Required Qualifications:
- Minimum of 12 years with BS/BA; Minimum of 10 years with MS/MA; Minimum of 7 years with Ph.D. Will consider Associate+14 or HS16+ years of experience.
- Cross-certified in multiple related technology areas in order to conduct reviews of network vulnerability scan, virtual infrastructure, cloud, and other related areas
- Able to analyze organization's cyber defense policies and configurations and evaluate compliance with regulations and organizational directives (i.e., analysis of mitigations)
- Familiar with the following areas:
- Boundary Security (i.e., Firewalls, Network Device Management (NDM) policies, and any boundary technology)
- Network Infrastructure (i.e., Firewalls, Routers, Switches, NDM, policies, and network infrastructure)
- Domain Name System (DNS)
- Exchange Server
- Network Vulnerability Scan
- Traditional Security
- Releasable Review
- Virtual Infrastructure and Environments
- Cross Domain Solution (CDS) (Administrative and Limited Technical Review)
- Endpoint Security Solutions
- Mobility (Wireless, Wireless Discovery, 802.11, BlackBerry Enterprise Server (BES), BlackBerry Handheld, etc.)
- Voice and Video over IP (VVOIP)
- Database (Oracle, SQL, or any other database)
- Windows Infrastructure
- UNIX Infrastructure (includes all systems based on UNIX)
- Web Review (i.e., services, servers, etc.)
- Technology not specifically assigned above using SRGs, STIGs, or best practices utilizing the most appropriate certified technology area
- U.S Citizenship required
- Active TS with ability to obtain/maintain SCI
Desired Qualifications:
- CERTIFICATIONS: Security+, GSEC, Network+, GCED, CySA+ and Scrum Master.
Peraton seeks an OT Reviewerto support PACOM J6 establish the organizational foundation for IC/SCADA-focused cybersecurity assessments across the PACOM AOR.
Location: Fort Meade (Annapolis Junction), MD
Primary responsibilities:
- Develop OT-specific assessment criteria aligned to DISA OT STIGs
- Provide expertise in current version of Vulnerability Scan Procedures Guide and any official correspondence sent via electronic transmission or verbal meetings to conduct scans.
- Conduct standard internal network scans, from the premise router inward while ensure scanning of all site-managed network spaces.
- Perform technical Security Readiness Reviews (SRR).
- Ensure the use the appropriate technology STIG/SRG and, where applicable, the appropriate automated script or tool for that technology.
- Conduct assessments of systems and networks within the network environment or enclave and identifies where those systems/networks deviate from acceptable configurations, enclave policy, or local policy.
- Assist in developing EXSUMs/ Briefings/Reports.
- Develop and maintain cybersecurity vulnerability review, inspection, and audit SOPs, TTPs, checklists, and guides.
- Prepare audit reports that identify technical and procedural findings and provide recommended remediation strategies/solutions .
- Adapt DCDC's existing inspection criteria framework for OT environments
- Integrate with DCDC DRSI workflows
- Complete initial PACOM coordination for Government acceptance of the OT Inspection Criteria Package (Del 15) - Phase 1
- Conduct assessments across AOR - Phase II