Mid-level Cybersecurity Assessment Specialist - Millennium Space Systems

Boeing Boeing · Aerospace · Boulder, CO

Mid-Level Cybersecurity Assessment Specialist role at Millennium Space Systems (a Boeing company) focused on performing adversarial security testing, penetration testing, and red teaming activities on IT environments. Requires strong foundational knowledge in system administration and software development, with experience in application and network layer penetration tests, exploitation analysis, and compliance scanning (ACAS, OpenRMF).

What you'd actually do

  1. Conduct application and network layer penetration tests on various IT environments
  2. Conduct red teaming activities, including physical security penetration testing
  3. Perform independent pen testing utilizing numerous penetration testing tools and leveraging mainly manual techniques, typically testing will necessitate source code analysis
  4. Write risk prioritized finding reports, debrief system owners and consult on remediation options
  5. Retest security vulnerabilities that have been identified as fixed to verify remediation

Skills

Required

  • Active U.S. Top Secret Security Clearance with SCI eligibility
  • Bachelors degree in engineering or related technical discipline and typically 9 or more years' related work experience or an equivalent combination of technical education and experience
  • 9 or more years' experience working in Cybersecurity enclaves
  • Minimum 1 year of experience working in ISSO role
  • System administration
  • Software development
  • Application and network layer penetration tests
  • Red teaming activities
  • Physical security penetration testing
  • Penetration testing tools
  • Manual testing techniques
  • Source code analysis
  • Risk prioritized finding reports
  • Vulnerability remediation consultation
  • Retesting security vulnerabilities
  • Exploitation analysis
  • Authors exploitation tools/techniques
  • ACAS and OpenRMF compliance scans
  • Secure software development lifecycle
  • Large-scale computing environments
  • Information Security principles, policies, and industry best practices
  • Critical Security Controls (CIS)
  • Open Worldwide Application Security Project (OWASP) Top 10
  • Mitre Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) framework
  • Authentication and Authorization Controls
  • Common server applications (IIS, Apache, LDAP, Tomcat, SSH)
  • Common network protocols (HTTP/HTTPS, TCP/IP, UDP)

Nice to have

  • 3 years' experience as an ISSM
  • At least 2 years working as ISSE across multiple bases and systems for civil engineering
  • Expertise in Risk Management Framework (RMF)
  • Experience with Security Authorization (ATO) process and Program Protection Plans (PPP/PPIP)
  • Experience performing Criticality Analysis
  • Programming experience in Python, PHP, Perl, Ruby, .NET, or other interpreted or compiled languages
  • Penetrating testing and vulnerability assessments using manual techniques and vulnerability testing tools (Burp, Nmap, Kali, Metasploit)
  • Configuring and conducting automated scanning and manual testing
  • Developing security control plan implementations across 10 NIST SP 800-53 control families for ATO submission
  • Reviewing and adjudicating RMF ATO artifacts
  • Evaluating system security configurations

What the JD emphasized

  • active U.S. Top Secret Security Clearance with SCI eligibility
  • Bachelors degree in engineering or related technical discipline and typically 9 or more years' related work experience or an equivalent combination of technical education and experience
  • 9 or more years' experience working in Cybersecurity enclaves
  • Minimum 1 year of experience working in ISSO role