Cyber Triage Analyst
About the Role
As a cybersecurity vulnerability analyst, you will support a Vulnerability Disclosure Program (VDP) within the federal government. You will be responsible for reviewing and vetting security vulnerability reports submitted to the DoD VDP from external hackers. Your role includes evaluating reports to ensure vulnerabilities are reproducible and valuable, assessing severity, and assigning risk statements. You will use the HackerOne Triage console tool to assist in prioritizing and identifying duplicate submissions. Valid reports will be documented in a DoD-approved format and forwarded to the Vulnerability Management Analyst team for coordination and mitigation. Additionally, you will serve as a VDP liaison with the hacker community.
Responsibilities
- Utilize offensive tool sets such as Kali Linux to safely analyze production networks and systems, documenting steps and procedures to produce usable vulnerability assessments.
- Identify and investigate vulnerabilities, assess exploit potential, and document findings and remedies for presentation to facilitate mitigations on customer systems.
- Conduct web application vulnerability assessment testing using both automated tools and manual web exploitation techniques, including tools such as Burp Suite and open-source toolsets.
- Utilize a variety of industry-standard security tools to conduct automated scans against systems and applications.
- Develop and execute proof-of-concept exploits to demonstrate the real-world impact of identified vulnerabilities using various web exploitation methods.
Requirements
- Experience operating in a professional IT or cybersecurity environment.
- Experience investigating security events, threats, or vulnerabilities.
- Knowledge of information security principles and practices.
- Knowledge of web exploitation concepts and techniques.
- Knowledge of the Open Web Application Security Project (OWASP) Top 10.
- Ability to utilize MITRE ATT&CK, CVSS, and NIST frameworks to assess vulnerability severity and risk impact.
- Secret clearance.
- HS diploma or GED and 9+ years of experience with vulnerability assessment, or Bachelor’s degree and 5+ years of experience, or Master’s degree and 3+ years of experience, or Doctorate degree.
- DoD IAT Level II Certification such as CompTIA Security+ Certification.
Preferred Qualifications
- Experience with multiple Hack-The-Box penetration testing labs and challenges, developing hands-on expertise in vulnerability enumeration, exploitation, privilege escalation, and post-exploitation techniques.
- Experience in one or more programming languages.
- Experience in HTML/CSS or SQL.
- Experience with scripting languages such as PowerShell, Bash, Python, or Perl.
- Knowledge of penetration testing methodology, including recon, exploit, or persistence.
- Knowledge of networking protocols, their uses, and potential misuses.
- Excellent customer service skills.
- Bachelor’s or Master’s degree in Information Technology, Computer Science, Cybersecurity, Information Systems, Software Engineering, or Data Science.
- CEH, CCNA-Security, CySA+, OSCP, PenTest+, or similar certification.
Clearance
Applicants selected will be subject to a security investigation and must meet eligibility requirements for access to classified information. A Secret clearance is required.
Benefits
Booz Allen offers health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. A recognition awards program acknowledges employees for exceptional performance and superior demonstration of company values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in these benefit programs. Individuals not meeting this threshold are eligible for select offerings, excluding health benefits.
Pay
Salary is determined by various factors, including location, education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $61,900.00 to $141,000.00 (annualized USD).
Schedule
This posting will close within 90 days from the posting date.
Work Model
Booz Allen’s people-first culture prioritizes collaboration, whether in-person or virtual. Employees working virtually are generally expected to have their cameras on during meetings.
- Remote: Primarily remote, with occasional in-person requirements at a Booz Allen or customer facility.
- Hybrid: Frequent work from a Booz Allen facility, with potential visits to customer facilities as needed.
- Onsite: Work primarily performed at a Booz Allen office or customer facility, with direct collaboration as required by the role.