwork and inspires professional excellence. When you consider a caree ...