BT-171 - Cyber Security Project EngineerLocation: Herndon (fully on-site, no remote option)
**MUST HAVE A POLY CLEARANCE TO APPLY. Those who do not have a Poly clearance will not be considered.**IntroductionBespoke Technologies is seeking support specializing in penetration testing and ethical hacking, to target, assess, and exploit risk and vulnerabilities of information systems. The intent is to provide senior decision makers with documented and actionable data to aid in making strategic investment decisions.
Work Requirements- The Candidate shall document all identified system risks, planned test procedures, and results.
- The Candidate shall perform analyses of vulnerabilities identified during testing.
- The Candidate shall review program-level documentation such as requirements specification, system architecture, design documents, test plans, and security plans.
- The Candidate shall create and document penetration testing plans and procedures.
- The Candidate shall conduct hands-on penetration testing by leveraging approved testing plans and procedures.
- The Candidate shall analyze penetration test results, document risks, and recommend countermeasures to uncovered risks.
- The Candidate shall participate or lead technical exchange meetings and application review boards.
- The Candidate shall document action items and results from technical exchange meetings and application review boards.
- The Candidate shall brief management on the status of action items and results of activities.
Required Skills and Demonstrated Experience- Demonstrated work experience in cyber security or related IT field.
- Demonstrated experience with cyber penetration testing.
- Demonstrated experience leveraging adversarial tactics to conduct hands-on security testing.
- Demonstrated experience applying computer attack methods and system exploitation techniques.
- Demonstrated working knowledge of cyber security principles for Linux, Windows, and virtual platforms.
- Demonstrated experience designing, testing, or implementing IT security architecture.
- Demonstrated experience performing network security analysis.
- Demonstrated experience analyzing network architectures.
- Demonstrated experience using network management tools
- Demonstrated experience developing risk management methodologies.
- Demonstrated experience analyzing test results to develop risk and threat mitigation plans.
- Demonstrated experience testing or reviewing system configuration, development, and design specifically around enterprise systems and hypervisors.
- Demonstrated experience designing, testing, or implementing complex Windows installations.
Highly Desired Skills and Demonstrated Experience- Demonstrated experience participating in public and private information security groups and organizations.
- Demonstrated experience communicating vulnerability results and risk posture to senior executives.
- Demonstrated experience performing complex technical tasks with minimal direction.
- A Bachelor's degree in Computer Science, Information Systems, Engineering, or other related scientific or technical discipline.
- Two or more of the relevant certifications:
- Offensive Security Certified Professional (OSCP)
- Global Information Assurance Certification Penetration Tester (GPEN)
- eLearn Security Certified Professional Penetration Tester (eCPPTv2)
- Global Information Assurance Certification Web Application Penetration Tester (GWAPT)