Find Jobs
Find Jobs Near You – Available Work in Your Location
Cybersecurity Analyst - Contingent
Choose a Location
This role is available in multiple locations. Pick one to apply.
Career Insights for Vulnerability Analyst / Penetration Tester
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on California data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Vulnerability Analyst or Penetration Tester probes for and exploits security vulnerabilities in web-based applications, networks and systems. Penetration Tests are designed to achieve a specific, attacker-simulated goal and should be requested by customers who are already at their desired security posture. A typical goal could be to access the contents of the prized customer database on the internal network, or to modify a record in an HR system. Vulnerability Assessments are designed to yield a prioritized list of vulnerabilities and are generally for clients who already understand they are not where they want to be in terms of security. The customer already knows they have issues and simply need help identifying and prioritizing them.
$125,034 / year median in California
+2% projected growth
Job Description
Responsibilities:
Technical Assessment & SME Support Serve as technical subject matter experts (SMEs) supporting the cybersecurity evaluation of product submissions Provide technical expertise and advisory support to the Government Blue List Program regarding cybersecurity requirements, technical standards, risk management, and assessment methodologies applicable to Blue List technologies Possess demonstrated knowledge of cybersecurity principles applicable to embedded systems, software, firmware, wireless communications, networking, encryption, authentication, supply chain security, and other technologies relevant to the Blue List Program Possess experience interpreting cybersecurity assessment methodologies, penetration testing results, vulnerability assessments, software assurance evaluations, and firmware analyses sufficient to evaluate cybersecurity risks associated with Blue List candidate technologies Assessment Review & Validation Review cybersecurity assessment reports, supporting technical documentation, and assessment evidence to evaluate the completeness, technical sufficiency, and adequacy of assessments in support of Government technical acceptance decisions Provide technical recommendations regarding cybersecurity findings, risk mitigation strategies, assessment requirements, technical acceptance, and the applicability of cybersecurity requirements to Blue List candidate technologies Verify and validate whether a company's submitted remediation plan would sufficiently mitigate any cyber vulnerabilities identified in provided assessments Risk Identification & Advisory Identify cybersecurity vulnerabilities, threats, attack vectors, and residual risks that may adversely affect DoW missions, warfighter safety, national security, operational resilience, or the confidentiality, integrity, and availability of Government information and systems Maintain awareness of applicable Federal statutes, DoW policies, NDAA requirements, cybersecurity frameworks, industry best practices, and Government processes relevant to the Blue List Program Provide technical consultation and advisory support to Government personnel and stakeholders regarding cybersecurity matters affecting Blue List technologies, assessments, policy implementation, and program execution Monitor emerging cybersecurity threats, vulnerabilities, technologies, and policy developments affecting small unmanned systems and provide recommendations to support the continued evolution of theBlue List Program Required Qualifications:
Bachelor's degree required in Cybersecurity, Computer Science, Computer Engineering, or a related technical discipline Active certification required : DoW 8570/8140 IAM or IAT Level II or III (e.g., CISSP, CISM, or CompTIA Security+) Must be a U.S. citizen with a favorably adjudicated Tier 3 (ADP/IT-II) investigation on file in DISS at the time of offerDesired Qualifications:
Minimum of five (5) years of practical experience Benefits Full-time employees are eligible for 401(k) and Roth retirement plans, Medical, Dental, and Vision Insurance (for employees and families), Supplemental Insurance, 11 Federal Holidays, and at least three weeks of Paid Time Off (PTO), including sick and personal leave. CRG is an equal opportunity employer. We make employment decisions based on merit, qualifications, and business need. All qualified applicants receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, status as a protected veteran, or any other state or federally protected category.Benefits
- Paid Time Off (PTO)
- 401(k) Plans
- Other Retirement and Savings
- Health Insurance