Cybersecurity EngineerTampa, FL

BuddoBot Inc.
Tampa, United States of America
15 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior

Job location

Tampa, United States of America

Tech stack

Amazon Web Services (AWS)
Software System Penetration Testing
Azure
Cloud Computing
Computer Security
Computer Forensics
Fiddler (Software)
Systems Analysis
Intrusion Detection and Prevention
Network Security
Open Source Technology
Reverse Engineering
Secure Coding
Security Information and Event Management
Software Engineering
Wireshark
Software Vulnerability Management
Mitre Att&ck
Malware
Cyber Threat Analysis
Gitlab
Containerization
Kubernetes
Information Technology
Purple Team (Cyber Security)
Encase
Devsecops
Vulnerability Analysis
Microservices

Job description

  • Leading and managing advanced security assessments, providing strategic guidance and oversight for the design, development, and execution of internal purple team exercises that align to the MITRE ATT&CK framework
  • Driving the deployment of secure IT infrastructure and cybersecurity services, utilizing both commercial and open-source security assessment tools to proactively address and remediate identified security gaps
  • Serving as a primary consultant for strategic threat modeling, incorporating TTP libraries of key adversaries to identify methods to detect emerging cyber threats and evolving attack methods
  • Acting as a key liaison and interacting with other Security and Engineering pillars to foster operational communication and collaborate on the ongoing cATO (continuous authority to operate) process for secure development
  • Managing and producing high-quality deliverables, including the thorough documentation of purple team assessment processes, results, and remediation efforts to provide clear status updates to stakeholders
  • Demonstrating creative thinking and superior problem-solving skills in complex environments, particularly when employing advanced forensic tools and techniques for attack reconstruction and post-incident analysis
  • Communicating in an organized, knowledgeable, and persuasive manner, both in written and verbal formats, ensuring quality assurance and the spreading of cybersecurity best practices across the organization
  • Identifying and proactively addressing client security needs, displaying the ability to contribute to a resilient threat defense vision and effectively manage implementation efforts
  • Managing and/or contributing significantly to project planning, execution, and reporting of incident responses, malware analysis, and vulnerability mitigation.

Requirements

Dark Wolf is seeking a highly motivated and experienced Senior Cybersecurity Specialist to lead advanced threat detection, vulnerability assessment, and adversarial simulation initiatives. The ideal candidate will be an expert in adversarial Tactics, Techniques, and Procedures (TTPs) and possess a proven track record of designing and executing internal purple team exercises aligned to the MITRE ATT&CK framework. This role demands a deep understanding of the DevSecOps lifecycle, including secure cloud deployments and continuous Authority to Operate (cATO) processes, along with the ability to effectively communicate assessment results to internal and external customers. You will be a critical part of a team dedicated to modernizing and securing software development and delivery capabilities for our clients., * 5+ years of experience in three or more specific areas to include: networking security, penetration testing tools, red teaming, vulnerability assessment tools, and SIEM threat detection

  • Strong technical proficiency with cloud technology and deployments (Amazon Web Services, Microsoft Azure) and familiarity with container technologies, including container orchestration (Kubernetes) and microservices
  • Proven experience conducting research and identifying methods to detect emerging cyber threats, attack methods, and evolving Tactics, Techniques, and Procedures (TTPs)
  • Strong understanding of organizational threat modeling and the ability to map exercises and detection methods directly to the MITRE ATT&CK framework
  • Proficiency with commercial and open-source security assessment tools, along with a deep understanding of secure development practices and the cATO process
  • Demonstrated strong written and verbal communication skills, with the ability to document complex technical assessment processes and results for internal and external customers
  • DOD 8570 IAT 3 Compliant (e.g., CISSP, CASP+, or equivalent)
  • US Citizenship and currently possess an active security clearance (clearable up to TS/SCI as required by client environments), * OSCP, CEH, CISSP, CKS, GCIH, GPEN, or equivalent technical certifications
  • Experience employing advanced forensic tools and techniques for attack reconstruction (including dead system analysis and volatile data collection/analysis) and familiarity with tools such as Wireshark, Fiddler, EnCase, and Sleuthkit
  • Prior Law Enforcement or Cyber Forensics experience, specifically in performing post-incident computer forensics without destruction of critical data
  • Direct experience in Malware Analysis and Reverse Engineering
  • Hands-on experience with DevSecOps practices, Helm, GitLab, and Kubernetes (K8s)
  • Desired experience ensuring quality assurance, establishing operational communications, and spreading security best practices across engineering teams.

Apply for this position