Senior Cyber Security Engineer / CSET
On-siteOrlando, Florida, United States
Job Summary
Execute offensive security engagements and adversarial emulation testing across diverse networks, developing comprehensive security strategies to verify control effectiveness. Conduct vulnerability scanning, exploitation, lateral movement, and C2 infrastructure management while evading detection tools like EDR. Systematically analyze applications through source code review and reverse engineering to locate programming flaws, then document findings and recommend risk mitigation techniques. Collaborate with stakeholders to facilitate solution agreements and assist Blue Team members in refining detection capabilities. Maintain situational awareness throughout engagements and continuously update knowledge on Tactics, Techniques, and Procedures.
Required Qualifications
- Bachelor's degree with a focus in computer science, computer information systems, engineering, mathematics, management information systems, cybersecurity, cyber operations, or a related discipline
- 5+ years of cyber adversarial emulation experience
- Experience with penetration testing of modern Windows and Linux operating systems
- Experience with IP-based networks and protocols
- Experience with 802.11 networks
- Experience with web applications
- Experience with hardware hacking
- Experience with software defined networks/RF
- 10+ years of experience in leading complex and technically diverse teams of cyber professionals
- Intermediate knowledge of known Advanced Persistent Threat (APT) actor Techniques, Tactics, and Procedures (TTPs)
- Familiarity with terminology from Mitre ATT&CK used to describe TTPs used in cyber attacks
- Intermediate knowledge of techniques and tools used for exploit development
- Intermediate knowledge of software debugging
- Intermediate knowledge of application fuzzing
- Intermediate knowledge of tools and techniques used for incident response
- Intermediate knowledge of reverse engineering
- Intermediate knowledge of digital forensics
- Superior oral communication skills
- Ability to project confidence and enthusiasm in formal presentations
- Ability to solicit goals and requirements from range users
- Ability to explain adversarial emulation in the context of testing and training events
- Ability to effectively communicate event and environment requirements to CSET members
- Ability to explain cost estimates based on estimated levels of CSET effort
- Ability to manage expectations as relevant to CSET TTPs
- Ability to explain technical nuances and significant attributes of advanced cyber attacks to non-cyber-savvy audiences
- Superior technical writing skills
- Ability to author, review, and provide input and feedback to documents drafted by CSET personnel
- Ability to create persuasive and impactful technical briefing materials
- Ability to work independently
- Ability to collaborate with range and event leadership, CSET team members, users, and other event stakeholders
- Required/Maintain IAT Level III or IAM Level III 8570 certifications
- One or more of the following certifications: CASP+ CE, CCNP Security, CISA, GIAC Incident Handler (GCIH), GIAC Certified Enterprise Defender (GCED), CISM, GSLC, CCISO, Certified Information Systems Security Professional (CISSP)
- One or more of the following vendor certifications within 6 months of being hired: Offensive Security Certified Engineer (OSCE), Offensive Security Certified Professional (OSCP), GIAC Certified Exploit Researcher and Advanced Penetration Testers (GXPN), Offensive Security Certified Engineer (OSCE3)
- U.S. Citizenship
- A U.S. Government Security Clearance at the Top Secret / SCI Level
Desired Qualifications
- Master's degree with a focus in computer science or cybersecurity
- 10+ years of experience supporting the execution of Department of Defense (DoD) offensive cyber operations (OCO) or defensive cyber operations (DCO)
- Experience with operational training programs and qualification standards
- Red Team, Computer Operator or Exploitation Analyst experience with Threat Systems Management Office (TSMO), US Air Force, US Navy or National Security Agency (NSA) / Cyber Mission Force teams
- Experience with OT, IoT, XIoT
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.