This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
At Boeing, we innovate and collaborate to make the world a better place. We're committed to fostering an environment for every teammate that's welcoming, respectful and inclusive, with great opportunity for professional growth. Find your future with us. Millennium Space Systems, a part of Boeing Defense, Space and Security (BDS), is a fast, agile small satellite company focused on national security space. Our missions have direct impact to global security, like missile warning and Earth observation. Our team is curious, bold and innovative. We take risks, innovate and explore new techniques and technologies. We influence change because we challenge the status quo. And when we watch our satellites launch, we know each one of us made it happen. The MSS Ground Systems & Operations Organization is looking for a Mid-Level Cybersecurity Assessment Specialist to join the team in Chantilly, VA. This position involves performing adversarial security testing of the enterprise's various Information Technology (IT) environments and penetration testing utilizing Proof of Concept (PoC) and homegrown exploitation in addition to red teaming activities. This individual must have strong foundational knowledge and working proficiency in both system administration and software development disciplines.
Job Responsibility
Conduct application and network layer penetration tests on various IT environments
Conduct red teaming activities, including physical security penetration testing
Perform independent pen testing utilizing numerous penetration testing tools and leveraging mainly manual techniques, typically testing will necessitate source code analysis
Write risk prioritized finding reports, debrief system owners and consult on remediation options
Retest security vulnerabilities that have been identified as fixed to verify remediation
Contribute to pen testing, red teaming, tooling, and reporting methodology enhancements
Evaluate effectiveness of defensive countermeasures and consult with blue teams to help improve detection methods and capabilities required for situational awareness
Performing exploitation analysis and authors exploitation tools/techniques
Experience performing ACAS and OpenRMF compliance scans for classified networks, identifying weaknesses and reporting results to external organizations
Experience with secure software development lifecycle and large-scale computing environments
Experience working with Information Security principles, policies, and industry best practices including the Critical Security Controls (CIS), Open Worldwide Application Security Project (OWASP), Top 10 and Mitre Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) framework
Experience working with Authentication and Authorization Controls
Experience working with common server applications such as Internet Information Services (IIS), Apache, Lightweight Directory Access Protocol (LDAP), Tomcat, and Secure Shell (SSH)
Experience working with common network protocols such as HyperText Transfer Protocol/ HyperText Transfer Protocol Secure (HTTP/HTTPS), Transmission Control Protocol/Internet Protocol (TCP/IP), and User Diagram Protocol (UDP)
Requirements
Active TS Clearance with SCI eligibility
At least 8 years of experience working in Cybersecurity enclaves
3 years' experience as an ISSM/ISSO
Nice to have
At least 2 years working as ISSE across multiple bases and systems for civil engineering
Expertise in Risk Management Framework (RMF)
Experience with Security Authorization (ATO) process and Program Protection Plans (PPP/PPIP)
Experience performing Criticality Analysis
Experience with programming experience in Python, PHP, Perl, Ruby, .NET, or other interpreted or compiled languages
Experience in penetrating testing and vulnerability assessments using manual techniques and vulnerability testing tools (including scanners, sniffers, fuzzers and exploit tools such as Burp, Nmap, Kali and Metasploit)
Experience configuring and conducting automated scanning and manual testing
What we offer
competitive base pay and variable compensation opportunities
health insurance
flexible spending accounts
health savings accounts
retirement savings plans
life and disability insurance programs
paid and unpaid time away from work
generous company match to your 401(k)
industry-leading tuition assistance program pays your institution directly
fertility, adoption, and surrogacy benefits
up to $10,000 gift match when you support your favorite nonprofit organizations