Principal Cloud/Web Penetration Tester
Requisition ID: R10093607
-
Category: Information Technology
-
Location: Fairfax, VA, USA
-
Citizenship Required: United States Citizenship
-
Clearance Type: Top Secret
-
Telecommute: Yes-May consider hybrid teleworking for this position
-
Shift: Days (United States of America)
-
Travel Required: Yes, 25% of the Time
-
Positions Available: 1
We build the most advanced technology solutions on, and off, Earth. Our products unfold the deepest mysteries of the Universe, vanish from radar, communicate when all else fails, and drive global security. We need good people to help those missions, and many more, be successful.
If you want to be a part of that, and have what it takes, you’re a unique breed. You’re the kind of person who can’t sleep when a problem is bugging you; to solve it you’ll teach yourself a new programming language, build your own frameworks, dismantle others’ tools to bend them to your will; you’ll want to share what you’ve learned because it’s just that cool.
Northrop Grumman is seeking creative, skilled and motivated Offensive Security professionals to join our Cyber Assessment Tiger Team (CATT) to conduct full-scope penetration testing to help find the holes in critical systems, products and networks before our adversaries can. This position is on a full-time permanent corporate team supporting the enterprise, not a contracts gig, focused primarily on cloud & web application penetration.
Duties include:
- Help our engineers and developers see through the eyes of the attacker.
- As part of a larger team, conduct analysis and penetration testing of myriad internal targets.
- Continually identify & engage targets of opportunity throughout the company. Think of it as an open bug bounty
- Exploit APIs, trust relationships and coding/implementation flaws in cloud infrastructures, containers/orchestration, applications, etc.
- Develop exploits for disclosed and undisclosed vulnerabilities.
- Prepare documentation, vetting, and weaponization of vulns for team use
- Advise and contribute to the Blue Teamers’ design, development, and implementation of countermeasures.
- Work with CATT teammates to develop tools and techniques that continually improve our effectiveness.
Basic Qualifications:
- First and foremost: be passionate, curious, diligent, and hungry for knowledge.
- Grasp security fundamentals and common vulnerabilities (e.g., OWASP Top Ten, MITRE ATT&CK) plus modern web app and enterprise app vulnerabilities.
- Have a solid understanding of AWS IAM, Lambda, S3, EC2, REST, OAUTH, etc.
- Be familiar with container solutions such as Docker, Kubernetes, App2Container, OpenShift, etc.
- Have experience writing scripts and exploit code. If you can share some samples, or have public projects, even better.
- Extensive technical computer/network knowledge and understanding of computer hardware, software, networks, communications, and connectivity.
- Proficiency in both Linux/Unix and Windows operating systems
- Experience conducting adversary emulation, including social engineering, server and client-side attacks, protocol subversion, physical access restrictions, web app and backend SQL exploitation, and remote C2.
- Proficiency in multiple common programming languages such as C, C++, C#, Go, Python, Ruby, Bourne/Bash, PowerShell, Visual Basic, VBScript, PHP, JavaScript, HTML
- Eligibility for a US security clearance
Preferred Qualifications:
- Relevant certifications such as OSCP/OSWA, GPEN/GXPN
- In depth understanding of layer 2-7 communication protocols, common encoding and encryption schemes and algorithms.
- Experience countering Advanced Persistent Threat (APT) type threats to large enterprises (USG or commercial) - familiarity with techniques and tools employed.
- Previous software development to support penetration testing including vuln dev, tool creation or modification, covert tunneling, scanning scripts, passive collection, reverse engineering, binary analysis, source code analysis, etc.
- Prior experience with modern enterprise hybrid network architecture
- Understanding of and experience either executing or defending against complex, targeted cyber threats to high-value systems and data.
- Familiarity with NIST Risk Management Framework (SP 800-53x, 800-171, etc.)
- Current TS/SCI w/ Poly Clearance or eligible and willing to go through the process to get one.
The health and safety of our employees and their families is a top priority. The company encourages employees to remain up-to-date on their COVID-19 vaccinations. U.S. Northrop Grumman employees may be required, in the future, to be vaccinated or have an approved disability/medical or religious accommodation, pursuant to future court decisions and/or government action on the currently stayed federal contractor vaccine mandate under Executive Order 14042 https://www.saferfederalworkforce.gov/contractors/.
Northrop Grumman is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Opportunity/Affirmative Action Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. For our complete EEO/AA and Pay Transparency statement, please visit http://www.northropgrumman.com/EEO. U.S. Citizenship is required for most positions.
Apply Now
What's great about
Northrop Grumman
- Be part of a culture that thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work.
- Use your skills to build and deliver innovative tech solutions that protect the world and shape a better future.
- Enjoy benefits like work-life balance, education assistance and paid time off.
Did you know?
Northrop Grumman leads the industry team for NASA’s James Webb Space Telescope, the largest, most complex and powerful space telescope ever built. Launched in December 2021, the telescope incorporates innovative design, advanced technology, and groundbreaking engineering, and will fundamentally alter our understanding of the universe.
- Administrative Services
- Business Development
- Business Management
- Communications
- Engineering
- Environmental
- Facilities/Real Estate
- Flight Operations
- Global Supply Chain
- Government Relations
- Health & Safety
- Human Resources
- Information Technology
- Legal and Regulatory
- Manufacturing and Production
- Mission and Quality Assurance
- Non-CJCS
- Program Management
- Research and Sciences
- Security
- Technical Support
- alabama
- alaska
- arizona
- arkansas
- california
- colorado
- connecticut
- delaware
- district of columbia
- florida
- georgia
- hawaii
- idaho
- illinois
- indiana
- iowa
- kansas
- kentucky
- louisiana
- maine
- maryland
- massachusetts
- michigan
- minnesota
- mississippi
- missouri
- montana
- nebraska
- nevada
- new hampshire
- new jersey
- new mexico
- new york
- north carolina
- north dakota
- ohio
- oklahoma
- oregon
- pennsylvania
- rhode island
- south carolina
- south dakota
- tennessee
- texas
- utah
- vermont
- virginia
- virgin islands
- washington
- west virginia
- wisconsin
- wyoming
- Albuquerque--- NM, New Mexico
- Alice Springs--- Northern Territory, Northern Territory
- Amberley--- Queensland, Queensland
- Annapolis Junction--- MD, Maryland
- Annapolis--- MD, Maryland
- Apopka--- FL, Florida
- Aurora--- CO, Colorado
- Australia-Fortitude Valley--- Queensland, Queensland
- Azusa--- CA, California
- Baltimore--- MD, Maryland
- Beale AFB--- CA, California
- Beavercreek--- OH, Ohio
- Belle Chasse--- LA, Louisiana
- Bellevue--- NE, Nebraska
- Beltsville--- MD, Maryland
- Bethpage--- NY, New York
- Bloomington--- MN, Minnesota
- Boulder--- CO, Colorado
- Buckley AFB--- CO, Colorado
- Buffalo--- NY, New York
- Burlington--- MA, Massachusetts
- California--- MD, Maryland
- Camarillo--- CA, California
- Canoga Park--- CA, California
- Cape Canaveral--- FL, Florida
- Chandler--- AZ, Arizona
- Chantilly--- VA, Virginia
- Charlotte--- NC, North Carolina
- Charlottesville--- VA, Virginia
- Cheltenham--- Gloucestershire, Gloucestershire
- Cincinnati--- OH, Ohio
- Clearfield--- UT, Utah
- Colorado Springs--- CO, Colorado
- Commerce--- CA, California
- Corinne--- UT, Utah
- Devens--- MA, Massachusetts
- Dulles--- VA, Virginia
- East Hartford--- CT, Connecticut
- Edinburgh Parks--- South Australia, South Australia
- Edwards AFB--- CA, California
- Eielson AFB--- AK, Alaska
- El Segundo--- CA, California
- Elk River--- MN, Minnesota
- Elkridge--- MD, Maryland
- Elkton--- MD, Maryland
- Emerado--- ND, North Dakota
- Fairbairn--- Australian Capital Territory, Australian Capital Territory
- Fairfax--- VA, Virginia
- Falls Church--- VA, Virginia
- Fort Bliss--- TX, Texas
- Fort Carson--- CO, Colorado
- Fort Gordon--- GA, Georgia
- Fort Greely--- AK, Alaska
- Fort Leavenworth--- KS, Kansas
- Fort Polk--- LA, Louisiana
- Fort Riley--- KS, Kansas
- Fort Sill--- OK, Oklahoma
- Fort Worth--- TX, Texas
- Gilbert--- AZ, Arizona
- Goleta--- CA, California
- Grand Forks AFB--- ND, North Dakota
- Hollywood--- MD, Maryland
- Hopkinton--- MA, Massachusetts
- Houston--- TX, Texas
- Huntsville--- AL, Alabama
- Irving--- TX, Texas
- Iuka--- MS, Mississippi
- Jacksonville--- FL, Florida
- Kennedy Space Center--- FL, Florida
- Kettering--- OH, Ohio
- Kirtland AFB--- NM, New Mexico
- Lake Charles--- LA, Louisiana
- Langley AFB--- VA, Virginia
- Lanham--- MD, Maryland
- Lemoore--- CA, California
- Lincoln--- Lincolnshire, Lincolnshire
- Linthicum--- MD, Maryland
- London--- London, London
- Los Angeles--- CA, California
- Madison--- AL, Alabama
- Magna--- UT, Utah
- Manchester--- Manchester, Manchester
- Manhattan Beach--- CA, California
- Mayport--- FL, Florida
- McClellan--- CA, California
- McLean--- VA, Virginia
- Melbourne--- FL, Florida
- Merritt Island--- FL, Florida
- Mesa--- AZ, Arizona
- Middle River--- MD, Maryland
- Mojave--- CA, California
- Morrisville--- NC, North Carolina
- Moss Point--- MS, Mississippi
- Naval Station Mayport--- FL, Florida
- Nellis AFB--- NV, Nevada
- New Church--- VA, Virginia
- New London--- CT, Connecticut
- New Malden--- London, London
- New Town--- ND, North Dakota
- Northridge--- CA, California
- Ocean Springs--- MS, Mississippi
- Oklahoma City--- OK, Oklahoma
- Orlando--- FL, Florida
- Oxnard--- CA, California
- Palm Beach Gardens--- FL, Florida
- Palmdale--- CA, California
- Panama City--- FL, Florida
- Patuxent River--- MD, Maryland
- Philadelphia--- PA, Pennsylvania
- Pinkenba--- Queensland, Queensland
- Plymouth--- MN, Minnesota
- Point Mugu--- CA, California
- Port Hueneme--- CA, California
- Radford--- VA, Virginia
- Redondo Beach--- CA, California
- Richmond--- New South Wales, New South Wales
- Ridgecrest--- CA, California
- Riyadh--- Riyadh, Riyadh
- Rocket Center--- WV, West Virginia
- Rocklin--- CA, California
- Rolling Meadows--- IL, Illinois
- Roy--- UT, Utah
- Saint Augustine--- FL, Florida
- Saint Charles--- MO, Missouri
- Salt Lake City--- UT, Utah
- San Antonio--- TX, Texas
- San Diego--- CA, California
- San Jose--- CA, California
- Schriever AFB--- CO, Colorado
- Sicily--- Catania, Catania
- Sierra Vista--- AZ, Arizona
- Signal Hill--- CA, California
- Sigonella--- Catania, Catania
- Springfield Central--- Queensland, Queensland
- Stafford--- VA, Virginia
- Sterling--- VA, Virginia
- Stuttgart--- Baden-Wurttemberg, Baden-Wurttemberg
- Suffolk--- VA, Virginia
- Sunnyvale--- CA, California
- Sykesville--- MD, Maryland
- Symonston--- Australian Capital Territory, Australian Capital Territory
- Tampa--- FL, Florida
- Tinker AFB--- OK, Oklahoma
- Tucson--- AZ, Arizona
- United Kingdom-Home Based--- London, London
- Unknown City--- AL, Alabama
- Unknown City--- AZ, Arizona
- Unknown City--- CA, California
- Unknown City--- CT, Connecticut
- Unknown City--- Guam, Guam
- Unknown City--- HI, Hawaii
- Unknown City--- MD, Maryland
- Unknown City--- NH, New Hampshire
- Unknown City--- NJ, New Jersey
- Unknown City--- NY, New York
- Unknown City--- OR, Oregon
- Unknown City--- PA, Pennsylvania
- Unknown City--- TX, Texas
- Unknown City--- UT, Utah
- Unknown City--- VA, Virginia
- Unknown--- VA, Virginia
- Vandenberg AFB--- CA, California
- Ventura--- CA, California
- Walpole--- MA, Massachusetts
- Warner Robins--- GA, Georgia
- Warrenton--- VA, Virginia
- Washington--- DC, District of Columbia
- Whiteman AFB--- MO, Missouri
- Williamtown--- New South Wales, New South Wales
- Woodland Hills--- CA, California
- Wright-Patterson AFB--- OH, Ohio
- Yigo--- Guam, Guam
- Yorktown--- VA, Virginia
- Yuma--- AZ, Arizona