Security Software Engineer – Red Team Penetration Tester

RPI Group Inc

  • Dahlgren, VA
  • 8 days ago
  • Full-time

Highlights

SANS certifications/courses: SEC560 – Network Penetration Testing and Ethical Hacking (GPEN), SEC542 – Web App Penetration Testing and Ethical Hacking (GWAPT), SEC660 – Advanced Penetration Testing, Exploit Writing, and Ethical Hacking (GXPN), SEC642 – Advanced Web App Penetration Testing and Ethical Hacking, SEC564 – Red Team Operations and Threat Emulation. Offensive Security certifications: Offensive Security Certified Expert (OSCE), Offensive Security Exploitation Expert (OSEE), Offensive Security Wireless Professional (OSWP).

Numbers & Facts

LocationDahlgren, VA
Job TypeFull-time
Websitehttps://rpigroupinc.com/

Description

Position Title: Security Software Engineer – Red Team Penetration Testers
Salary Range: $110,000 to $150,000 Annually
Location: Dahlgren, VA

About the Role

RPI Group is seeking a skilled, driven Security Software Engineer to support Red Team penetration testing for a mission-focused Navy customer. If you are energized by complex technical challenges, enjoy finding and analyzing security weaknesses, and want your work to inform real-world defensive decisions, this role is for you.

What We’re Looking For

 
  • Five(5)Yearsexperiencein:
    • Linux–firmgrasp/demonstratedknowledge
    • AssociatedTraining:COMPTIALinux+orFedVTELinux+
  • Five(5)Yearsexperiencein:
  • Windows–foundationalknowledgewithgoodunderstandingofenterprise networks
  • AssociatedTraining:Microsoftcourse(MCSA;Various)
 
  • Strong workingknowledgeofcommonPenetrationTesting(PENTEST)tools:
    • Kali,Metasploit,NMAP,CobaltStrike
    • AssociatedTraining:CertifiedEthicalHackerorOffensiveSecurity Certified Professional and;
 
  • Documentedexperienceinatleastoneofthefollowing:
  • PenetrationTesting(PENTEST)(governmentorcontractor)
  • RedTeamOperations(governmentorcontractor)
  • Tool/SoftwareDevelopment(exploits/malware,C2,reverse engineering, bug bounties)
  • Python,C,CSharp,C++,Go,Perl,Powershell
  • WebDev/WebAppDev/WebPenetrationtesting
      • NSX,vCenter,vRealizeSuite,HorizonView(VDI)and others
      • PAN-OS
      • FirePower,Nexus,IOS, ASA
      • ONTAP, SnapMirror
      • Active-Directory
      • EntraID(AzureAD),ActiveDirectory,SSO,MFA,Azure application integration, Identity Federation.
      • AutomationusingPowershell,PowerAutomate,LogicApps, Graph API.
      • MicrosoftEntraIDandMicrosoft365inahybrid environment.
      • ExperiencewithPaloAlto,Cisco,VMWare,NetAppand Microsoft products.
      • ExtendingorintegratingonpremisesADwithEntraID.
      • ManagingidentityandaccessinMicrosoftEntraID.
      • ExperienceconductingRedTeamoperationsinanMDE environment.
      • ExperiencewithAWS,CloudAudit,Serverlessand Microservice Architecture
      • ExperienceworkingwithAWSservices(suchasEC2,S3, KMS, RDS) and security best practices relevant to those services
      • ExperiencewithWebServicespenetrationtesting(RESTful and SOAP) Web Authentication protocols (e.g. OAuth2, SAML, LDAP)
  • PHP, ASP, SQL db's, Java, HTML, No SQL
  • Minimum certification as IAT Level II per DoD 8570.01, or successor.

  • Must possess an active Offensive Security Certified Professional (OSCP) certification at a minimum. OSCP is a required qualification for this position.

  • Additional penetration testing, offensive security, or red team certifications and experience may include:

    • Offensive Security certifications: Offensive Security Certified Expert (OSCE), Offensive Security Exploitation Expert (OSEE), Offensive Security Wireless Professional (OSWP)

    • SANS certifications/courses: SEC560 – Network Penetration Testing and Ethical Hacking (GPEN), SEC542 – Web App Penetration Testing and Ethical Hacking (GWAPT), SEC660 – Advanced Penetration Testing, Exploit Writing, and Ethical Hacking (GXPN), SEC642 – Advanced Web App Penetration Testing and Ethical Hacking, SEC564 – Red Team Operations and Threat Emulation

    • OSD-sponsored Cyber Operations Academy Course (COAC) graduate

    • Capture the Flag (CTF) participation, including DEF CON, OverTheWire (OTW), Hack The Box, or USS Secure CTFs

    • Security research resulting in a Common Vulnerabilities and Exposures (CVE) publication

 
  • Possess the ability to:
  • Debug and reverse engineer software.
  • Analyze Windows Events and Linux syslog's, boot logs and dmesg logs.
  • Program and debug Web 2.0, Java, Perl, Ada, C++, Tool Command Language (tcl/tk)scriptsandgraphicaluserinterfaces(GUis)usingMicrosoftVisualteland Rational ClearCase for software configuration management.
  • Program and debug Web 2.0, Java, Perl, Ada, C++, Tool Command Language (tcl/tk)scriptsandgraphicaluserinterfaces(GUis)usingMicrosoftVisualteland Rational ClearCase for software configuration management.
  • Recommendsoftwaremodificationstosystemstomitigateknownvulnerabilities. Operate and administrate computer systems running HP-UX, UNIX, Solaris, Linux and Microsoft Windows.
  • Identify security flaws in compiled and human readable source code. Understand code utilizing real-time VxWorks and Lynx OS operating systems, Common Object Resource Broker Architecture (CORBA), firewalls and networking protocols.
  • Understand how to implement NSA approved encryption technologies and devices.ApplyDISASecurityTechnical ImplementationGuides(STIGs).
  • Applyvirtualhostingandservertechnologyinsystemarchitectures.Understand and apply the concept of deceptive technology such as honey pots in system architectures.
  • Participate in Code Reviews. Perform Static Source Code Analysis. Author recommendations for improving software and code design.
  • Contribute to a System Security Administrator and Operators Manual (SSAOM)

 
  • Must be a U.S. Citizen and Possess an Active Security Clearance


RPI Group, Inc. is an Equal Opportunity Employer, including individuals with disabilities and protected veterans.
 
 

Powered by JazzHR

Similar Jobs

See more jobs