Назад
Company hidden
26 дней назад

Cybersecurity Engineer (Offensive Security)

96 000 - 130 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Cybersecurity Engineer (Offensive Security): Evaluating mission-critical systems, networks, products, and embedded devices through vulnerability assessments, penetration testing, and security validation with an accent on attack-surface analysis, CVE assessment, and practical remediation. Focus on developing repeatable security-testing methods, validating controls and remediation, and supporting critical infrastructure and air-traffic-control programs.

Location: On site at the Frederick, Maryland facility, United States

Salary: $96,000–$130,000 total annual compensation

Company

Rohde & Schwarz is a global technology company developing solutions across test and measurement, technology systems, networks, and cybersecurity for business, government, and public-sector customers.

What you will do

  • Perform vulnerability assessments and authorized penetration tests across systems, networks, applications, operating systems, COTS products, appliances, and embedded devices.
  • Analyze attack surfaces, trust boundaries, data flows, authentication mechanisms, exposed services, CVEs, and vendor security advisories.
  • Produce technical findings, risk ratings, remediation recommendations, assessment reports, and supporting evidence.
  • Track vulnerabilities throughout the system lifecycle, validate remediation, and improve repeatable testing, evidence-collection, and reporting methods.
  • Support security testing, architecture reviews, threat modeling, incident response, forensic analysis, customer deployments, and acceptance testing.
  • Collaborate with cybersecurity, product, engineering, and R&D teams in North America and Europe, initially supporting Air Traffic Control programs.

Requirements

  • Must work on site at the Frederick, Maryland facility.
  • Must be a U.S. citizen or permanent resident able to obtain an interim or final suitability determination.
  • Bachelor’s degree in cybersecurity, computer science, engineering, information systems, or a related technical field; a master’s degree is preferred.
  • 7+ years of relevant experience in cybersecurity, penetration testing, vulnerability management, network security, or security engineering.
  • Strong knowledge of vulnerability assessment, penetration testing, attack methodologies, remediation, TCP/IP networking, routing, switching, VLANs, firewalls, network segmentation, Linux, and Windows security.
  • Experience with tools such as Nessus, Nmap, Wireshark, Burp Suite, Metasploit, or comparable tools, plus analysis of CVEs, scan results, and technical findings.

Nice to have

  • Experience with NIST SP 800-53, NIST CSF, DISA STIGs, CIS Benchmarks, or similar frameworks.
  • Experience in laboratory or controlled test environments and with mission-critical, safety-critical, aviation, transportation, defense, or critical infrastructure systems.
  • Knowledge of VoIP/SIP/RTP, RF communications, embedded systems, PLCs, appliances, or related technologies.
  • Certifications such as OSCP, GPEN, GCIH, GWAPT, PNPT, CISSP, or Security+.
  • Scripting experience with Python, PowerShell, Bash, or similar languages.

Culture & Benefits

  • Work within a U.S. cybersecurity organization supporting mission-critical products and customer programs.
  • Collaborate with international cybersecurity, product, and engineering teams.
  • Total compensation includes base salary, variable pay when applicable, and benefits.
  • Support programs across cybersecurity, technology systems, networks, and communications.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →