Responsibilities
Arcfield is expanding its Cyber initiative and seeking a Pen Tester, Level 4 subject matter expert (SME) to help lead our evolving Cyber Security efforts. The ideal candidate will be able to provide Penetration Testing support by way of reviewing and evaluating our Customer's Information Systems (IS) as well as recommending changes, to our government stakeholders to improve information confidentiality, integrity, and availability. This pivotal role offers the opportunity to shape Arcfield's cyber defense strategies and contribute to our expanding portfolio of cyber programs. Note : An offer for this position is contingent upon contract award.
Responsibilities include, but are not limited to the following :
- Conduct basic reconnaissance and vulnerability scanning using established methodologies
- Identify, document, and report common vulnerabilities that could be exploited
- Perform security-focused services to improve the security posture of NRO Information Systems
- Execute active and passive penetration testing capabilities on NRO IT assets, as per government policy and direction
- Document findings in detailed reports for inclusion in Security Assessment Reports (SARs)
- Support Risk Management Framework (RMF) Steps 4 and 6 processes
- Review and write Information System Accreditation Packages (ISAPs) and Technical Information System Security Requirements (TISSRs)
- Conduct approved testing as well as writing reports following government-approved templates
- Complete ISAP / TISSR reports within 30 calendar days of on-site assessment completion
- Maintain and update report templates with government approval
- Demonstrate basic scripting abilities and understanding of network fundamentals
- Proficiently use vulnerability scanning tools
- Adhere to rules of engagement agreements between COMM Pen Testers and NRO Program ISO
- Collaborate with Program Offices to determine the scope and depth of Information System testing
Qualifications
Required :
Must possess and be able to maintain a TS / SCI clearance with PolyBS 10-12, MS 8-10, PhD 5-7Bachelor / STEM with 7+yrs Relevant Experience6+ yrs-Pen Testing experienceCertifications :GCIH
GPENPenTest+Basic scripting abilitiesBasic understanding of network fundamentalsBasic understanding of vulnerability scanning toolsExpertise in :Network protocols
Application securitySocial engineeringAdvanced scriptingExtensive knowledge of :Cybersecurity frameworks
Industry standardsAdvanced security toolsStrong leadership and project management abilitiesExcellent communication skills (both written and verbal)Ability to work with both technical and non-technical stakeholdersProblem-solving and analytical thinking skillsAbility to work under pressure and manage multiple prioritiesDesired :
BS / STEM degree(s) in Computer Science, Information Technology, Cybersecurity, or a related fieldExperience with government and military IT systems, particularly in the IC and DoD environmentsUnderstanding of IC and DoD organizational structures and processesFamiliarity with government reporting requirements and proceduresDemonstrated ability to develop innovative solutions for complex technical problemsRecognition as an authority in information security within previous rolesExperience in developing and implementing security policies and proceduresEEO Statement
We are an equal opportunity employer and federal government contractor. We do not discriminate against any employee or applicant for employment as protected by law.