This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Astrion has an exciting opportunity for an SE-3 Cybersecurity Penetration Tester for the TMAS 2 96 CTG Task Order, supporting the 48 CTS / TGEE. The 48th CTS/Det 1 conducts Cyber Security Test & Evaluation of Embedded Avionics & Weapons Systems for multiple platforms within the Air Force.
Job Responsibility:
Execute test projects and program objectives with various DoD and federal agency customers
Review technical documentation related to Avionics Embedded Systems and RF datalinks and identify potential design shortfalls that might result in a cybersecurity weakness
Develop test corpus and test plans to validate the presence of weaknesses
Analysis data from test events and present this data in a coherent and accurate manner for the customer
Work with operational testers and pilots to identify vulnerabilities which might affect the cyber resiliency of the platform for a given mission
Assist with developing cyber contested environments to demonstrate the resiliency of the platform under test
Requirements:
Technical BS Degree and 3-10 years of applicable experience
Active Secret clearance is required and must be able to obtain/maintain a Top Secret clearance
U.S. Citizenship is required
Must have or be able to obtain DOD 8140 IAT Level 3 certification (CASP, CISSP, ISSEP, etc.) within 6 months of hire
Prior understanding of aircraft avionics navigation, communication, and datalinks is desired (GPS, ACARS, Mode-S, Link-16, and etc.)
Proficiency in analyzing and/or manipulating avionics communication protocols, such as ARINC 429, MIL-STD-1553
Military aircraft operations, maintenance, test or acquisition experience is desired
Prior knowledge and applicable experience using various RF testing tools such as HackRF, SDR’s, spectrum analyzers, and Wireshark
Knowledge of common vulnerabilities and attack vectors in aviation systems
Understanding of aircraft network architectures
Understanding of cryptographic principles and their application in aviation security
Familiarity with industry-standard frameworks and methodologies for conducting penetration tests, such as OWASP Testing Guide and NIST SP 800-115
Knowledge of endpoint security technologies and techniques
Experience in identifying and exploiting security vulnerabilities in web applications
Familiarity with common networking protocols and technologies
Proficiency in conducting vulnerability assessments and penetration tests on network infrastructure
Ability to effectively communicate technical findings and recommendations to both technical and non-technical stakeholders
Prior experience with the use of enterprise penetration test tools
Experience with python, bash, and PowerShell scripts
Capable of rewriting preexisting scripts, tools, or exploits to work on target systems
Conduct penetration tests on Active Directory environments
Execute advanced attack techniques, including pass-the-hash and golden ticket attacks
Provide actionable recommendations and remediation strategies
Demonstrate the ability to complete a CTF if requested
Nice to have:
Bachelor’s Degree in either Engineering or Cybersecurity related Discipline desired
Active TS/SCI preferred
OSCP, CPTS, PNPT certifications desired
Prior understanding of aircraft avionics navigation, communication, and datalinks is desired (GPS, ACARS, Mode-S, Link-16, and etc.)
What we offer:
Competitive salaries
Continuing education assistance
Professional development
Multiple healthcare benefits package options
401K with employer matching
Competitive time off policy along with a federally recognized holiday schedule