Exploit Development / Penetration Tester
Requisition ID: R10042604
-
Category: Information Technology
-
Location: Fairfax, Virginia, United States of America
-
Citizenship Required: United States Citizenship
-
Clearance Type: Top Secret
-
Telecommute: Yes- May Consider Full Time Teleworking for this position
-
Shift: 1st Shift (United States of America)
-
Travel Required: Yes, 25% of the Time
Northrop Grumman is seeking creative, skilled, and motivated Exploit Development / Penetration Tester security professional to join our Cyber Assessment Tiger Team in Fairfax, VA. The role is focused on vulnerability research, reverse engineering, and exploit development against Northrop Grumman’s systems, products & services. CATT conducts full-scope vulnerability assessment, exploit development, and penetration testing against Space Systems, Aeronautics, Mission Systems, manufacturing and enterprise IT.
To succeed, the team member must have an intense desire to exploit real production or R&D satellites, avionics, and weapons systems, and be knowledgeable in a wide range of security issues including various computing architectures, network comms protocols, programming languages and defenses.
Position conducts network or software vulnerability assessments and penetration testing, utilizing reverse engineering techniques. It perform vulnerability analysis and exploitation of applications, operating systems, or networks. Also identifies intrusion or incident path and method. Isolates, blocks or removes threat access. Evaluates system security configurations. Evaluates findings and performs root cause analysis. Performs analysis of complex software systems to determine both functionality and intent of software systems. Resolves highly complex malware and intrusion issues. Contributes to the design, development and implementation of countermeasures, system integration, and tools specific to Cyber and Information Operations. May prepare and presents technical reports and briefings. May perform documentation, vetting and weaponization of identified vulnerabilities for operational use.
Responsibilities include:
- Code analysis & hardware/binary reverse engineering to identify functionality and vulnerabilities on hardware & software including avionics and embedded systems
- Evaluate system security configurations for effectiveness and exploitation opportunities
- Develop and execute complete adversarial cyber testing scenarios against components, applications, operating systems, or complete integrated systems
- Contribute to the design, development, implementation, and integration of Offensive Cyber Operations tools against platforms, payloads & systems
- Contribute to the design, development, implementation, and integration of system Cyber Survivability Attributes
- Contribute to the preparation of technical reports and briefings
- Continually improve the knowledge and capabilities of yourself & the greater team
This position requires occasional travel within the continental United States, as well as possible international travel (up to 25% of the time). The individual will be required to work from Fairfax, VA during the interim phase of employment. However, some level of remote work may be supported after initial start period.Â
NOTE- This Evergreen requisition does not necessarily represent an actual opening. However, this requisition may be used to consider candidates across multiple technical disciplines, and/or various levels, for our future hiring needs.
Basic Qualifications:Â
- High School Diploma, or a GED, and 2 years of experience with Cyber Security, Red Team, Penetration Testing, or Exploit Development is required
- Must have software development to support penetration testing, including vuln dev, R/E tool modules, covert tunneling, scanning scripts, and passive collection
- Must have 2 years of experience in at least three (3) of the following languages: C, C++, C#, Python, Ruby, Perl, Bourne/Bash, PowerShell, Visual Basic, VBScript, PHP, Javascript, HTML
- Must be willing to travel domestically and internationally (up to 25% per year) Â
- Must have the ability to obtain, and maintain, a DOD Top Secret security clearance, as well as an SCI access level, as a condition of continued employment. Additional clearances may also be required for certain government programs
Preferred Qualifications:Â
- The ideal candidate will have a BS degree in Software Development, Computer Engineering, Computer Science, or other similar STEM related degree, to include 9 years of experience in Cyber Protection
- Technical computer/network knowledge and understanding of common computer hardware, software, networks, communications and connectivity
- Experience conducting full-scope assessments and penetration tests including:Â social engineering, server & client-side attacks, protocol subversion, physical access restrictions, and web application exploitation
- Proficiency in the internal workings of either Linux, Unix, and/or Windows operating systems
- Experience using scan / attack / assess tools and techniques
- Ability and desire to learn additional Operating Systems, Computing Architectures, and Programming languages
- Demonstrated experience in technical report writing
- Technical certifications that support pen testing such as OSCP/OSCE/OSEE, GPEN/GXPN
- Software/hardware reverse engineering for vulnerability and exploit R&D
- RTOS experience (Integrity, Nucleus, VxWorks, etc.)
- PowerPC, ARM, Xilinx FPGA, RISCx, other hardware computing development experience
- Assembly language experience (any current architecture/OS)
- TCP/IP MITM, spoofing, exploitation experience
- Platform communications protocol expertise (ARINC 429, MIL-STD-1553, Spacewire, etc.)
- Cryptanalysis and cryptosystem exploitation experience
- In depth understanding of layer 2-7 communication protocols, common encoding and encryption schemes and algorithms
- Understanding of and experience either executing or defending against complex, targeted cyber threats to high-value systems and data
- Active Top Secret, and/or SCI access with an SSBI completed within the past 4 years, is highly desirable
The health and safety of our employees and their families is a top priority. The company encourages employees to remain up-to-date on their COVID-19 vaccinations. U.S. Northrop Grumman employees may be required, in the future, to be vaccinated or have an approved disability/medical or religious accommodation, pursuant to future court decisions and/or government action on the currently stayed federal contractor vaccine mandate under Executive Order 14042 https://www.saferfederalworkforce.gov/contractors/.
Northrop Grumman is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Opportunity/Affirmative Action Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. For our complete EEO/AA and Pay Transparency statement, please visit http://www.northropgrumman.com/EEO. U.S. Citizenship is required for most positions.
Apply Now
What's great about
Northrop Grumman
- Be part of a culture that thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work.
- Use your skills to build and deliver innovative tech solutions that protect the world and shape a better future.
- Enjoy benefits like work-life balance, education assistance and paid time off.
Did you know?
Northrop Grumman leads the industry team for NASA’s James Webb Space Telescope, the largest, most complex and powerful space telescope ever built. Launched in December 2021, the telescope incorporates innovative design, advanced technology, and groundbreaking engineering, and will fundamentally alter our understanding of the universe.
- Administrative Services
- Business Development
- Business Management
- Communications
- Engineering
- Environmental
- Facilities/Real Estate
- Flight Operations
- Global Supply Chain
- Health & Safety
- Human Resources
- Information Technology
- Legal and Regulatory
- Manufacturing and Production
- Mission and Quality Assurance
- Non-CJCS
- Program Management
- Research and Sciences
- Security
- Technical Support
- alabama
- alaska
- arizona
- arkansas
- california
- colorado
- connecticut
- delaware
- district of columbia
- florida
- georgia
- hawaii
- idaho
- illinois
- indiana
- iowa
- kansas
- kentucky
- louisiana
- maine
- maryland
- massachusetts
- michigan
- minnesota
- mississippi
- missouri
- montana
- nebraska
- nevada
- new hampshire
- new jersey
- new mexico
- new york
- north carolina
- north dakota
- ohio
- oklahoma
- oregon
- pennsylvania
- rhode island
- south carolina
- south dakota
- tennessee
- texas
- utah
- vermont
- virginia
- virgin islands
- washington
- west virginia
- wisconsin
- wyoming
- APO AE, Guam
- Aberdeen Proving Ground, Maryland
- Al Udeid, Ad Dawhah
- Albuquerque, New Mexico
- Alice Springs, Northern Territory
- Amberley, Queensland
- Anchorage, Alaska
- Annapolis, Maryland
- Annapolis Junction, Maryland
- Apopka, Florida
- Arlington, Virginia
- Arlington Heights, Illinois
- Aurora, Colorado
- Australia-Fortitude Valley, Queensland
- Azusa, California
- Baltimore, Maryland
- Beale AFB, California
- Beavercreek, Ohio
- Bellevue, Nebraska
- Beltsville, Maryland
- Bethpage, New York
- Bloomington, Minnesota
- Boulder, Colorado
- Buffalo, New York
- Burlington, Massachusetts
- Camarillo, California
- Cape Canaveral, Florida
- Chandler, Arizona
- Chantilly, Virginia
- Charlotte, North Carolina
- Charlottesville, Virginia
- Cheltenham, Gloucestershire
- Cheyenne, Wyoming
- Cincinnati, Ohio
- Clearfield, Utah
- Colorado Springs, Colorado
- Commerce, California
- Corinne, Utah
- Corsham, Wiltshire
- Dallastown, Pennsylvania
- Davis Monthan AFB, Arizona
- Dayton, Ohio
- Devens, Massachusetts
- Dulles, Virginia
- East Hartford, Connecticut
- Edwards AFB, California
- El Segundo, California
- Elk River, Minnesota
- Elkridge, Maryland
- Elkton, Maryland
- Emerado, North Dakota
- Fairbairn, Australian Capital Territory
- Fairfax, Virginia
- Falls Church, Virginia
- Fareham, Hampshire
- Fort Bliss, Texas
- Fort Gordon, Georgia
- Fort Greely, Alaska
- Fort Hood, Texas
- Fort Leavenworth, Kansas
- Fort Riley, Kansas
- Fort Worth, Texas
- Fortitude Valley, Queensland
- Gilbert, Arizona
- Goleta, California
- Great Falls, Montana
- Harrogate, North Yorkshire
- Helena, Montana
- Herndon, Virginia
- Hill AFB, Utah
- Hollywood, Maryland
- Hopkinton, Massachusetts
- Huntsville, Alabama
- Hurlburt Field, Florida
- Irving, Texas
- Iuka, Mississippi
- Jacksonville, Florida
- Kennedy Space Center, Florida
- Kettering, Ohio
- Kings Bay, Georgia
- Kirtland AFB, New Mexico
- Lake Charles, Louisiana
- Langley AFB, Virginia
- Lanham, Maryland
- Las Cruces, New Mexico
- Lemoore, California
- Linthicum, Maryland
- Logan, Utah
- London, London
- Los Angeles, California
- Madison, Alabama
- Magna, Utah
- Manchester, Manchester
- Manhattan Beach, California
- Mascot, New South Wales
- McClellan, California
- McLean, Virginia
- Melbourne, Florida
- Mesa, Arizona
- Middletown, Rhode Island
- Minot, North Dakota
- Misawa, Aomori
- Mojave, California
- Monterey, California
- Moody AFB, Georgia
- Morrisville, North Carolina
- Moss Point, Mississippi
- Nashua, New Hampshire
- Naval Station Mayport, Florida
- Nellis AFB, Nevada
- New Church, Virginia
- New Malden, London
- New Town, North Dakota
- New York, New York
- Newport, Rhode Island
- Newport News, Virginia
- Norfolk, Virginia
- Northridge, California
- Ocean Springs, Mississippi
- Offutt AFB, Nebraska
- Ogden, Utah
- Oklahoma City, Oklahoma
- Orlando, Florida
- Oxnard, California
- Palm Beach Gardens, Florida
- Palmdale, California
- Patrick AFB, Florida
- Patuxent River, Maryland
- Peterson AFB, Colorado
- Philadelphia, Pennsylvania
- Pinkenba, Queensland
- Plymouth, Minnesota
- Point Mugu, California
- Port Hueneme, California
- Radford, Virginia
- Redondo Beach, California
- Redstone Arsenal, Alabama
- Richmond, New South Wales
- Ridgecrest, California
- Riyadh, Riyadh
- Rocket Center, West Virginia
- Rolling Meadows, Illinois
- Rome, New York
- Ronkonkoma, New York
- Roy, Utah
- Sacheon, Gyeongsangnam-do
- Sacramento, California
- Saint Augustine, Florida
- Saint Charles, Missouri
- Saint Rose, Louisiana
- Salt Lake City, Utah
- San Antonio, Texas
- San Diego, California
- San Jose, California
- Santa Maria, California
- Santa Rosa, California
- Schriever AFB, Colorado
- Sierra Vista, Arizona
- Signal Hill, California
- Silverdale, Washington
- Springfield Central, Queensland
- Stafford, Virginia
- Sterling, Virginia
- Suffolk, Virginia
- Sunnyvale, California
- Sykesville, Maryland
- Symonston, Australian Capital Territory
- Tampa, Florida
- Tinker AFB, Oklahoma
- Tucson, Arizona
- Unknown, Virginia
- Unknown City, Alabama
- Unknown City, Arizona
- Unknown City, California
- Unknown City, Colorado
- Unknown City, Florida
- Unknown City, Guam
- Unknown City, Illinois
- Unknown City, Maryland
- Unknown City, Massachusetts
- Unknown City, Minnesota
- Unknown City, Nevada
- Unknown City, New Jersey
- Unknown City, North Carolina
- Unknown City, North Dakota
- Unknown City, Pennsylvania
- Unknown City, Texas
- Unknown City, Utah
- Unknown City, Virginia
- Unknown City, Wyoming
- Vandenberg AFB, California
- Ventura, California
- Walpole, Massachusetts
- Warner Robins, Georgia
- Warrenton, Virginia
- West Hampton Beach, New York
- White Sands, New Mexico
- Whiteman AFB, Missouri
- Windsor Locks, Connecticut
- Woodland Hills, California
- Wright-Patterson AFB, Ohio
- Yigo, Guam
- Yorktown, Virginia
- Yuma, Arizona