cFocus Software Incorporated · 1 month ago
Navy - Advanced Red Team Operator - TS/SCI Required
cFocus Software seeks an Advanced Red Team Operator to join our program supporting the Department of Defense (DoD). This role involves leading red team operations, conducting penetration testing, and ensuring compliance with cyber testing standards and procedures.
ChatbotGovernmentInformation TechnologySoftware
Responsibilities
Review and become proficient in OPTEVFOR cyber T&E concept of operations, SOPs, policies and guidance
Maintain and participate in the development of 01D SOPs and documentation for DCAT authorization established in DoDI 8585.01
Research, review, prioritize, and submit operational requirements for acquisition of equipment or cyber capabilities, following the 01D tool approval process
Support development and execution of TTPs for penetration testing or Red Teaming
Research adversary cyber actors’ TTPs, organizational structures, capabilities, personas, and environments, and integrate findings into cyber survivability test planning and execution
Conduct open-source research and system under test documentation review to familiarize with the system’s mission, architecture and interfaces including critical components to identify its attack surface and threat vectors
Participate in checkpoint meetings
Guide development of test plan objectives
Review test plans, ensuring that test plans objectives are feasible
Participate in test planning site visits
Participate in site pre-test coordination visits. Support in-brief to the test site
Lead red team test plan review
Add relevant system technical information to test reference library
Organize and lead research presentations for advanced capability development in support of future tests
Prepare OPTEV-RT test assets (Government Furnished)
Execute test events, including Cooperative Vulnerability Penetration Assessments, Adversarial Assessments, and Cyber Tabletops, in support of Operational Testing, Developmental Testing, risk reduction events, or other events, as assigned
Use OPTEVFOR provided and NAO approved commercial and open-source network cyber assessment tools (e.g. Core Impact, Nmap, Burp, Metasploit, and Nessus)
Employee ethical hacking expertise to exploit discovered vulnerabilities and misconfigurations associated with but not limited to operating systems (Windows, Linux, etc.), protocols (HTTP, FTP, etc.), and network security services (PKI, HTTPS, etc.) to accomplish test objectives
Be able to accomplish testing independently and provide direction to basic and intermediate operators
Ensure tests are conducted safely, in accordance with the test plan, and OPTEVFOR policies are adhered to
Follow Joint Forces Headquarters (JFHQ)-DODIN deconfliction procedures
Verify collected data for accuracy and completeness
Participate in the post-test iterative process, including generation of documents (e.g. deficiency/risk sheets)
Document lessons learned
Participate in capture the flag events, cyber off sites, external engagements such as red team huddles and red team technical exchange meetings; develop required products and materials in support of these events
Attend OPTEVFOR required meetings in support of OT&E
Generate and update documentation to maintain DCAT authorization compliance per DoDI 8585.0
Qualification
Required
Minimum 6 years' experience performing any combination of: penetration testing, red teaming, or exploitation development
Minimum 6 years' with proficiency in leading red team operators in penetration testing/red teaming to accomplish assigned test objectives
Ability to obtain a TS/SCI clearance
Company
cFocus Software Incorporated
cFocus Software automates FedRAMP compliance and develops government chatbots for the Azure Government Cloud, Office 365, and SharePoint.