The cybersecurity test engineer role focuses on Whitebox adversarial testing for Department of Defense Air Force clients, aligning with NIST 800-53 RMF controls and concentrating on data flows and access controls within system architectures in a collaborative team environment.
Responsibilities
- Collaborate with a team of problem solvers to test and evaluate systems using a Whitebox adversarial approach in support of DoD Air Force clients.
- Assess systems against NIST 800-53 Risk Management Framework security controls.
- Examine filtering capabilities and data flows, including low-level aspects of system architecture, as well as Mandatory Access Controls and Discretionary Access Controls.
- Develop capabilities by learning from the expertise within the skilled team.
Requirements
- Experience with Linux command line, including scripting in Ruby, Python, or Bash, and automating basic tasks
- Experience with networking concepts
- Experience with virtualization
- Secret clearance
- HS diploma or GED
- Ability to obtain a DoD IAT Level II Security+ CE Certification within 120 days of start date
Technologies
- Ruby
- Python
- Bash
- Linux
- Kali Linux
- Wireshark
- Tripwire
- Burp Suite
- Metasploit
Benefits
- Health, life, disability, financial, and retirement benefits
- Paid leave
- Professional development
- Tuition assistance
- Work-life programs
- Dependent care
- Recognition awards program
The Opportunity
Collaborate with a team of problem solvers to test and evaluate systems using a Whitebox adversarial approach for the DoD in support of Air Force clients.
Work with systems evaluated under NIST 800-53 Risk Management Framework security controls, with emphasis on data flows and filtering at multiple levels within the architecture, including Mandatory Access Controls and Discretionary Access Controls.
Expand capabilities through learning from experienced colleagues within a skilled team.
Nice If You Have
- Experience analyzing and executing test plans and procedures
- Experience developing or analyzing technical documentation
- Experience with penetration testing or adversarial emulation
- Experience with NIST 800-53 security controls
- Knowledge of cyber threats and how to harden a system to prevent them
- Knowledge of vulnerability assessment tools, including Kali Linux, Wireshark, Tripwire, Burp Suite, and Metasploit
- Certifications such as OSCP, CISSP, CASP, Red Hat CSA, or GPEN
Clearance
Applicants selected will undergo a security investigation and must meet eligibility requirements for access to classified information. A Secret clearance is required.
Compensation
Salary is determined by factors such as location, education, knowledge, skills, competencies, and experience, along with contract-specific affordability and organizational requirements. The typical annual salary range is USD 61,900.00 to USD 141,000.00.
Identity Statement
As part of the hiring process, you may be asked to complete an identity verification process that uses biometrics and artificial intelligence to confirm authenticity and prevent fraud. Interviews and assessments may require you to be on camera, and Booz Allen reserves the right to verify identity by capturing imagery.
Candidate AI Usage Policy
AI is part of Booz Allen operations, and the firm promotes responsible use of AI tools. Candidate evaluation will be based on your own skills and knowledge. Use of AI or similar tools to assist with interview responses is prohibited unless explicit permission is granted.
Work Model
Onsite: This position is primarily performed at a Booz Allen office or customer facility, enabling direct collaboration with colleagues and clients as required by the role.
Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to disability, protected veteran status, or any other status protected by applicable law.