Emulate adversary tactics, techniques, and procedures (TTPs) to validate security controls effectiveness; develop rules of engagement, brief partners on findings and mitigation techniques. As a member of the Penetration Testing Team, perform the following tasks: • Emulate adversary tactics, techniques, and procedures (TTPs) to validate security controls efficacy • Perform penetration test assessments of DOE assets • Develop rules of engagement, and configure, tune, and operate industry standard pen test assessment tools • Coordinate, schedule, and support pen test requests • Evaluate findings to determine applicability, saturation, and potential impact • Analyze pen test reports and produce summary guidance for System Owners and administrators • Advise System Owners and Administrators of findings and provide remediation guidance • Monitor remediation efforts of findings and communicate progress to stakeholders • Work with Information System Security Officers (ISSOs) and System Owners to develop Plan of Action & Milestones (POA&Ms) or formalized exceptions to document findings • Develop, capture, and deliver summary metrics of pen test activities • Draft and deliver executive and technical briefings on pen testing related topics
We are GDIT. The people supporting some of the most complex government, defense, and intelligence projects across the country. We deliver. Bringing the expertise needed to understand and advance critical missions. We transform. Shifting the ways clients invest in, integrate, and innovate technology solutions. We ensure today is safe and tomorrow is smarter. We are there. On the ground, beside our clients, in the lab, and everywhere in between. Offering the technology transformations, strategy, and mission services needed to get the job done.
GDIT is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status, or any other protected class.