Oasis Systems - Colorado Springs, CO

posted 3 months ago

Full-time - Senior
Colorado Springs, CO
Professional, Scientific, and Technical Services

About the position

Astrion is seeking a Senior Cybersecurity Penetration Tester to join our dynamic cybersecurity test team supporting the 48th Cyber Space Test Squadron (48 CTS) at Peterson Space Force Base, Colorado. This role is pivotal in enhancing the cybersecurity posture of the United States Air and Space Forces by conducting thorough penetration testing and security analysis on various systems and software. The ideal candidate will thrive in a fast-paced, multi-disciplinary environment and will be eager to learn and adapt to new technologies. The position offers a unique opportunity to engage in both compliance testing and penetration testing, depending on the candidate's skill set and interests. As a Senior Cybersecurity Penetration Tester, you will be responsible for conducting independent penetration tests, collecting data, automating tests, and reporting findings. You will develop innovative test tools and strategies tailored for cybersecurity testing within the Department of Defense (DOD). Your role will also involve performing system security analyses to identify vulnerabilities, executing hands-on testing across multiple operating systems, and providing technical guidance to penetration test teams. Effective communication of test results to both technical and non-technical audiences is crucial, as is the ability to work collaboratively in both small and large team settings. This position requires a strong foundation in cybersecurity principles, with a focus on penetration testing methodologies and tools. You will be expected to maintain a high level of self-initiative and motivation, working under minimal supervision while contributing to the overall mission of the 48 CTS. The role includes travel requirements, with up to 25% of your time spent traveling within the United States and potentially overseas to meet mission objectives.

Responsibilities

  • Conduct independent penetration testing, data collection, test automation, and reporting.
  • Develop test tools and strategies for cybersecurity testing in DOD.
  • Perform system security analysis on systems and/or software to understand and identify vulnerabilities.
  • Execute hands-on testing which includes technical skills with multiple operating systems (Windows, Linux, Unix) as well as various software/databases (Apache, SQL Server, Oracle, etc.).
  • Provide technical guidance and support to penetration test teams.
  • Document and communicate test results effectively to technical and non-technical user groups in written and oral formats.
  • Provide technical support in the management, planning, and execution of CVI, ACD, and other related activities.

Requirements

  • Technical Master's Degree and at least 10 years of applicable experience.
  • Active Secret clearance is required and must be able to obtain/maintain a Top Secret clearance.
  • Must have or be able to obtain DOD 8570 IAT Level 3 certification (CASP, CISSP, ISSEP, etc.) within 6 months of hire, and maintain certification throughout employment.
  • Experience using modern penetration testing tools and methods.
  • Experience with testing and exploiting web applications.
  • Analytical skills and problem-solving skills.
  • Good organization, decision making, and verbal and written communication skills.
  • Excellent self-initiative and self-motivation with the ability to work under minimal supervision.
  • Ability to work effectively in small and large team settings to solve complex problems.
  • Ability to work with DOD Program Offices to scope, plan, execute, and report on penetration tests.
  • Significant knowledge of Windows and Linux (including Kali) Operating Systems.

Nice-to-haves

  • Experience leading the team and performing penetration test activities/events.
  • Knowledge of source code vulnerability analysis.
  • Knowledge of network security/engineering.
  • Knowledge of common wired and wireless network protocol structures.
  • Experience using interpreted languages (Python, Ruby, JavaScript, Bash, PowerShell, PHP, etc.).
  • Knowledge of compiled languages (C, C++, Assembly, Java, etc.).
  • Certifications: CISSP, CASP, OSCP, OSEP, OSWA, OSWE, OSED, OSCE, GCIH, GPEN, and/or GWAP.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service