Must be US citizen (must be willing to submit to federal, state, and local background checks and other requirements). The development of novel attack methods.…
Communication: Excellent written and verbal communication skills; able to explain technical decisions clearly to technical and non-technical stakeholders.…
Communicate technical findings, trends, and recommendations to both technical and non-technical stakeholders. Ability to identify data discrepancies, anomalies,……
We are seeking a Cybersecurity Architect to design, implement, and oversee security solutions across enterprise IT and operational technology environments.…
Requires current DoD 8570 IAT Level II certification (CCNA Security, CySA+, CICSP, GSEC, Security+ CE, SSCP). Demonstrated deep knowledge of Security Operations……
Own components end-to-end — From breaking down ambiguous problems into clear technical design specs, test driven development through to production support.…
This information is collected for employment purposes, including identification, work authorization, FCRA-compliant background screening, human resource……
Advanced event analysis leveraging SIEM tools. Regularly develop new and interesting use cases for future SIEM logic. Advanced knowledge of ServiceNow a plus.…
Education: Minimal 2-year technical degree with 5+ years of relevant experience in Information Security, or bachelor’s degree (Computer Science, Cybersecurity,……
Bachelor's degree in Cybersecurity, Information Technology, or a related field preferred; Experience supporting HITRUST certification or attestation.…
Ensures cybersecurity needs established and maintained for operations, security requirements definition, security risk assessment, information systems analysis,……
Lead technical design for complex security platform features from conception to production. Design and develop real-time security detection engines using Apache……
Science, or a closely related field; OR. Advanced knowledge of key IT infrastructure technologies including virtualization technologies, server architectures,……
Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, Computer Engineering, or a related technical field.…
Required Education: Bachelor's degree in computer science, Cybersecurity, Information Technology, or a related field (or equivalent work experience).…
Reviews recommended changes from fleet and other activities, ECPs, Site Activation Schedules, WSPDs, Navy Training Plans, Production Training and Support……
Bachelor's degree in Computer Science, IT, or related field. Knowledge of penetration testing and vulnerability assessment capabilities and tools.…
Apply a technical baseline and translate technical and financial risk into cost including risk application to develop cost estimations, budgeting, planning, and……
Certification Required: DoD 8570 IAT Level II certification and CSSP/CND certification required. Participate in program reviews, product evaluations, and onsite……
Communication: Excellent written and oral communication skills, with the ability to document findings and present risk to both technical and non-technical……
Provide technical leadership and guidance for junior penetration testers during all phases of an assessment. Go beyond automated and “push-button” attack tools……
The Columbia Group (TCG), is a technical services support company which has a successful 50+ year history of providing the United States government with……
Experience with basic scripting languages including bash and/or PowerShell.
Experience with at least one object-oriented programming language (Python, Ruby, Java, etc.).
Must be US citizen (must be willing to submit to federal, state, and local background checks and other requirements).
Knowledge of Windows, Unix, TCP/IP, IDS/IPS, and web content filtering.
Demonstrated ability to:
Adhere to the highest standards of honesty and scientific and business integrity.
Think critically about complex problems and situations.
Consider emerging vulnerabilities and threats from within the context of organizational risk and business impact(s).
Develop novel attack vectors based on newly discovered vulnerabilities.
Develop home-grown software solutions and utilities for computer network attack (CNA) and computer network defense (CND).
Apply industry standards and best practices including the Penetration Testing Execution Standard (PTES) and the Mitre Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) Framework.
Go beyond automated and “push-button” attack tools and utilities.
Possess a basic understanding of regulatory standards and requirements including the Health Insurance Portability and Accountability Act (HIPAA), Payment Card Industry Data Security Standard (PCI-DSS), and the Gramm-Leach-Bliley Act (GLBA).
Responsibilities:
Project-Based
Help develop and deliver test strategies for attacking and assessing complex and distributed systems.
Provide representative tactics, techniques, and procedures (TTPs) for opportunistic, advanced, and sophisticated attackers according to customer goals and objectives.
Prepare clear and concise situation reports and activity summaries for BLS customers and senior leadership.
Execute verification and validation testing for customer mitigations and fixes.
Develop and deliver walkthrough(s), proof(s) of concept (PoCs), articles, and formal presentations.
Research and Development (R&D)
Attend and/or present at professional conferences and events.
Conduct independent research for:
The development of novel attack methods.
Discovering new and/or undisclosed vulnerabilities.