National Security Agency logo

Cybersecurity Testing and Evaluation Specialist - Entry to Mid-Level Maryland

  • $87,362–$153,082 Per Year

Highlights

Cybersecurity testers at NSA play a vital role in the security of NSA's mission by conducting both security controls and adversarial testing against our state-of-the-art Information Technology (IT) systems executing NSA's SIGINT and Cybersecurity missions. Relevant experience must be in engineering of computer or information systems over their lifecycle (i.e., requirements analysis, design, development, implementation, testing, integration, deployment/installation, and maintenance), programming, vulnerability analysis, penetration testing, computer forensics, and/or systems engineering.

Numbers & Facts

LocationMD
IndustryGovernment and Military
Salary$87,362–$153,082 Per Year
Company Size10,000 employees or more
Year Founded1952
Websitehttps://www.intelligencecareers.gov/NSA/

Description

Cybersecurity testers at NSA play a vital role in the security of NSA's mission by conducting both security controls and adversarial testing against our state-of-the-art Information Technology (IT) systems executing NSA's SIGINT and Cybersecurity missions. NSA is advancing technology to deliver mission outcomes. As such, Cybersecurity testers have the opportunity to work across a broad set of technologies including commercial cloud fabrics, artificial intelligence, high performance computing, and advanced cryptographic systems. These personnel are involved in both developmental and operational testing so NSA systems can be protected from the most sophisticated nation state adversaries. Some examples of tasks include:

  • Conducting security controls testing of NSA systems to ensure controls are properly implemented by system owner(s)
  • Conducting testing against cloud fabrics, including various security configuration options of cloud services and a wide variety of different security configurations
  • Assessing the effectiveness of security solutions against cybersecurity frameworks (e.g. MITRE Attack Framework)
  • Operating within teams focused on implementing and evolving cybersecurity testing procedures and implementing automation to reduce testing time and improve consistent analysis
  • Operating within a cybersecurity team for each of the life cycle steps of the Federal Government's Risk Management Framework (RMF), as maintained by the National Institute of Standards and Technology (NIST 800-53)
  • Implementing automation across the cybersecurity testing processes

Depending on their education, training, and experience, Cybersecurity testers are hired into positions as a Testing and Evaluation Specialist and placed into functional positions performing cybersecurity testing functions commensurate with their skills. Entry-level cybersecurity professionals will take on the front-line control testing of our systems while beginning to learn the intricacies of secure system design. The most experienced testing personnel will have opportunities to formulate unconstrained cybersecurity testing to emulate cybersecurity adversary and rogue system administrator threats.

Note: Please upload a copy of your transcripts from all schools attended into your Candidate Profile, prior to applying for this position. Unofficial transcripts are fine at this stage. Minimum qualifications for this position require a degree that demonstrates a concentration of computer science (CS) courses in foundational CS areas.We're looking for someone with knowledge, skills, and experience in one or more of the following:

  • Cloud Security Knowledge for commercial cloud environments such as Amazon Web Services, Microsoft Azure, Oracle or Google cloud environments
  • Knowledge of or experience with penetration testing or ethical hacking methodologies
  • Knowledge of network attacks based on MITRE Attack Framework
  • Familiarity with exploitation techniques and frameworks (network firewalls, intrusion detection systems, networks)
  • Familiarity with various exploitation frameworks (e.g. Metasploit)
  • Understanding of shell scripting for the development of network attack tools and techniques (e.g. Python, Perl, or Ruby)
  • Knowledge of vulnerability identification, mitigations, and countermeasures
  • Understanding of network protocols
  • Knowledge of Windows / Linux network programming
  • Knowledge of network architecture, network and IT infrastructure devices, physical and virtual
  • Understanding of tools (nmap, nessus, dsniff, libnet, netcat, network sniffers) and techniques (e.g. fuzzing)
  • Understanding of threat modeling and development of test scenarios
  • Critical thinking and ability to break large complex problems into manageable parts

Experience and knowledge of computer security tools, vulnerability analysis, systems architecture, systems engineering, test and evaluation tradecraft, and software engineering is helpful. Working knowledge of automation tools and Linux is helpful.

The ideal candidate is someone with a desire for experiential learning and strong problem-solving, analytic and interpersonal skills who is:

  • willing to take the initiative
  • innovative
  • able to work effectively across several different functional areas in a collaborative environment
  • able to communicate effectively (both orally and written)
  • well-organized and able to handle multiple assignments.The qualifications listed are the minimum acceptable to be considered for the position.

Degree must be in Computer Science (CS) or related field (e.g., Engineering, Mathematics). Degrees in Information Technology, Information Systems, Information Security, Networking (Systems Administration), Information Assurance, and Cybersecurity may be considered relevant if the programs contain, at minimum, a concentration of courses in the following foundational CS areas: algorithms; computer architecture (not network architecture); programming methodologies and languages; data structures; logic and computation; and upper-level mathematics.

Relevant experience must be in engineering of computer or information systems over their lifecycle (i.e., requirements analysis, design, development, implementation, testing, integration, deployment/installation, and maintenance), programming, vulnerability analysis, penetration testing, computer forensics, and/or systems engineering. Completion of military training in a relevant area such as JCAC (Joint Cyber Analysis course) will be considered towards the relevant experience requirement (i.e., 24-week JCAC course will count as 6 months of experience).

ENTRY Entry is with a Bachelor's degree and no experience. An Associate's degree plus 2 years of relevant experience may be considered for individuals with in-depth experience that is clearly related to the position.

FULL PERFORMANCE Entry is with a Bachelor's degree plus 3 years of relevant experience or a Master's degree plus 1 year of relevant experience or a Doctoral degree and no experience. An Associate's degree plus 5 years of relevant experience may be considered for individuals with in-depth experience that is clearly related to the position.Pay: Salary offers are based on candidates' education level and years of experience relevant to the position and also take into account information provided by the hiring manager/organization regarding the work level for the position.

Salary Range: $87,362 - $153,082 (Entry/Developmental, Full Performance) Salary range varies by location, work level, and relevant experience to the position.

Training will be provided based on the selectee's needs and experience.

Benefits: NSA offers a comprehensive benefits package.

Work Schedule: This is a full-time position, Monday - Friday, with basic 8hr/day work requirement between 6:00 a.m. and 6:00 p.m. (flexible).

DCIPS Trial Period: If selected for this position, you will be required to serve a two-year DCIPS trial period, unless you are a veterans' preference-eligible employee, in which case you are required to serve a one-year trial period. This trial period runs concurrently with your commitment to the position, if applicable. Before finalizing your appointment at the conclusion of your trial period, NSA will determine whether your continued employment advances the public interest. This decision will be based on factors such as your performance and conduct; the Agency's needs and interests; whether your continued employment would advance the Agency's organizational goals; and whether your continued employment would advance the efficiency of the Federal service.

Upon completion of your trial period, your employment will be terminated unless you receive certification, in writing, that your continued employment advances the public interest.

If you do not receive certification for continued employment, you should receive written notice prior to the end of your trial period that your employment will be terminated and the effective date of such termination.

About Company

NSA is at the forefront of U.S. government cryptology, integrating signals intelligence (SIGINT) and cybersecurity to enhance national and allied advantages. Our mission encompasses computer network operations aimed at securing critical insights and services, ensuring decisive advantages for the nation and our allies.

NSA's cybersecurity initiatives are pivotal in safeguarding U.S. national security systems, particularly within the Defense Industrial Base and enhancing the security of U.S.  weaponry. We are committed to advancing cybersecurity through education, research, and career development.

 Through foreign signals intelligence (SIGINT), NSA delivers crucial intelligence to U.S. policymakers and military forces. This intelligence, derived from electronic signals and systems used by foreign entities, provides essential insights into the capabilities, actions, and intentions of adversaries worldwide. It supports our efforts to defend the nation, save lives, and advance U.S. objectives and alliances globally.

Visit IntelligenceCareers.gov/NSA to learn about our mission and how you can have a rewarding career that safeguards the country’s future ­– and your own.

Similar Jobs