State of Montana

Senior Threat Validation Specialist

State of Montana$88K — $105K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Associates degree in Information Security or Technology; AND 6 years' experience in a security-related role.
  • Preferred: Bachelor's degree in Information Security or Technology; AND 4 years' experience; AND advanced certifications like OSCP, CISSP.
  • Experience in penetration testing specifically for web applications, cloud, and database security.
  • Familiarity with AI-assisted security tools and techniques including prompt engineering and validation of AI outputs.
  • Knowledge of cyber threats, vulnerabilities, and methodologies for intrusion detection.

Responsibilities

  • Conduct vulnerability assessments and provide expert consultation on security measures.
  • Lead offensive security tactics through red teaming and penetration testing activities.
  • Facilitate attack/defense exercises to clarify operational effectiveness.
  • Analyze malware and deliver subject matter insights to partner agencies.
  • Implement AI and LLM tools to enhance data analysis and reporting processes.

Benefits

  • Health Coverage
  • Paid Vacation and Sick Leave and Holidays
  • Retirement plans
  • Public Service Loan Forgiveness (PSLF) eligibility for student loan forgiveness
  • Work/life Balance
Full Job Description
What is this career opportunity?

Do you want to help Montana protect and defend our citizen's data from cyber threats? Are you naturally curious? Are you a critical thinker? Do you have a strong interest in finding threats? If you answered yes to all these questions, then this might be the perfect job for you! Whether you are transitioning from a technical career, already a cybersecurity veteran, or wanting to start down the exciting path of cybersecurity, you might be able to join our team as a Senior Threat Validation Specialist. This position is primarily responsible for vulnerability assessments, vulnerability consultation, red teaming and penetration testing.

If you are experienced in penetration testing of web application, cloud, and/or database security, consider joining our team as an Senior Threat Validation Specialist and lead the team in offensive security tactics, teach efficient techniques for responding to threat actors, facilitate attack/defense exercises within the Bureau, and recommend controls to reach desired security posture. You will also be able to analyze malware, provide subject matter expertise to agencies and substantially impact enterprise security.

You will also use artificial intelligence (AI) and large language model (LLM) tools to work faster and dig deeper across engagements-accelerating reconnaissance, code and log analysis, tooling and script development, and reporting-while rigorously validating AI-generated output and safeguarding sensitive state data.

What are we looking for?

Education and Experience:

Alternate combinations of education, experience, and certifications will be considered on a case-by-case basis.

Required for the first day of work, including alternatives:
• Associates degree in Information Security or Technology; AND
• 6 years' experience in a security-related role

Preferred:
• Bachelors degree in Information Security or Technology; AND
• 4 years' experience in a security-related role; AND
• OSCP, Pentest+, KLCP, GCFE, GCFA, E|CIH, or CISSP
• CPENT AI, Offsec OSAI, CompTIA SecAI+, or comparable AI-integrated offensive security training

Competencies:

Knowledge of:
  • Cyber threats and vulnerabilities.
  • Network traffic analysis methods.
  • Database, Cloud, and/or Web Application Security
  • Vulnerability assessment
  • Cyber-attack stages (e.g., reconnaissance, scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks).
  • Website types, administration, functions, and content management system (CMS).
  • Attack methods and techniques (DDoS, brute force, spoofing, etc.).
  • Host-based security products and how those products affect exploitation and reduce vulnerability.
  • Internal tactics to anticipate and/or emulate threat capabilities and actions.
  • Network protocols such as TCP/IP, Dynamic Host Configuration, Domain Name System (DNS), and directory services.
  • Intrusion detection methodologies and techniques for detecting host and network-based intrusions.
  • Web Application Security Risks (e.g., Open Web Application Security Project Top 10 list)
  • Generative AI and large language model (LLM) fundamentals and architecture, including models and model selection, tokens and context windows, prompting, retrieval-augmented generation (RAG), agentic (tool-using) AI, the Model Context Protocol (MCP), and the trade-offs between cloud-hosted and locally hosted models.
  • How AI and LLM-assisted capabilities apply across the penetration testing lifecycle, including reconnaissance and open-source intelligence (OSINT) synthesis, code and configuration review, script and exploit development, log and data analysis, and reporting, as well as AI-augmented and semi-autonomous testing platforms.
  • Limitations and risks of generative AI in security work, including hallucination and the need to independently verify output, data-handling and confidentiality constraints, tool licensing, and applicable law and policy.
  • How threat actors use AI to accelerate their own operations, such as generating phishing and social-engineering content, developing or obfuscating malware, and automating reconnaissance.

Skill in:
  • Conducting research using our threat intelligence tools.
  • Social engineering techniques
  • Defining and characterizing all pertinent aspects of the operational environment.
  • Evaluating information for reliability, validity, and relevance.
  • Identifying cyber threats which may jeopardize organization and/or partner interests.
  • Using security event correlation tools.
  • Detecting host and network-based intrusions via intrusion detection technologies.
  • Conducting trend analysis.
  • Reading, interpreting, developing, and deploying signatures.
  • Prompt engineering and integrating AI and LLM tools into offensive security workflows to improve speed, coverage, and quality.
  • Critically evaluating and validating AI-generated code, findings, and recommendations before acting on them or including them in deliverables.
  • Using AI tools without exposing sensitive, confidential, or regulated state data to unauthorized or third-party services.

Ability to:
  • Communicate complex information, concepts, or ideas in a confident and well-organized manner through verbal, written, and/or visual means.
  • Accurately and completely source all data used in intelligence, assessment and/or planning products.
  • Evaluate, analyze, and synthesize large quantities of data (which may be fragmented and contradictory) into high quality, fused targeting/intelligence products.
  • Function in a collaborative environment, seeking continuous consultation with other analysts and experts-both internal and external to the organization-to leverage analytical and technical expertise.
  • Think critically.
  • Think like threat actors.
  • Develop or recommend analytic approaches or solutions to problems and situations for which information is incomplete or for which no precedent exists.
  • Apply techniques for detecting host and network-based intrusions using intrusion detection technologies.
  • Conduct forensic analyses in and for both Windows and Unix/Linux environments.
  • Interpret the information collected by network tools
  • Apply AI and LLM-assisted techniques to accelerate offensive security work while maintaining accuracy, scope discipline, and data protection.
  • Evaluate, pilot, and responsibly adopt emerging AI-assisted offensive security tools, and advise the team on appropriate and authorized use.
  • Explain AI and LLM capabilities, limitations, and risks to both technical and non-technical audiences.


Does this sound like you?

Please tell us how and why by submitting your resume and cover letter. In your cover letter, provide an example of how you've directly contributed to the security of an environment you were responsible for in a technical or advisory capacity. (Please Note: You do not need to complete the "work experience" or the "education & certifications" portion of the application process in our recruiting system. You only need to upload the requested documentation.)

What can you expect from us in return for your hard work?
• Look here to see the additional benefits! They include:

o Work/life Balance

o Health Coverage

o Retirement plans

o Paid Vacation and Sick Leave and Holidays

o And more...
Public Service Loan Forgiveness (PSLF) - Employment with the State of Montana may qualify you to receive student loan forgiveness under the PSLF. Look here to learn more and see if you may qualify!

Other important information to be aware of.
• This position requires the successful completion of a criminal background check.
• Only online applications are accepted. By applying online, you are able to receive updates and monitor the status of your application.

About State of Montana

State of Montana Careers

Joining the State of Montana offers a unique opportunity to balance life and work in an environment that supports growth, innovation, and diversity. The State of Montana is recognized for its commitment to service, which is reflected in its dynamic team culture and dedication to the community it serves.

Explore Job Opportunities

State of Montana provides a plethora of job opportunities that cater to a variety of skills and professional interests. Whether one is looking to start a career in public service or seeking to leverage their experience in a new role, State of Montana offers positions that foster professional and personal development.

Internship Programs

For those beginning their career journey, State of Montana offers internship programs that provide invaluable workplace experience and networking opportunities. Interns at State of Montana gain hands-on experience, working alongside seasoned professionals and contributing to meaningful projects.

Professional Growth and Leadership

Career advancement is a cornerstone of employment at State of State of Montana. With a strong emphasis on professional growth, the company offers extensive training and leadership programs designed to enhance skills and foster innovation. Employees are encouraged to take on new challenges and lead projects that stretch their capabilities.

Diversity and Inclusion

State of Montana is committed to creating a diverse and inclusive workplace. The company believes that diversity training and an inclusive culture are key to innovation and the success of their team. Employees from all backgrounds are valued for their unique perspectives and contributions.

Benefits and Culture

The benefits at State of Montana go beyond the standard employment package. Employees enjoy comprehensive health benefits, retirement plans, and flexible working conditions that underscore the company’s commitment to employee well-being. The culture at State of Montana is built on mutual respect, collaboration, and a shared commitment to excellence.

Hiring Process

The hiring process at State of Montana is designed to be transparent and inclusive, ensuring that all candidates are given the opportunity to succeed. Prospective employees can expect a thorough interview process where they can showcase their skills and learn more about the team they will be joining. Interested candidates should tailor their resume to highlight relevant experience and prepare to engage in a dialogue about how they can contribute to the State of Montana.

Networking and Career Development

State of Montana actively supports networking and career development for its employees through various programs and initiatives. Employees are encouraged to engage in cross-departmental collaborations and participate in professional networks that enhance their career trajectories.

Stay Connected with State of Montana Jobs

For those interested in joining the team, keep up to date with the latest job alerts and insider tips tailored to your career preferences. Discover the rewarding opportunities that await at State of Montana and be part of a team that is dedicated to making a difference.

Explore State of Montana Careers

Search open positions that match your skills and interests. State of Montana looks for passionate, curious, creative, and solution-driven team players.

SEARCH STATE OF MONTANA JOBS

Read Careers Blog

Stay ahead with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the people who work at State of Montana.

JOB ALERT EMAILS

Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. See what exciting and rewarding opportunities await at State of Montana.
Learn more about State of Montana
Size
5,001 employees
Industry

Similar Jobs

More Jobs at State of Montana

More Information Technology Jobs

Find similar Senior Threat Validation Specialist jobs: