Serve as a Blue Team Vulnerability Assessment subject matter expert. Conducts Blue Team risk and vulnerability assessment at the network, system and application levels. Conducts cyber threat modeling exercises with commercial tools such as Red Seal, Sky Box or like tools. Ensure applicable Blue Team Vulnerability Assessment discipline is applied. Leverage customer/contractual Vulnerability Assessment Process Framework to include documentation creation and review as it relates the assessment, document risk/issues. Designs, tests, and implements secure operating systems, networks, security monitoring, tuning and management of IT security systems and applications, incident response, digital forensics, loss prevention, and eDiscovery actions.
Thorough understanding in a wide range of security issues including vulnerability assessment architectures, firewalls, electronic data traffic, and network access. Experience with utilizing commercial tools such as NESSUS, KIBANA, RedSeal, Lancope, WireShark, etc. Researches, evaluates and recommends new security tools, techniques, and technologies and introduces them to the enterprise in alignment with IT security strategy. Utilizes COTS/GOTS and custom tools and processes/procedures in order to scan, identify, contain, mitigate and mitigate vulnerabilities, and intrusions. Assists in the implementation of the required government security policy ICD/503 in support of Cyber lab environment.
Performs analysis to validate established security requirements and to recommend additional security requirements and safeguards. Support cyber metrics development, maintenance and reporting. Supports the formal Security Test and Evaluation (ST&E) required by each government accrediting authority through pre-test preparations, participation in the tests, analysis of the results, and preparation of required reports. Periodically conducts review of each system's audits and monitors corrective actions until all actions are closed. Experience with providing briefings to senior staff. Applies advanced technical principles, theories, and concepts. Contributes to development of new principles and concepts. Participates with senior managers to establish strategic plans and objectives: Serves as organization spokesperson on advanced projects and/or programs. Acts as advisor to management and customers on advanced technical research studies and applications
PROBLEM COMPLEXITY: Works on unusually complex technical problems and provides solutions which are highly innovative and ingenious. FREEDOM TO ACT: Works under consultative direction toward pre-determined long-range goals and objectives. Assignments are often self-initiated. Determine and pursue courses of action necessary to obtain desired results. Work checked through consultation and agreement with others rather than by formal review of supervisor. Exercises independent judgment in methods, techniques and evaluation criteria for obtaining results.
IMPACT: Develops advanced technological ideas and guides their development into a final product. Erroneous decisions or recommendations would typically results in failur to achieve critical organizational objectives and affect image of organization's technological capability. LIASON: Serves as organization spokesperson on advanced projects and/or programs. Acts as advisor to management and customers on advanced technical research studies and applications.
QualificationsTYPICAL EDUCATION AND EXPERIENCE: Bachelors and fourteen (10) years or more experience; Masters and twelve (8) years or more experience; must have DoD 8570 IAT Level III certification, CISSP preferred