Job Summary (List Format) Senior Security Test & Evaluation Analyst (Artificial Intelligence):
- Lead and implement comprehensive security testing, including all phases of ethical hacking (reconnaissance, footprinting, scanning, exploitation, and post-exploitation) for on-premises and cloud environments.
- Conduct static and dynamic code reviews, system architecture assessments, and security control evaluations.
- Design and execute AI-enabled solutions to enhance security test and evaluation processes and integrate AI capabilities into standard security operations.
- Provide input and documentation to support the development and adoption of AI technologies for security testing and evaluation programs.
- Perform scenario-based and functional security assessments using both authenticated and unauthenticated approaches, leveraging AI where possible.
- Analyze AI model outputs to identify vulnerabilities in hardware, software, and cloud systems; recommend remediation strategies to reduce risk.
- Ensure compliance with all governance, standards, and regulatory requirements when implementing AI-driven security solutions.
- Develop analytic products, metrics, and technical reports to demonstrate the effectiveness of AI-enabled security practices.
- Collaborate with stakeholders to prioritize and address identified security gaps and vulnerabilities.
- Stay current on emerging AI technologies and security testing methodologies to maintain robust and effective security evaluation practices.
Required Experience & Skills:
- 5+ years hands-on security test and evaluation experience with industry tools (e.g., Nessus, GitLab, Fortify, Invicti, Mandiant MSV, Kali Linux, Wiz).
- 3+ years security testing experience with cloud platforms (AWS, Azure, ServiceNow, etc.).
- Direct experience implementing AI-driven solutions for security testing and evaluation.
- Strong analytical, problem-solving, communication, and documentation skills.
- Deep knowledge of network protocols, security technologies, vulnerabilities, and attack vectors.
- Familiarity with government security standards (NIST, FISMA, FedRAMP, OMB) is a plus.