Job Summary:
Dark Wolf is looking for a Penetration Tester who will plan and perform continuous cross-domain vulnerability assessments and penetration testing. The role involves analyzing systems for vulnerabilities and providing remediation strategies, while also developing custom tools and conducting assessments for federal government clients.
Responsibilities:
• Candidates may be asked to move between projects and participate in either single engagement penetration tests or continuous engagement Red Teams.
• The position will primarily require the candidate to lead the technical aspect of a specific, long-term penetration testing effort, helping to conduct varied testing efforts against applications and networks for the federal government.
• Candidates may also be placed on a larger Red Team and be expected to develop a continuous campaign-based assessment that emulates the target’s real-world adversaries by developing new tools specific to the target.
• Candidates will be expected to integrate into ongoing testing efforts, requiring subject matter expertise in multiple disciplines of vulnerability testing and assessment, the ability to interact and liaison directly with clients and a strong ability to write and document findings.
• Travel is required on an occasional basis for clients requiring onsite testing.
Qualifications:
Required:
• 3+ years’ experience in three or more specific areas to include: intelligence analysis, network engineering, networking security, penetration testing, red team operations, hardware engineering, software engineering, exploit development, reverse engineering, vulnerability assessment, physical security assessments, social engineering
• Strong knowledge of testing simulated intrusion attempts and physical penetration testing
• Proficiency in the testing and assessment of mobile operating systems, embedded systems and/or IoT devices
• Familiarity with unmanned aerial vehicles and associated mobile and wireless technologies
• Proficiency of various operating systems: Windows, iOS, Android, Mac or Linux
• Proficiency with cloud technology and deployments: Amazon Web Services, Microsoft Azure, Google Cloud Platform
• Moderate competency in at least one scripting and/or coding language
• Working knowledge of software development, with preference for experience working around software development teams and efforts
• Experience in network analysis methodologies
• Experience in drafting reports, documenting case details, and being able to summarize findings and recommendations based on system analysis
• Demonstrated strong written and verbal communication skills
• BS (or equivalent) in Cybersecurity, Information Security, IT, EE, Network Engineering, Computer Science, or related field
• Willingness to travel
• US Citizenship and an active Top Secret/SCI security clearance required
Preferred:
• Familiarity with container technologies to include container orchestration and microservices
• Experience with DevSecOps and adjacent tools; strong preference for experience with Kubernetes, software development pipelines
• Security Certification: CEH, OSCP, PNPT or similar security/pentesting certs
• Experience employing advanced forensic tools and techniques for attack reconstruction, including dead system analysis and volatile data collection and analysis
• Experience in performing post-incident computer forensics without destruction of critical data.
• Desired experience ensuring quality assurance and the spreading of best practices
• MS degree in technical field
• Security+ Certification
Company:
Dark Wolf provides DevSecOps agile software development, information operations, penetration testing and incident response, applied research and rapid prototyping, machine learning, and mission support and engineering services to the Intelligence Community, national security, and Fortune 500 customers. Founded in 2009, the company is headquartered in Herndon, USA, with a team of 501-1000 employees. The company is currently Late Stage.