Cyber Security Evaluation Team (CSET) Member
About the role
The National Cyber Range Complex (NCRC) is seeking a Cyber Security Evaluation Team (CSET) Member to support the Department of Defense (DoD) mission. The NCRC provides training support, cyber risk assessments, and cyber testing to enable cyber forces to train as they fight and assist program offices with vulnerability assessments.
Responsibilities
- Perform adversarial threat emulation (Red Teaming) and penetration testing to assess aeronautical systems, subsystems, and equipment (platform IT).
- Conduct adversarial threat emulation (Red Teaming) and penetration testing on government networks including Windows domains, Linux systems, switches, routers, and other network devices.
- Apply and/or develop advanced penetration testing principles, concepts, and tactics.
- Identify issues and vulnerabilities associated with operational networks and programs.
Requirements
- Current Top Secret clearance with SCI eligibility.
- Bachelor’s degree from an accredited college in a related discipline, or equivalent experience/combined education and/or advanced certification.
- At least 10 years of pen testing, red team operations, and/or offensive security experience.
- Experience operating open source and commercial tools such as Metasploit, Burp Suite, Cobalt Strike, NMAP, Core Impact, etc.
- Working knowledge of IP network protocols, subnetting, routing, switching, etc.
- Experience in one or more of the following cybersecurity disciplines:
- Penetration testing of modern Windows and Linux operating systems and IP-based networks.
- Exploit and malware development targeting modern operating systems and defenses.
- Reverse engineering.
- Web application penetration testing.
- Software development.
- Hardware hacking.
- Cryptography.
- Software defined networks.
- Digital forensics.
- Control systems.
- Radio Frequency (RF) hacking.
Desired Qualifications
- Cyber related military training courses such as Title 10 Interactive On-Net Operator Course, Joint Cyber Analysis Course (JCAC), and Cyber Operations Specialist Qualification Course.
- Industry certification of Offensive Security Certified Professional (OSCP).
- Specialization in web application penetration testing.
- Experience with WiFi and/or Software Defined Radio (SDR) hacking.
- Experience with red team / adversarial emulations.
- Experience executing Close Access Team (CAT) assessments.
- Experience with weapon systems assessments.
- Experience with bash scripting, Python, and/or PowerShell.
- Experience working in a cyber range.
Benefits
Great health benefits, leadership training, 401k with generous company matching, Employee Stock Ownership Plan (ESOP), career professional development, tuition reimbursement, flexible hours, work/life balance, rewards and recognition, paid time off, parental leave.
Schedule
This position requires an on-site schedule with 5 days on-site. Schedule may require flexible weekend and/or evening shifts, subject to change based on company/contract requirements.