Job Description
Position Overview
WarCollar Industries is seeking an experienced Operator / Penetration Tester to support the National Telecommunications and Information Administration (NTIA) in conducting High Value Asset (HVA) cybersecurity assessments. The Operator will perform hands-on technical assessment activities, including security testing, vulnerability scanning, evidence collection, artifact validation, system interaction, and technical analysis.
The Operator will work under the direction of the Assessment Lead and Technical Lead while supporting the end-to-end assessment of Non-Tier 1 HVA systems. This position will have a particular emphasis on penetration testing and will lead penetration testing activities for Non-Tier 1 HVA environments.
,
Required Skills
Key Responsibilities
• Execute hands-on technical cybersecurity assessment activities in support of HVA assessments.
• Lead penetration testing activities for Non-Tier 1 HVA systems.
• Perform internal and external penetration testing designed to emulate real-world attacks and identify methods for circumventing security controls.
• Support assessment planning by preparing testing tools, scripts, methodologies, and analysis procedures.
• Conduct vulnerability scanning and technical security testing as directed by the Technical Lead and Assessment Lead.
• Perform system interaction, data capture, evidence collection, and initial technical analysis.
• Collect, validate, and analyze technical evidence supporting assessment findings.
• Extract relevant technical information from system configurations, logs, scan results, screenshots, and other assessment artifacts.
• Perform hands-on control testing and validate evidence provided by system stakeholders.
• Support network mapping, vulnerability assessments, operating system security assessments, database assessments, web application assessments, wireless assessments, and other RVA activities as assigned.
• Apply penetration testing techniques to identify vulnerabilities and weaknesses in applications, systems, networks, and security controls.
• Utilize penetration testing and network analysis tools to identify exploitable vulnerabilities.
• Apply knowledge of attack stages, system and application vulnerabilities, and social engineering techniques during authorized assessment activities.
• Support Technical Exchange Meetings (TEMs) by demonstrating systems, tools, testing methodologies, and technical evidence.
• Provide technical data, observations, screenshots, logs, and other evidence to support assessment findings and reports.
• Analyze and document penetration testing and assessment results.
• Prepare the testing results appendix for HVA assessment reports.
• Contribute technical content and findings to other sections of final assessment reports.
• Provide technical clarification and supporting information during assessment report review cycles.
• Communicate technical findings, observations, and assessment results to the Technical Lead and Assessment Lead.
• Support assessment meetings, technical discussions, status meetings, and assessment out-briefs.
• Execute assigned technical tasks in accordance with established assessment objectives, Rules of Engagement, schedules, and government requirements.
• Maintain accurate documentation of testing activities, findings, evidence, and results.
,
Desired Skills
Required Qualifications
• Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or a related field.
• Minimum of 8 years of experience in Cloud Architecture and Cybersecurity.
• Demonstrated experience conducting hands-on cybersecurity assessments, vulnerability assessments, penetration testing, or related security testing activities.
• Experience with penetration testing tools and methodologies.
• Knowledge of system and application security threats and vulnerabilities.
• Knowledge of general attack stages, including reconnaissance, scanning, enumeration, gaining access, privilege escalation, exploitation, maintaining access, and covering tracks.
• Experience conducting vulnerability scans and analyzing vulnerability and configuration data.
• Ability to collect, validate, and analyze technical evidence in support of cybersecurity assessment findings.
• Strong understanding of network security concepts and technical security controls.
• Cybersecurity, Cloud Architecture, Engineering, or similar professional certification.
• Ability to obtain and maintain a Department of Commerce Secret security clearance.
,
Additional Details
Security Requirement
This position requires a minimum of a Secret security clearance. An interim Secret clearance is acceptable to begin work, subject to applicable government requirements.
,
About WarCollar Industries
About us:
WarCollar Industries, LLC is a veteran-owned small business. We maintain a team of cybersecurity experts committed to protecting complicated data and distribution systems and providing decision makers with the most accurate assessment of residual risk possible. We work with our clients to solve the toughest challenges in the ever-evolving digital landscape. Services include network defense, computer network attack, secure network design, penetration testing and vulnerability assessment. WarCollar enables its clients to find, fix, stop, and ultimately solve cybersecurity problems across their entire enterprise.
WarCollar offers generous benefits including: Medical insurance premium coverage; PTO based on billable hours; federal holidays plus your birthday; matching 401k, education reimbursement plus paid training days; performance bonuses; referral bonuses; government shutdown protection; monthly team building events plus two major social events annually.
WarCollar Industries, LLC is an equal opportunity employer. WarCollar does not discriminate in employment based upon race, color, religion, sex (including pregnancy and gender identity), national origin, political affiliation, sexual orientation, marital status, disability, genetic information, age, membership in an employee organization, retaliation, parental status, status as a protected military veteran, or other non-merit factor.