Jobs
>
Beltsville

    Penetration Tester with Security Clearance - Beltsville, United States - SAIC

    SAIC
    SAIC Beltsville, United States

    3 weeks ago

    Default job background
    Description
    You will need to login

    before you can apply for a job.
    Penetration Tester with Security Clearance

    Description SAIC is seeking a highly motivated Penetration Tester.

    The successful candidate will provide support to the Cybersecurity Integrity Center (CIC) in the Department of State Bureau of Information Resource Management (IRM).

    Duties are in the Washington, D.C. metropolitan area (30% in downtown D.C; 70% in Beltsville, MD.

    The CIC supports cybersecurity monitoring, threat analysis, incident response, and infrastructure remediation within and across all of the State Department's information technology (IT) infrastructure.

    The CIC coordinates and collaborates with other State Department bureaus as well as other organizations within the Federal Government, and commercial partners.

    The position allows hybrid remote work. Team is currently reporting onsite 3 days per week or more as needed.

    Description of Duties The Penetration Tester will provide support for HVA Assessments using methodology by Cybersecurity and Infrastructure Security Agency (CISA) Assessment Evaluation and Standardization (AES) program with broad and in–depth knowledge to conduct offensive cyber operations across the organization globally.

    In this role, you will conduct offensive security operations to emulate adversary tactics and procedures to test preventative, detective, and response controls across the global technology landscape.


    The Penetration Tester will:

    Conduct highly complex offensive security operations testing consistent with known adversary tactics techniques and procedures and contribute to the development of objectives and approaches taken to remediate risk.

    Apply sound technical and management principles to identify and remediate cybersecurity vulnerabilities across the State Department global IT enterprise infrastructure.

    Apply organizational and process change principals. Evaluate system performance results, perform risk assessments, and evaluate performance metrics.


    Responsibilities include:
    Provide ad–hoc penetration testing and assessment services on Department of State systems identified by the leadership. Develop, Identify and resolve security vulnerabilities related to deployment and testing processes. Streamline and optimize processes and procedures in order to rapidly remediate vulnerabilities from cybersecurity threats. Collaborate with Department and external cyber stakeholders on cybersecurity technology implementations to meet specific operational needs. Perform technical evaluations of recommended vulnerability mitigation actions and make recommendations based on impact and/or other countermeasures. Develop strategies for CIC cyber defense technologies, ensuring integration and alignment for continued operation.

    Conduct assessments of threats and vulnerabilities; determine deviations from acceptable configurations, enterprise, or local policy; assess the level of risk; and develop and/or recommend appropriate mitigation countermeasures in operational and non–operational situations.

    Network Mapping include but are not limited to a network map of the organization's system that includes a visual representation of the organization's physical devices and digital network.

    Perform operation and maintenance activities in support of existing CIC cyber tools and technologies (MSV, Qualys, Tenable Nessus and others).

    Identify, diagnose, and prioritize anomalies in cyber defense infrastructure and resources. Perform cybersecurity testing of developed applications and/or systems. Identify and direct the remediation of technical problems encountered during testing and implementation of new systems.

    Document security issues and impacts identified through offensive operations in a clear and concise manner to facilitate reporting to impacted stakeholders.

    Provide guidance and recommendations to stakeholders responsible for security remediation actions to close identified gaps and remediation validation testing. Independently handle complex issues with minimal supervision, while escalating only the most complex issues to appropriate staff.

    Qualifications Required Education & Experience Bachelor's and five (5) years or more experience; Master's and three (3) years or more experience.

    A degree in Cybersecurity or related field. 4–6+ years penetration testing experience. Web application penetration testing, LPT, Source code vulnerability analysis, serious problem–solving skills experience. All penetration testers/operators must be DHS/CISA AES qualified within 90 days of onboarding. Required Clearance US Citizenship.

    Active Top Secret Clearance Desired 4 years Microsoft Operating Systems (OS) engineering and support experience focusing on Active Directory (AD), System Center Configuration Manager (SCCM), System Center Operations Manager (SCOM).

    4–6 years Network penetration testing experience. In–depth experience in planning, implementing, and managing large/global enterprise infrastructures. Familiarity of various analytical tools (Splunk, USBDeview, Netwitness, MimiKatz). Understanding of Security Information and Event Management (SIEM) tools (Splunk, McAfee). Familiarity of Cobalt Strike, Nessus, Kali Linux, Burp Suite, Nmap and OpenVAS for databases. Knowledge of general attack stages. Skill in the use of social engineering techniques and using penetration testing tools. Familiarity with OMB, NIST, DHS, and related security guidelines and directives. Interpersonal skills including the ability to collaborate effectively, and excellent written and oral communications. Network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense–in–depth). Server/endpoint OS (Microsoft, Linux, IOS) along with mobile and cloud technologies. Cloud application security, Vulnerability Management and Security Information, and Event Management capabilities. Countermeasures / mitigations to identified cybersecurity risks. Knowledge of network protocols such as TCP/IP, Dynamic Host Configuration Protocol (DHCP), domain name system, and directory services.


    Certifications:
    LPT (Licensed Penetration Testers, Microsoft Certifications (MCSE, MCSA, MCSD),OSCP (Offensive Security Certification Professional), ISACA Certified Information Systems Auditor (CISA), SCP Security Certified Network Architect (SCNA), ISACA Certified Information Security Manager (CISM) SAIC accepts applications on an ongoing basis and there is no deadline


    Covid Policy:
    SAIC does not require COVID–19 vaccinations or boosters. Customer site vaccination requirements must be followed when work is performed at a customer site.
    Create a job alert and receive personalised job recommendations straight to your inbox.

    #J-18808-Ljbffr


  • Veterans Enterprise Technology Solutions San Francisco, United States Permanent

    Staffing Pros, a division of VETS Inc., is recruiting for a full-time Malware Analyst. This position supports multiple onsite locations. This role will be located in both Beltsville, MD AND Rosslyn, VA. The customer requirement requires every employee to be onsite for the first 9 ...


  • Consulting Services Group, LLC Laurel, United States

    Consulting Services Group (CSG) is a premier provider of support services, bringing a new and unique level of subject matter expertise to our clients, with a focus on intelligence, communication solutions, information technology, social media, and logistics. We are seeking a Spec ...


  • Advanced Software Design San Francisco, United States Permanent

    Seeking candidates to fill a Manufacturing Technician position for our Beltsville, MD facility. Position is for 1st shift. Candidate will provide technician support for the manufacturing of integrated products in our loop heat pipe area. Candidates will need to be mechanically sk ...


  • Veterans Enterprise Technology Solutions San Francisco, United States Permanent

    Staffing Pros, a division of VETS Inc., is recruiting for a full-time Systems Administrator with SolarWinds experience. This is a Hybrid position located in Beltsville, MD rotating every other week- 3 days onsite and 2 days remote/2 days onsite and 3 days remote. An Active Secret ...


  • Veterans Enterprise Technology Solutions Beltsville, United States

    Staffing Pros, a division of VETS Inc., is recruiting for a full-time Systems Administrator with SolarWinds experience. This is a Hybrid position located in Beltsville, MD rotating every other week- 3 days onsite and 2 days remote/2 days onsite and 3 days remote. Must work onsite ...


  • IntePros Federal Washington, United States

    The Opportunity: IntePros Federal is seeking a Security Specialist in support of our federal government customer. The IT Systems Security Specialist supports our customer to provide technical, analytical, and liaison support for implementing systems and network engineering functi ...


  • NAIS San Francisco, United States Permanent

    Contract/Location: National Capital Region / Pensacola, FL Overview: · NAIS LLC is seeking an experienced Security Engineer to provide services on a contract supporting a U.S. Government agency. The ideal candidate will have excellent problem-solving and communications skills as ...


  • Mission Services LLC (MSI) College Park, United States

    000 Serves as a technical expert and main point of contact for all IT related matters pertaining to the operations and maintenance of an IT infrastructure and support. The minimum qualifications are: 10 years' of experience in networking managing LANs, WANs, helpdesk, and infrast ...


  • DAED Industries LLC Laurel, United States

    Derive lower-level requirements from higher-level allocated requirements, ensure requirements are complete, and provide input to program and contract work breakdown structure (WBS); develop systems engineering documentation; Assess and manage risks in accordance with an approved ...


  • Super Systems Inc San Francisco, United States Permanent

    Full time, on-site System Administrator (SA) to manage multiple Information Systems (IS) in accordance with DoD/Risk Management Framework (RMF) policies. The position will require the SA to support existing ISs and to assist in the development and accreditation of new ISs. This p ...


  • BlueHalo Annapolis Junction, United States

    Overview · At BlueHalo our analysts provide actionable intelligence. We quickly convert customer requirements into real hardware, software, firmware, and mechanical solutions in weeks, not years. With an organizational structure and design processes tailored to quick reaction, ou ...


  • Anonymous Employer San Francisco, United States Permanent

    Senior ISSO · Washington, DC - Hybrid $140k + bonus My client is looking for a Senior ISSO to be on site in a hybrid role. This position requires someone with an active top secret clearance, to be considered for this role you need experience with the following: Required: TS Clear ...


  • The Tatitlek Corporation Arlington, United States

    Overview This Security Analyst works with the current Security team to support program activities and processes. The Personnel Security & Suitability Security Analyst should be familiar with all aspects of industrial, information, insider threat, communication, personnel, operati ...


  • Gridiron IT Solutions Arlington, United States

    GridironIT is seeking a Security Engineer local to the Arlington, VA area. · 100% onsite. · TS/SCI is required. The Challenge: · Everyone knows security needs to be "baked in" to a system architecture, but you actually know how to bake it in. You can identify and implement ways t ...


  • CACI Chantilly, United States

    Security Administrator Job Category: Security Time Type: Full time Minimum Clearance Required to Start: TS/SCI Employee Type: Regular Percentage of Travel Required: Up to 10% Type of Travel: Local * * * What You'll Get to Do: CACI is looking for a Contractor Special Security Offi ...


  • SAIC Springfield, United States

    You will need to login · before you can apply for a job. · Security Engineer with Security Clearance · Description SAIC is looking for a qualified Security Engineer to join an exciting program in Springfield, Virginia. Individual will be responsible for providing systems securi ...


  • CenCore LLC Reston, United States

    Job Description: PLEASE NOTE THIS IS A FULL TIME POSITION ONLY ON A 24/7 site. Must have an Active and Current Top-Secret Clearance with Full Scope Polygraph. Pay is based on experience with Benefits. RESPONSIBILITIES: Oversees the provision of armed and unarmed security Services ...


  • Peraton Washington, United States

    About Peraton Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deli ...


  • MELE Associates, Inc. Washington, United States

    MELE Associates maintains a contract with the National Nuclear Security Administration (NNSA) Office of Infrastructure (NA-90), which works to maintain, operate, and modernize NNSA infrastructure to enable program results. NNSA's infrastructure protects global security through un ...


  • Johns Hopkins Applied Physics Laboratory (APL) Laurel, MD, United States

    Are you a security professional who likes to solve complex security challenges? · Do you have a keen interest in providing top notch security support in a dynamic and rich R&D environment? · We are seeking a special security representative (SSR) to help us provide APL and its cu ...