VariQ has an exciting opportunity for a highly qualified Cyber Security SME to support our client in Northern VA.
* Salary: Highly Competitive
* Security Clearance: TS/SCI
* Available: ASAP
The candidate will serve as a contract penetration testing engineer (Cyber Security). This position will support activities of the group to target, assess, exploit, and report risks and vulnerabilities of organization systems in order to provide senior decision makers with actionable data to make strategic investment decisions.
Roles and responsibilities include but are not limited to:
* provide documentation to Sponsor which describes all identified system risks, planned test procedures taken, and test results
* provide enhancement capabilities and SOPs to assessment operations for execution and implementation
* maintain accountability to endure integrity and confidentiality of the process
* provide analysis of vulnerabilities
* Review and make recommendations on program-level documentation (e.g., requirements specification, system architecture, design documents, test plans, security plans, etc.)
* Develop and document security evaluation test plan and procedures
* Assist in researching, evaluating, and developing relevant Information Security policies and guidance
* Actively participate in or lead technical exchange meetings and application review boards, documenting actions items/results of these events
* Brief management, as needed, on the status of action items and/or results of activities
* Conduct hands-on security testing, analyze test results, document risk, and recommend countermeasures
* Coordinate with other program elements conducting security testing
* Assess/calculate risk based on threats, vulnerabilities, and shortfalls uncovered in testing
* Identify mitigating countermeasures to identified threats, vulnerabilities, and shortfalls
1. Demonstrated work experience in cyber security or IT related field.
2. Demonstrated experience with penetration testing from a cyber-attacker perspective with computer attack methods and system exploitation techniques.
3. Demonstrated working knowledge of cyber security principles for Linux, Windows and virtual platforms.
4. Demonstrated experience with, and knowledge of, IT security architecture and engineering.
5. Demonstrated experience performing network security analysis.
6. Demonstrated experience with network architectures and network management tools.
7. Demonstrated experience creating systems and applications security test plans and performing hands-on security testing leveraging adversarial tactics.
8. Demonstrated experience with risk management methodologies.
9. Demonstrated experience analyzing test results and suggesting mitigation plans for security problems.
10. Demonstrated experience with system configuration, development, and design specifically around enterprise systems and hypervisors.
11. Demonstrated experience with complex Windows installations.
1. Demonstrated experience with public and private information security groups and organizations.
2. Demonstrated experience communicating vulnerability results and risk posture to senior executives.
3. Demonstrated experience with information security policies and guidance, as well as assisting in researching, evaluating, and developing relevant security policies and guidance.
4. Demonstrated experience performing complex technical tasks in pursuit of overall goals with minimal direction.
5. A Bachelor's degree in Computer Science, Information Systems, Engineering, Business, or other related scientific or technical discipline.
6. Certifications: Certified Ethical Hacker (CEH).
7. Offensive Security Certified Professional (OSCP).
8. Global Information Assurance Certification Penetration Tester (GPEN).
VariQ is an equal opportunity employer.
Category: Cyber Security