RPI Group Inc
Security Software Engineer – Red Team Penetration Tester
$110,000 to $150,000 a year
About the job
Position Title: Security Software Engineer – Red Team Penetration Testers
Salary Range: $110,000 to $150,000 Annually
Location: Dahlgren, VAAbout the Role
RPI Group is seeking a skilled, driven Security Software Engineer to support Red Team penetration testing for a mission-focused Navy customer. If you are energized by complex technical challenges, enjoy finding and analyzing security weaknesses, and want your work to inform real-world defensive decisions, this role is for you.What We’re Looking For
• Five (5) Years experience in:• Linux – firm grasp/demonstrated knowledge
• Associated Training: COMPTIA Linux+ or FedVTE Linux+
• Five (5) Years experience in:
• Windows – foundational knowledge with good understanding of enterprise networks
• Associated Training: Microsoft course (MCSA; Various)
• Strong working knowledge of common Penetration Testing (PENTEST) tools:• Kali, Metasploit, NMAP, Cobalt Strike
• Associated Training: Certified Ethical Hacker or Offensive Security Certified Professional and;
• Documented experience in at least one of the following:
• Penetration Testing (PENTEST) (government or contractor)
• Red Team Operations (government or contractor)
• Tool/Software Development (exploits/malware, C2, reverse engineering, bug bounties)
• Python, C, C Sharp, C++, Go, Perl, Powershell
• Web Dev/Web App Dev/Web Penetration testing
• • • NSX, vCenter, vRealize Suite, Horizon View (VDI) and others
• PAN-OS
• FirePower, Nexus, IOS, ASA
• ONTAP, SnapMirror
• Active-Directory
• Entra ID (Azure AD), Active Directory, SSO, MFA, Azure application integration, Identity Federation.
• Automation using Powershell, PowerAutomate, Logic Apps, Graph API.
• Microsoft Entra ID and Microsoft 365 in a hybrid environment.
• Experience with Palo Alto, Cisco, VMWare, NetApp and Microsoft products.
• Extending or integrating on premises AD with Entra ID.
• Managing identity and access in Microsoft Entra ID.
• Experience conducting Red Team operations in an MDE environment.
• Experience with AWS, Cloud Audit, Serverless and Microservice Architecture
• Experience working with AWS services (such as EC2, S3, KMS, RDS) and security best practices relevant to those services
• Experience with Web Services penetration testing (RESTful and SOAP) Web Authentication protocols (e.g. OAuth2, SAML, LDAP)
• PHP, ASP, SQL db's, Java, HTML, No SQL
• Minimum certification as IAT Level II per DoD 8570.01, or successor.
• Must possess an active Offensive Security Certified Professional (OSCP) certification at a minimum. OSCP is a required qualification for this position.
• Additional penetration testing, offensive security, or red team certifications and experience may include:
• Offensive Security certifications: Offensive Security Certified Expert (OSCE), Offensive Security Exploitation Expert (OSEE), Offensive Security Wireless Professional (OSWP)
• SANS certifications/courses: SEC560 – Network Penetration Testing and Ethical Hacking (GPEN), SEC542 – Web App Penetration Testing and Ethical Hacking (GWAPT), SEC660 – Advanced Penetration Testing, Exploit Writing, and Ethical Hacking (GXPN), SEC642 – Advanced Web App Penetration Testing and Ethical Hacking, SEC564 – Red Team Operations and Threat Emulation
• OSD-sponsored Cyber Operations Academy Course (COAC) graduate
• Capture the Flag (CTF) participation, including DEF CON, OverTheWire (OTW), Hack The Box, or USS Secure CTFs
• Security research resulting in a Common Vulnerabilities and Exposures (CVE) publication
• Possess the ability to:
• Debug and reverse engineer software.
• Analyze Windows Events and Linux syslog's, boot logs and dmesg logs.
• Program and debug Web 2.0, Java, Perl, Ada, C++, Tool Command Language (tcl/tk) scripts and graphical user interfaces (GUis) using Microsoft Visual tel and Rational ClearCase for software configuration management.
• Program and debug Web 2.0, Java, Perl, Ada, C++, Tool Command Language (tcl/tk) scripts and graphical user interfaces (GUis) using Microsoft Visual tel and Rational ClearCase for software configuration management.
• Recommend software modifications to systems to mitigate known vulnerabilities. Operate and administrate computer systems running HP-UX, UNIX, Solaris, Linux and Microsoft Windows.
• Identify security flaws in compiled and human readable source code. Understand code utilizing real-time VxWorks and Lynx OS operating systems, Common Object Resource Broker Architecture (CORBA), firewalls and networking protocols.
• Understand how to implement NSA approved encryption technologies and devices. Apply DISA Security Technical Implementation Guides (STIGs).
• Apply virtual hosting and server technology in system architectures. Understand and apply the concept of deceptive technology such as honey pots in system architectures.
• Participate in Code Reviews. Perform Static Source Code Analysis. Author recommendations for improving software and code design.
• Contribute to a System Security Administrator and Operators Manual (SSAOM)
• Must be a U.S. Citizen and Possess an Active Security Clearance
RPI Group, Inc. is an Equal Opportunity Employer, including individuals with disabilities and protected veterans.