Senior Threat Validation Specialist

Munro Footwear Group

Helena (MT)

Hybrid

USD 120,000 - 165,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

State Information Technology Services Division - Office of Information Security in Helena, MT seeks a Senior Threat Validation Specialist to lead vulnerability assessments, red teaming, and penetration testing. You will analyze malware, advise agencies, and apply AI/LLM tools to speed up investigations while protecting state data.

The role emphasizes collaboration, threat hunting, and creating robust security postures through proactive testing and incident simulations.

Qualifications

  • Associates degree in Information Security or Technology; AND
  • 6 years’ experience in a security-related role
  • Bachelors degree in Information Security or Technology; AND
  • 4 years’ experience in a security-related role; AND
  • OSCP, Pentest+, KLCP, GCFE, GCFA, E|CIH, or CISSP
  • CPENT AI, Offsec OSAI, CompTIA SecAI+, or comparable AI-integrated offensive security training

Responsibilities

  • Lead vulnerability assessments, vulnerability consultation, red teaming and penetration testing engagements.
  • Analyze malware and provide subject matter expertise to agencies.
  • Use AI/LLM tools to accelerate reconnaissance, code/log analysis, tooling development, and reporting while safeguarding state data.
  • Teach efficient offensive-security techniques and facilitate attack/defense exercises.
  • Recommend controls to reach desired security posture.

Skills

Threat validation
Penetration testing
Vulnerability assessments
AI/LLM tooling
Offensive security

Education

Associates degree in Information Security or Technology
Bachelor's degree in Information Security or Technology

Tools

OSCP
Pentest+
KLCP
GCFE
GCFA
E|CIH
CISSP
CPENT AI
Offsec OSAI
CompTIA SecAI+

Job description

Job Description - Senior Threat Validation Specialist (26142249)

Position Title:

Senior Threat Validation Specialist - ( 26142249 )

Why live in Helena, Montana?

Helena is surrounded by rolling hills and lofty mountains and is tucked below the Continental Divide.

It is a relatively quiet place to call home where small‑town living collides with outdoor adventure.

Helena has a rich history and was originally founded as a gold camp during the Montana gold rush.

Learn more about moving to and/or living in Helena, Montana here .

In this position you will be afforded the opportunity to telework, however there will be required weekly in-office day(s) in Helena. Specific conditions will be outlined as part of the job offer and must adhere to state policy.

Why should you keep reading and consider working here?

The State Information Technology Services Division - Office of Information Security provides security services and support to all state government agencies, our mission is to protect citizen’s data. We utilize best practice standards and frameworks to deliver high quality security services to state agencies. We value collaboration, teamwork, and respect; and we promote a culture of diversity, equity, and inclusion to provide a safe environment for our employees to grow their skills. We invest in our employees by providing professional development opportunities that lead to career advancement and fulfillment. We use exciting technologies and solve complex issues. Our team has visibility into the State’s network and systems, and our actions have a direct impact on the State’s cybersecurity posture. Security Services is a fun place to do serious work. (You can learn more about SITSD here .)

What is this career opportunity?

Do you want to help Montana protect and defend our citizen’s data from cyber threats? Are you naturally curious? Are you a critical thinker? Do you have a strong interest in finding threats? If you answered yes to all these questions, then this might be the perfect job for you! Whether you are transitioning from a technical career, already a cybersecurity veteran, or wanting to start down the exciting path of cybersecurity, you might be able to join our team as a Senior Threat Validation Specialist. This position is primarily responsible for vulnerability assessments, vulnerability consultation, red teaming and penetration testing.

If you are experienced in penetration testing of web application, cloud, and/or database security, consider joining our team as an Senior Threat Validation Specialist and lead the team in offensive security tactics, teach efficient techniques for responding to threat actors, facilitate attack/defense exercises within the Bureau, and recommend controls to reach desired security posture. You will also be able to analyze malware, provide subject matter expertise to agencies and substantially impact enterprise security.

You will also use artificial intelligence (AI) and large language model (LLM) tools to work faster and dig deeper across engagements—accelerating reconnaissance, code and log analysis, tooling and script development, and reporting—while rigorously validating AI-generated output and safeguarding sensitive state data.

What are we looking for?
Education and Experience:

Alternate combinations of education,experience, and certifications will be considered on a case‑by‑case basis.

Required for the first day of work, including alternatives:

Associates degree in Information Security or Technology; AND

6 years’ experience in a security-related role

Preferred:

Bachelorsdegree in Information Security or Technology; AND

4 years’ experience in a security-related role; AND

OSCP, Pentest+, KLCP, GCFE, GCFA, E|CIH, or CISSP

CPENT AI, Offsec OSAI, CompTIA SecAI+, or comparable AI-integrated offensive security training

  • Database, Cloud, and/or Web Application Security
  • Vulnerability assessment
  • Cyber-attack stages (e.g., reconnaissance, scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks).
  • Website types, administration, functions, and content management system (CMS).
  • Attack methods and techniques (DDoS, brute force, spoofing, etc.).
  • Host-basedsecurityproducts and how those products affect exploitation and reduce vulnerability.
  • Internal tactics to anticipate and/or emulate threat capabilities and actions.
  • Network protocols such as TCP/IP, Dynamic Host Configuration, Domain Name System (DNS), and directory services.
  • Intrusion detection methodologies and techniques for detecting host and network-based intrusions.
  • Web Application Security Risks (e.g., Open Web Application Security Project Top 10 list)
  • Generative AI and large language model (LLM) fundamentals and architecture, including models and model selection, tokens and context windows, prompting, retrieval-augmented generation (RAG), agentic (tool-using) AI, the Model Context Protocol (MCP), and the trade‑offs between cloud-hosted and locally hosted models.
  • How AI and LLM‑assisted capabilities apply across the penetration testing lifecycle, including reconnaissance and open‑source intelligence (OSINT) synthesis, code and configuration review, script and exploit development, log and data analysis, and reporting, as well as AI‑augmented and semi‑autonomous testing platforms.
  • Limitations and risks of generative AI in security work, including hallucination and the need to independently verify output, data‑handling and confidentiality constraints, tool licensing, and applicable law and policy.
  • How threat actors use AI to accelerate their own operations, such as generating phishing and social‑engineering content, developing or obfuscating malware, and automating reconnaissance.
Skill in:
  • Conducting research using our threat intelligence tools .
  • Social engineering techniques
  • Defining and characterizing all pertinent aspects of the operational environment.
  • Evaluating information for reliability, validity, and relevance.
  • Identifyingcyberthreats which may jeopardize organization and/or partner interests.
  • Using security event correlation tools.
  • Detecting host and network-based intrusions via intrusion detection technologies.
  • Conducting trend analysis.
  • Reading, interpreting, developing, and deploying signatures.
  • Prompt engineering and integrating AI and LLM tools into offensive security workflows to improve speed, coverage, and quality.
  • Critically evaluating and validating AI-generated code, findings, and recommendations before acting on them or including them in deliverables.
  • Using AI tools without exposing sensitive, confidential, or regulated state data to unauthorized or third‑party services.
Ability to:
  • Communicate complex information, concepts, or ideas in a confident and well‑organized manner through verbal, written, and/or visual means.
  • Accurately and completely source all data used in intelligence, assessment and/or planning products.
  • Evaluate, analyze, and synthesize large quantities of data (which may be fragmented and contradictory) into high quality, fused targeting/intelligence products.
  • Function in a collaborative environment, seeking continuous consultation with otheranalysts and experts—both internal and external to the organization to leverage analytical and technical expertise.
  • Think critically.
  • Think like threat actors.
  • Develop or recommend analytic approaches or solutions to problems and situations for which information is incomplete or for which no precedent exists.
  • Apply techniques for detecting host and network-based intrusions using intrusion detection technologies.
  • Conduct forensic analyses in and for both Windows and Unix/Linux environments.
  • Interpret the information collected by network tools
  • Apply AI and LLM-assisted techniques to
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Threat Validation Specialist - Remote Security Lead
Senior Threat Validation Specialist - Remote Security Lead

Munro Footwear Group • Helena (MT)

Hybrid
USD 120,000 - 165,000
Cyber Defense Analyst
Cyber Defense Analyst

State of Montana • East Helena (MT)

On-site
USD 65,000 - 90,000
Sr. IT Security Engineer (Hybrid)
Sr. IT Security Engineer (Hybrid)

Belk • Charlotte (NC)

On-site
USD 140,000 - 210,000
Senior System Security Specialist
Senior System Security Specialist

Compunnel, Inc. • Baltimore (MD)

On-site
USD 120,000 - 150,000
Risk Specialist 3
Risk Specialist 3

State of Montana • East Helena (MT)

Hybrid
USD 80,000 - 110,000
Health Coverage
Retirement plans
Paid Vacation and Sick Leave and Holl-
+1
Network Security Analyst
Network Security Analyst

Allied Consultants, Inc. • Austin (TX)

On-site
USD 90,000 - 130,000
Medical insurance
Life insurance
401(K) plan with company match
+2
Cybersecurity Threat Analyst I
Cybersecurity Threat Analyst I

Jobtailor • Sioux Falls (SD)

On-site
USD 45,000 - 65,000
Manager, Threat Detection Engineer
Manager, Threat Detection Engineer

Jobtailor • Washington

On-site
USD 140,000 - 190,000
IT Security Analyst
IT Security Analyst

Fortegra • Jacksonville (FL)

On-site
USD 85,000 - 120,000
Senior Security Analyst
Senior Security Analyst

Yardi • Santa Barbara (CA)

On-site
USD 97,000 - 110,000