Cyber Security Engineer ( R-00065025 )
Leidos is seeking a Cyber Security SME/Penetration Tester to perform and support activities of the group to target, assess, exploit, and report risks and vulnerabilities of organization systems in order to provide senior decision makers with actionable data to make strategic investment decisions. This position requires an active TS/SCI with Polygraph and is located in the Herndon, VA area.
The Cyber Security SME will provide documentation which describes all identified system risks, planned test procedures taken, and test results. The Cyber Security SME will perform analysis of vulnerabilities identified during the testing. They will review and make recommendations on program-level documentation (e.g., requirements specification, system architecture, design documents, test plans, security plans, etc.). They will create and document penetration testing security test plans and procedures. The Cyber Security SME will conduct hands-on security testing based on the approved test plan and analyze test results, document risk, and recommend countermeasures. They will assist in researching, evaluating, and developing relevant Information Security policies and guidance to improve security. They will actively participate in or lead technical exchange meetings and application review boards, documenting actions items/results of these events. The Cyber Security SME will brief management, as needed, on the status of action items and/or results of activities.
Requires BS degree and 12 – 15 years of prior relevant experience.
Demonstrated work experience in cyber security or IT related field.
Demonstrated experience with penetration testing from a cyber-attacker perspective with computer attack methods and system exploitation techniques.
Demonstrated working knowledge of cyber security principles for Linux, Windows and virtual platforms.
Demonstrated experience with, and knowledge of, IT security architecture and engineering.
Demonstrated experience performing network security analysis.
Demonstrated experience with network architectures and network management tools.
Demonstrated experience creating systems and applications security test plans and performing hands-on security testing leveraging adversarial tactics.
Demonstrated experience with risk management methodologies.
Demonstrated experience analyzing test results and suggesting mitigation plans for security problems.
Demonstrated experience with system configuration, development, and design specifically around enterprise systems and hypervisors.
Demonstrated experience with complex Windows installations.
Demonstrated experience with public and private information security groups and organizations.
Demonstrated experience communicating vulnerability results and risk posture to senior executives.
Demonstrated experience with information security policies and guidance, as well as assisting in researching, evaluating, and developing relevant security policies and guidance.
Demonstrated experience performing complex technical tasks in pursuit of overall goals with minimal direction.
Desired Certifications (Non-Mandatory):
Certified Ethical Hacker (CEH)
Offensive Security Certified Professional (OSCP)
Global Information Assurance Certification Penetration Tester (GPEN)