Scientific Research Corporation

Senior Cyber Security Engineer / CSET

Scientific Research Corporation$100K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in computer science, cybersecurity, or related field with relevant experience.
  • 5+ years of adversarial emulation and penetration testing experience.
  • 10+ years leading diverse cyber teams across multiple domains.
  • Intermediate knowledge of Advanced Persistent Threat (APT) methodologies and the Mitre ATT&CK® framework.
  • Intermediate skills in exploit development and incident response tools.
  • Exceptional oral and technical writing communication skills.
  • Required IAT Level III or IAM Level III certifications with specific security credentials.

Responsibilities

  • Support offensive security/red team engagements from planning to reporting.
  • Execute adversarial emulation testing using real-world tactics across various networks.
  • Develop comprehensive security testing strategies for effective control assurance.
  • Create innovative tools and processes to enhance security team's efficiency.
  • Facilitate stakeholder collaborations for risk mitigation.
  • Analyze applications for vulnerabilities using advanced exploitation techniques.
  • Document exploit activities and recommend remediation strategies.

Benefits

  • Opportunity to contribute to impactful national security initiatives.
  • Access to cutting-edge tools and technology for security testing.
  • Collaboration with an elite team of cybersecurity professionals.
  • Professional development opportunities and ongoing training in advanced cyber techniques.
  • Work in a fast-paced, dynamic environment with diverse challenges.
Full Job Description
Description
  • Supporting offensive security/red team/adversarial emulation testing
  • Executing Red Team engagements in a variety of networks using real-world adversarial Tactics, Techniques, and Procedures (TTPs) from conception to report delivery
  • Developing comprehensive security testing strategies and programs across NCRC-U to provide assurance that security controls are designed and operating effectively
  • Developing innovative accelerators, tools, mechanisms, and processes to enhance the security team's velocity and scale to customer needs
  • Facilitating multiple stakeholders to agree on appropriate solutions and verifying that risks are mitigated appropriately
  • Demonstrating creativity, insight, intellectual flexibility, and sound business judgment throughout the process
  • Working independently but collaborate with cross-functional to provide security engineering consulting and control design recommendations to reduce risk
  • Conducting open-source intelligence gathering, network vulnerability scanning, exploitation of vulnerable services, lateral movement, install persistence in a target network(s), and manage C2 infrastructure
  • Systematically analyzing each component of an application with the intent of locating programming flaws that could be leveraged to compromise the software through source code review or reverse engineering
  • Developing payloads, scripts and tools that weaponize new proof-of-concepts for exploitation, evasion, and lateral movement
  • Safely utilize attacker tools, tactics, and procedures when in sensitive environments/devices
  • Evading EDR devices such as Windows Defender and Carbon Black to avoid detection by Defenders/behavioral based alerting in order to further the engagement objectives
  • Demonstrating expertise in one of the following: Active Directory, Software Development, Incident Response, or Cloud Infrastructure
  • Carefully document and log all exploitation activities
  • Continually exercise situational awareness in order quickly identify any instances of cohabitation
  • Documenting identified vulnerabilities and researching corrective/remediation actions in order to recommend a risk mitigation technique(s)
  • Demonstrating new vulnerabilities and assist Network Defenders (Blue Team) with the refinement of detection capabilities
  • Maintaining knowledge of applicable Red Team policies, Standing Ground Rules, regulations, and compliance documents
  • Communicating effectively with team members and during an engagement
  • Ability to think unconventionally in order to develop adversarial TTPs
  • Keeping current with TTPs and the latest offensive security techniques

[#LI-DH1]

Requirements
  • Bachelor’s degree with a focus in computer science, computer information systems, engineering, mathematics, management information systems, cybersecurity, cyber operations, or a related discipline with corresponding experience and demonstrated mastery of relevant computer science topics
  • 5+ years of cyber adversarial emulation experience, to include penetration testing of modern Windows and Linux operating systems, IP-based networks and protocols, 802.11 networks, and/or web applications, hardware hacking, software defined networks/RF
  • 10+ years of experience in leading complex and technically diverse teams of cyber professionals (software developers, system administrators, penetration testers, incident responders, etc.)
  • Intermediate knowledge of known Advanced Persistent Threat (APT) actor Techniques, Tactics, and Procedures (TTPs), to include familiarity with terminology from Mitre ATT&CK® used to describe TTPs used in cyber attacks
  • Intermediate knowledge of techniques and tools used for exploit development of common operating systems, software debugging, and application fuzzing
  • Intermediate knowledge of tools and techniques used for incident response, reverse engineering, and digital forensics
  • Superior oral communication skills, including the ability to project confidence and enthusiasm, in the following core areas: formal presentations; soliciting goals and requirements from range users; explaining adversarial emulation in the context of testing and training events; effectively communicating event and environment requirements to CSET members; explaining cost estimates based on estimated levels of CSET effort; managing expectations as relevant to CSET TTPs; and explaining technical nuances and significant attributes of advanced cyber attacks to non-cyber-savvy audiences
  • Superior technical writing skills, including the ability to author, review, and provide input and feedback to documents drafted by CSET personnel, as well as the ability to create persuasive and impactful technical briefing materials as relevant to range training and test events
  • Ability to work independently and to collaborate with range and event leadership, CSET team members, users, and other event stakeholders
  • Required/Maintain IAT Level III or IAM Level III 8570 certifications include one or more of the following:
    • CASP+ CE
    • CCNP Security
    • CISA
    • GIAC® Incident Handler (GCIH)
    • GIAC® Certified Enterprise Defender (GCED)
    • CISM
    • GSLC
    • CCISO
    • Certified Information Systems Security Professional (CISSP)
  • In addition to meeting the applicable cyber security workforce (CSWF) requirements for Computer Network Defenders (CND) Auditors (DoD 8570) or Vulnerability Assessment Analysts (SECNAV 5239.2), CSET members must obtain one or more of the following vendor certifications within 6 months of being hired:
    • Offensive Security Certified Engineer (OSCE)
    • Offensive Security Certified Professional (OSCP)
    • GIAC Certified Exploit Researcher and Advanced Penetration Testers (GXPN)
    • Offensive Security Certified Engineer (OSCE3)
Desired Skills
  • Master’s degree with a focus in computer science or cybersecurity
  • 10+ years of experience supporting the execution of Department of Defense (DoD) offensive cyber operations (OCO) or defensive cyber operations (DCO) as a civilian, contractor, or uniformed personnel
  • Experience with operational training programs and qualification standards
  • Red Team, Computer Operator or Exploitation Analyst experience with Threat Systems Management Office (TSMO), US Air Force, US Navy or National Security Agency (NSA) / Cyber Mission Force teams
  • Experience with OT, IoT, XIoT is a plus
Clearance Information

SRC IS A CONTRACTOR FOR THE U.S. GOVERNMENT, THIS POSITION WILL REQUIRE U.S. CITIZENSHIP AS WELL AS, A U.S. GOVERNMENT SECURITY CLEARANCE AT THE TOP SECRET / SCI LEVEL

Travel Requirements

n/a

About Scientific Research Corporation

Scientific Research Corporation provides innovative solutions to the U.S. Government, private industry, and international markets. Scientific Research Corporation was founded in 1988 and was headquartered in Atlanta, Georgia.

Scientific Research Corporation Careers

Joining Scientific Research Corporation means becoming part of a world-class team of professionals who are committed to pioneering scientific and technological innovations. This esteemed company offers a plethora of job opportunities that pave the way for personal and professional growth in numerous cutting-edge fields.

Explore Career Opportunities

Scientific Research Corporation is actively hiring and continually seeks talented individuals who are eager to drive innovation and lead in their respective fields. With a variety of positions available, candidates can find the perfect match for their skills and career ambitions.

Internship Programs

For those starting their career journey, Scientific Research Corporation provides robust internship programs designed to offer hands-on experience in a dynamic environment. Internships are a cornerstone of the company's commitment to nurturing new talent and fostering leadership skills among the future leaders of the industry.

Professional Growth and Development

At Scientific Research Corporation, the growth of its team members is a priority. The company supports career advancement through comprehensive professional development and diversity training programs. These initiatives ensure that every employee has the opportunity to excel and innovate within their roles.

Culture and Benefits

The culture at Scientific Research Corporation is built on a foundation of diversity and inclusion, where every team member’s contribution is valued. Employees enjoy a range of benefits designed to support their professional and personal lives, including competitive health benefits, retirement plans, and flexible working conditions.

Networking and Leadership

Employees at Scientific Research Corporation are encouraged to engage in networking opportunities within and beyond the company. This fosters a culture of collaboration and continuous learning. Leadership within the company is not just about guiding others but also about driving forward the mission of innovation and excellence.

Applying for a Position

To apply for a position at Scientific Research Corporation, candidates should prepare their resume to highlight relevant experience and skills. The interview process is designed to assess not only professional qualifications but also a candidate's alignment with the company’s values and culture.

Stay Connected with Scientific Research Corporation Careers

Prospective candidates are encouraged to stay informed about new job opportunities and company news by subscribing to job alert emails. This ensures that they do not miss out on exciting and rewarding employment opportunities at Scientific Research Corporation.

Join the Team

Search open positions that match your skills and interests. Scientific Research Corporation looks for passionate, curious, creative, and solution-driven team players.

SEARCH SCIENTIFIC RESEARCH CORPORATION JOBS

Keep Up to Date

Stay ahead with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the people who are part of Scientific Research Corporation.

READ CAREERS BLOG

Job Alert Emails

Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Discover what exciting and rewarding opportunities await at Scientific Research Corporation.
Learn more about Scientific Research Corporation

Similar Jobs

More Jobs at Scientific Research Corporation

More Information Technology Jobs

Find similar Senior Cyber Security Engineer / CSET jobs: