KBR, Inc

Cybersecurity Practitioner

KBR, Inc$95K — $115K *
Aerospace & Defense
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3+ years in software engineering, development, or cybersecurity
  • Understanding of programming standards and secure coding principles
  • Knowledge of risk management methodologies
  • Ability to obtain Secret/Top-Secret security clearance
  • Relevant cybersecurity certification within 6 months (e.g., CySA+, Security+, CISSP)
  • Bachelor’s degree in a related field preferred
  • Experience with industrial control systems or military applications preferred

Responsibilities

  • Evaluate and verify third-party software deliverables
  • Assess technical compliance reports and recommend risk mitigations
  • Conduct SAST on source code and binary analysis
  • Identify software weaknesses from scan reports
  • Reverse engineer software to find flaws and defects
  • Develop utilities for system information gathering and log consolidation
  • Support security engineering for acquisition programs

Benefits

  • Opportunity to work with the NIST Risk Management Framework
  • Potential for diverse project involvement including IT and OT systems
  • Access to advanced security testing tools and methodologies
  • Engagement in continuous professional development through certifications
  • Dynamic team environment focused on mission success
Full Job Description

Title:

Cybersecurity Practitioner

KBR is seeking a Cybersecurity practitioner with experience in software development, software assurance, and risk management to evaluate and verify third-party software deliverables, assess technical compliance reports, and provide risk-mitigation recommendations for Information Technology (IT) and Operational Technology (OT) systems. The successful candidate will join a team that evaluates cybersecurity policies and implements the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) to assess, authorize, and monitor system risks and ultimately ensure mission success for the customer. The successful candidate will conduct Static Application Security Testing (SAST) on source code and static binary analysis on compiled executables, assess scan reports to identify software weaknesses and prioritize mitigation plans, and maintain various security testing tools. The successful candidate will reverse engineer commercial and custom software to identify software flaws, logic defects, or undocumented embedded objects. The successful candidate will leverage expertise in Development, Security, and Operations (DEVSECOPS) and secure coding practices to provide technical support that effectively directs system security engineering for acquisition and sustainment programs. The successful candidate will develop and maintain custom software utilities to gather computer system information, consolidate logs and Security Content Automation Protocol (SCAP) results, generate visual metrics, and produce Continuous Monitoring (CONMON) artifacts.

REQUIREMENTS

The position requires at least three (3) years of experience in software engineering, software development or a cybersecurity-related field. Candidates must demonstrate an understanding of legacy and modern programming standards, secure coding principles, and risk management methodologies. Within six (6) months of the assignment, the candidate must possess or obtain one of the following certifications: CySA+, CGRC (formerly CAP), Security+, CISSP, SSCP, or CSSLP. The candidate must be familiar with secure coding and cybersecurity practices. Additionally, the candidate must be able to obtain and maintain a Secret or Top-Secret security clearance.

PREFERRED: A bachelor’s degree in Computer Science, Computer Engineering, Software Engineering, or Cybersecurity, and at least five (5) years of experience in related engineering or cybersecurity positions. Desired qualifications include hands-on experience with ICS/SCADA systems, vulnerability hunting, threat analysis, software reverse engineering, Ghidra, Binwalk, hardware debugging interfaces (e.g., JTAG, UART, I2C). Possession of one of the following certifications: CDP, CDE, CEH, CASE, GREM, or GICSP. Direct experience supporting USAF, military service, or military weapon systems is highly preferred. Must possess an active Secret or Top-Secret security clearance.

About KBR, Inc

KBR, Inc is an American engineering, procurement, and construction company headquartered in Houston, Texas. The company provides services to customers in the energy, chemical, and government sectors, among others. KBR has a global presence, with operations in over 40 countries. The company was founded in 1901 as M.W. Kellogg Company and has undergone several name changes and mergers since then. KBR is committed to delivering innovative and sustainable solutions to its customers while also being a responsible corporate citizen.
Learn more about KBR, Inc
Size
28,000 employees
Market Cap
$7.1 billion
Industry
Net Income
-$72 million
Founded
1919
5 Year Trend
+11.5%
Revenue
$5.7 billion
NASDAQ

Similar Jobs

More Jobs at KBR, Inc

More Aerospace & Defense Jobs

Find similar Cybersecurity Practitioner jobs: