Cydecor is seeking a Security Software Engineer/Penetration Tester to support advanced cybersecurity and software assurance efforts for U.S. Department of Defense (DoD) systems.
Requirements
- Five (5) years of software engineering experience supporting program development or modeling and simulation for DoD or IT systems.
- Five (5) years of Linux experience, demonstrating firm command-line and system administration skills.
- Five (5) years of Windows experience with solid understanding of enterprise network environments.
- Strong working knowledge of common Penetration Testing (PENTEST) tools: Kali, Metasploit, NMAP, Cobalt Strike
- Documented experience in at least one of the following areas: Penetration Testing (PENTEST) (government or contractor), Red Team Operations (government or contractor), Tool/Software Development (exploits/malware, C2, reverse engineering, bug bounties)
- Python, C, C Sharp, C++, Go, Perl, Powershell
- NSX, vCenter, vRealize Suite, Horizon View (VDI) and others
Responsibilities
- Debug and reverse engineer software to identify vulnerabilities and optimize security performance.
- Analyze Windows Event logs, Linux syslogs, boot logs, and dmesg logs to identify anomalies and security concerns.
- Program and debug software using Web 2.0, Java, Perl, Ada, C++, and Tool Command Language (Tcl/Tk) scripts, including GUIs and configuration management tools such as Microsoft Visual Studio and Rational ClearCase.
- Recommend and implement software modifications to mitigate known vulnerabilities.
- Administer systems running HP-UX, UNIX, Solaris, Linux, and Microsoft Windows operating systems.
- Identify and remediate security flaws in both compiled and human-readable source code.
- Understand and work with real-time operating systems (VxWorks, LynxOS), CORBA, firewalls, and networking protocols.
Other
- Active Top Secret clearance with SCI eligibility.
- Minimum IAT Level II certification per DoD 8570.01 (or successor).
- Minimum penetration testing certification, holding at least one of the following: Offensive Security Certifications: OSCP, OSCE, OSEE, OSWP, SANS Certifications: GPEN, GWAPT, GXPN, or equivalent Red Team / Penetration Testing certifications
- Strong understanding of computer security principles, military system specifications, and DoD Cybersecurity policies for both land-based and afloat/tactical systems.
- Ability to communicate effectively and succinctly in both written and verbal formats.