Lead Red Team Engineer jobs in United States
cer-icon
Apply on Employer Site
company-logo

State of Ohio · 2 days ago

Lead Red Team Engineer

The Ohio Department of Administrative Services (DAS) is dedicated to supporting the state's priorities and ensuring secure data and technology resources. They are seeking a Lead Red Team Engineer to identify weaknesses in the State’s security controls, conduct penetration tests, and develop offensive security solutions to enhance cybersecurity measures.

AssociationCommunitiesGovernmentNon Profit

Responsibilities

Planning exercises emulating adversaries’ operations
Identifies & uncovers misconfigurations in the State’s network
Evaluates the security of the State’s websites to discover otherwise unknown security issues
Conducts/leads penetration tests &/or coordinates with external penetration testing partners to verify vulnerabilities are exploitable
Presents findings to stakeholders & advises on corrective measures on vulnerabilities
Engineers’ offensive security solutions to exploit IT infrastructure & application weaknesses
Collaborate with other technical resources to develop & implement mitigation strategies for discovered vulnerabilities
Monitors & evaluates the effectiveness of the enterprise's cybersecurity safeguards vis-à-vis findings to ensure that findings from exercises are adequately addressed
Identifies, collects, & reports metrics related to progress, operations, & findings
Works with agencies on requests for regulatory penetration testing to ensure that their testing is adequate
Leads efforts to evaluate, recommend & implement IT security standards & best practices to remediate discovered vulnerabilities
Conducts threat or target analysis of cyber defense information & production of threat information within the enterprise
Mentors & assists junior staff

Qualification

CybersecurityPenetration testingNetwork securityVulnerability scanningTechnical writingProblem solvingCritical thinking

Required

Completion of undergraduate core coursework in computer science; 24 mos. trg. or 24 mos. exp. in computer data security either through monitoring system/network traffic for anomalous activity, systems development or controlling accessibility of data
12 mos. exp. as Enterprise Information Security Professional 1, 69981
Equivalent of Minimum Class Qualifications For Employment noted above
Job Skills: Cybersecurity, Information Technology, Problem Solving, Critical thinking
Knowledge: Computer science, computer security best practices
Knowledge: Cyber security policy development & business/IT planning
Knowledge: Network security measures, equipment & software
Knowledge: Federal statutes, laws, regulations, policies, & guidelines pertaining to computer security
Knowledge: Technical writing techniques
Knowledge: TCP/IP protocols & computer hardware systems
Knowledge: Integration of firewalls, intrusion detection/prevention systems, users' authentication systems, virtual private networks
Knowledge: Computer networking both wired & wireless
Knowledge: Disaster recovery planning
Knowledge: Security architecture
Knowledge: Division & agency policies & procedures
Knowledge: Information security program management & project management principles & techniques
Knowledge: Enterprise incident response program, roles, & responsibilities
Knowledge: Penetration testing principles, tools, & techniques
Skills: Operation of personal computer & associated hardware/software
Skills: Skill in determining how a security system should work (including its resilience & dependability capabilities) & how changes in conditions, operations, or the environment will affect these outcomes
Skills: Use of penetration testing tools & techniques
Skills: Use of social engineering techniques
Skills: Use of vulnerability scanning tools
Skills: Software development & scripting
Abilities: Interpret extensive variety of technical material in books, manuals, & network/system diagrams
Abilities: Apply techniques for conducting host & network-based intrusions using offensive security technologies
Abilities: Apply techniques for detecting host & network-based intrusions using intrusion detection technologies

Benefits

Medical Coverage
Free Dental, Vision and Basic Life Insurance premiums after completion of eligibility period
Paid time off, including vacation, personal, sick leave and 11 paid holidays per year
Childbirth, Adoption, and Foster Care leave
Education and Development Opportunities (Employee Development Funds, Public Service Loan Forgiveness, and more)
Public Retirement Systems (such as OPERS, STRS, SERS, and HPRS) & Optional Deferred Compensation (Ohio Deferred Compensation)

Company

State of Ohio

company-logo
Employment with the State of Ohio is more than ‘just a job’ – it is a privilege to serve our families, friends and neighbors who rely on us throughout our great state.

Funding

Current Stage
Late Stage

Leadership Team

leader-logo
Beverlyn Johns, MS
Deputy Chief Operating Officer
linkedin
leader-logo
Holly Drake
State Chief Information Security Officer
linkedin
Company data provided by crunchbase