Req ID: RQ164785
Type of Requisition: Regular
Clearance Level Must Be Able to Obtain: None
Public Trust/Other Required: Other
Job Family: Cyber Engineering
Skills:
IT Documentation,IT Policy Development,Offensive Cyber Operations,Penetration Testing,Script Development
Certifications:
OSCE - Offensive Security Certified Expert - Offensive Security, CISSP - ISC2, GIAC Web Application Penetration Tester (GWAPT) - Global Information Assurance Certification - GIAC, GPEN: GIAC Certified Penetration Tester - GIAC
Experience:
10 + years of related experience
Job Description:
At GDIT, people are our differentiator. We are seeking a cybersecurity professional with experience performing blue team/adversary simulation exercises to join our Cyber Security Engineering Team at the National Institute of Allergy and Infectious Disease (NIAID) . This position will work closely with the cybersecurity engineering team, cybersecurity incident response team and system owners to conduct adversary simulation exercises against NIAID’s critical scientific and business infrastructure. These exercises are intended to evaluate, validate and tune system configurations, security tools & incident response processes across the organization. This position is fully remote.
Tasks and responsibilities in this role include, but are not limited to the following:
Execute adversary simulation exercises that mimic real-world attacks to evaluate the resilience of networks, systems, and applications, with special consideration for high-performance computing and storage environments.
Develop and maintain a comprehensive library of threat actor profiles and simulation scenarios to test the effectiveness of security controls and incident response plans.
Enhance the organization's defensive posture by integrating findings from adversary simulations into our security strategies.
Document and communicate the outcomes of simulation exercises to both technical and non-technical stakeholders, providing actionable insights and recommendations.
Work with teams to help craft design and refine security policies and procedures in collaboration with the cybersecurity team to fortify defenses based on simulation feedback.
Design, build, and employ custom tools and scripts to automate and enrich adversary simulation activities.
Remain at the forefront of cybersecurity trends and advancements to ensure that adversary simulation practices are current and impactful.
Train and mentor cybersecurity team members, sharing knowledge to strengthen skills in adversary simulation techniques and strategies.
Work in concert with cross-functional teams to ensure security measures are ingrained throughout the software development lifecycle.
Required Qualifications:
BA/BS and 15+ years of experience or equivalent years of experience
A track record of performing adversary simulations, threat modeling, and risk assessment in complex computing environments.
Dedicated experience in cybersecurity roles with a significant focus on adversary simulation and threat emulation.
Deep understanding of cybersecurity principles, knowledge of various attack vectors, and familiarity with network protocols and application security.
Experience utilizing and integrating a range of cybersecurity tools in complex threat simulations.
Proficiency in scripting and coding for the purpose of automating simulation tasks and creating custom testing scenarios.
Innovative problem-solving skills and a strategic mindset in approaching threat emulation and vulnerability discovery.
Excellent communication skills for presenting complex security issues and guidance to a broad audience.
Experience in troubleshooting and solving complex information security issues
Ability to obtain a NIH Public Trust
Excellent verbal and written communication skills
Desired Qualifications:
Proficiency with cybersecurity threat hunting
Ability to create original pentesting scripts
Relevant professional certifications in the areas of cyber defense and cyber offense such as GPEN, GWAPT, CISSP, OSCP or others in the field of cybersecurity are desirable.
GDIT IS YOUR PLACE:
Full-flex work week to own your priorities at work and at home
401K with company match
Comprehensive health and wellness packages
Internal mobility team dedicated to helping you own your career
Professional growth opportunities including paid education and certifications
Cutting-edge technology you can learn from
Rest and recharge with paid vacation and holidays
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match.To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. GDIT typically provides new employees with 15 days of paid leave per calendar year to be used for vacations, personal business, and illness and an additional 10 paid holidays per year. Paid leave and paid holidays are prorated based on the employee’s date of hire. The GDIT Paid Family Leave program provides a total of up to 160 hours of paid leave in a rolling 12 month period for eligible employees.To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available.We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.
We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 30 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.
We connect people with the most impactful client missions, creating an unparalleled work experience that allows them to see their impact every day. We create opportunities for our people to lead and learn simultaneously. From securing our nation’s most sensitive systems, to enabling digital transformation and cloud adoption, our people are the ones who make change real.
GDIT is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status, or any other protected class.