Cybersecurity Vulnerability Analyst

Peraton Inc
Linthicum Heights, MD, United States
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
0 years minimum
Compensation
$104,000.0 - $166,000.0
Working hours
Regular working hours

Tech stack

Software System Penetration Testing Bash Shell Burp Suite Cascading Style Sheets (CSS) CompTIA Security+ Cyber Security Information Systems Computer Programming Digital Forensics Perl (Programming Language) Python (Programming Language) Kali Linux
+16 more
Network Protocols Open Source Technology Open Web Application Security Windows PowerShell Comptia Pentest+ CE Security Information and Event Management Software Engineering SQL Databases Software Vulnerability Management Web Applications Scripting Mitre Att&ck Cyber Threat Analysis SC Clearance Information Technology Vulnerability Analysis

Job description

Peraton is seeking a Cybersecurity Vulnerability Analyst in our Linthicum, MD office in support of our Department of Defense (DoD) customer as part of a highly talented, highly motivated, and high-performing team. This position offers a unique opportunity to work at the forefront of cyber investigations, digital forensics, cyber threat analysis, and mission support in a dynamic and collaborative environment. The successful candidate will contribute to protecting national security interests by leveraging technical expertise, analytical skills, and innovative problem-solving to address complex cyber challenges. Individuals who are passionate about cybersecurity, committed to excellence, and eager to make a meaningful impact are encouraged to apply.

This Cybersecurity Vulnerability Analyst supports a Vulnerability Disclosure Program (VDP) within the federal government and is responsible for reviewing and vetting security vulnerability reports submitted to the DoD VDP from outside hackers. The Analyst will evaluate the reports to ensure the vulnerability is reproducible and therefore valuable to the customer. They will assess each vulnerability for severity and assign an associated risk statement. The HackerOne Triage console tool will be utilized to assist in assigning and prioritizing reports. It will also assist the Analyst in helping identify duplicate submissions. Valid reports will be written in a DoD approved format and sent to the Vulnerability Management Analyst team for system owner coordination and mitigation. The Vulnerability Analyst will be a VDP liaison with the hacker community.

The Vulnerability Analyst will also: Utilize offensive toolsets such as Kali Linux to safely analyze production networks and systems, documenting steps and procedures to produce usable vulnerability assessments for the customer.

  • Identify and investigate vulnerabilities, asses exploit potential, and document findings and remedies for presentation to facilitate mitigations on customer systems.
  • Conduct web application vulnerability assessment testing using both automated tools and manual web exploitation techniques, using tools such as Burp Suite and open-source toolsets.
  • Utilize a variety of industry standard security tools to conduct automated scans against systems and applications.
  • Develop and execute proof-of-concept exploits to demonstrate the real-world impact of identified vulnerabilities, utilizing various web exploitation methods.

This position is fully on-site M-F in the Baltimore-Metropolitan area.

Requirements

  • Education: Bachelor’s degree and 5+ years of experience, or Master’s and 3+ years of experience, or PhD and 0+ years of experience. A degree in one of the following fields of study is highly desired: Information Technology, Computer Science, Cybersecurity, Information Systems, Software Engineering, or Data Science. An additional 4 years of relevant experience or specialized training may be considered in lieu of Bachelor’s degree.
  • Security Clearance: Active Secret clearance.
  • Certifications: Active IAT Level II certification (CompTIA Security+ preferred).
  • In-depth understanding of information security principles and practices.
  • Pentesting experience.
  • Utilize MITRE ATT&CK, CVSS, and NIST frameworks to assess vulnerability severity and risk impact.
  • In-depth understanding of web exploitation concepts and techniques.
  • Knowledge and understanding of the Open Web Application Security Project (OWASP) top 10.
  • Experience operating in a professional IT or cybersecurity environment.
  • Experience investigating security events, threats and/or vulnerabilities.
  • Understand information security principles, technologies and practices.
  • Excellent customer service skills.

Preferred Additional Skills:

  • CEH, CCNA-Security, CySA+, OSCP (or equivalent), PenTest+ or similar certification a plus.
  • Completed multiple Hack-The-Box penetration testing labs and challenges, developing handson expertise in vulnerability enumeration, exploitation, privilege escalation, and postexploitation techniques within realistic, adversarial environments.
  • Must possess an in-depth understanding of penetration testing methodology, including recon, exploit, persistence, etc.
  • Must have a solid understanding of networking protocols, their uses, and their potential misuses.
  • Programming experience in one or more languages, experience in HTLM/CSS or SQL.
  • Experience with one or more scripting languages such as PowerShell, Bash, Python or Perl.

About the company

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can’t be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we’re keeping people around the world safe and secure. Target Salary Range

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on diversityjobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

4:36 min

Exploiting e-commerce basket identifiers with Burp Suite

Anna Bacher · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · WWC 2023

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

Videos

See all

Related articles

See all