A Vulnerability Analyst or Penetration Tester probes for and exploits security vulnerabilities in web-based applications, networks and systems. Penetration Tests are designed to achieve a specific, attacker-simulated goal and should be requested by customers who are already at their desired security posture. A typical goal could be to access the contents of the prized customer database on the internal network, or to modify a record in an HR system. Vulnerability Assessments are designed to yield a prioritized list of vulnerabilities and are generally for clients who already understand they are not where they want to be in terms of security. The customer already knows they have issues and simply need help identifying and prioritizing them.
Job Requirements Palm Bay, FL Top Secret/SCI Polygraph not specified Mid Level Career (5+ yrs experience) $100,000 - $160,000
Job Description Essential Functions:
Prepare and manage Assessment and Authorization documentation using RMF and derivative processes (e.g., DOD 8510, JSIG, ICD-503, CNSSI 1253) to achieve security authorization of supported systems. Support the design, integration, and maintenance of secure system architectures for on-premises environments. Apply cybersecurity principles and security-by-design practices throughout the system development lifecycle. Analyze system requirements and derive security requirements, controls, and technical solutions. Perform security assessments, gap analyses, and risk evaluations for information systems and supporting infrastructure. Perform research required to identify vulnerability details and solutions to assist other cyber disciplines with their correction or mitigation. Support implementation and validation of security controls in alignment with applicable regulatory, contractual, and organizational requirements. Participate in Linux & Windows system hardening, secure configuration, patch management, and vulnerability remediation activities. Contribute to development of policies, standards, procedures, and technical documentation related to information security engineering. Support audits, inspections, and customer assessments by providing technical evidence and responses. Communicate technical risks, findings, and recommendations to both technical and non-technical stakeholders.
Qualifications:
Bachelor's Degree and minimum 4 years of prior relevant experience. Graduate Degree and a minimum of 2 years of prior related experience. In lieu of a degree, minimum of 8 years of prior related experience.
Must possess an active clearance:
TS/SCI Must have or be able to obtain and maintain IAT Level II minimum (Security+ CE, CCNA Security, or equivalent) within 3-months of start. Work is 100% on-site and cannot be accomplished remotely.
Preferred Additional Skills:
Familiarity with emerging technologies such as cloud computing, containerization, and microservices, and their security implications (e.g. Understanding of security control inheritance in cloud-based systems.) Familiarity with
STIG/SRG
compliance validation and automated compliance scanning tools. Experience with security tools such as IDS/IPS, vulnerability scanners, and endpoint protection solutions. Professional certifications such as Security+, CISSP, or similar. Familiarity with DevSecOps practices, CI/CD pipeline security, and infrastructure as code security principles. Experience in regulated environments such as defense, aerospace, government contracting, or critical infrastructure.