Supports the United States Navy, Naval Air Warfare Center, Aircraft Division, Cyber Warfare Engineering Services. As a Red Team member, work independently to establish vulnerability research environments, assess the operational impact and understand the root-cause, and design proof-of-concept (PoC) mitigations. Responsibilities include, but are not limited to:
- Threat intelligence and research synthesis: Research open-source intelligence, web forums, and security advisories to track adversarial tactics, techniques, and procedures. Develop and contribute to internal vulnerability databases to ensure threat signatures and severity metrics are accurate.
- Vulnerability discovery and analysis: Conduct static and dynamic analysis on applications and system components. Perform source code reviews to locate logical flaws, memory corruption vulnerabilities, and cryptographic weaknesses.
- Mitigation and remediation support: Use debugging, disassembling, and binary analysis tools to reverse-engineer compiled binaries. Develop functional, stable PoC exploits to validate the severity and reachability of discovered flaws. Triage crash reports generated by automated testing tools, determine if a vulnerability is exploitable or a denial-of-service (DoS) state. Collaborate with software developers and engineering teams to design and implement robust, long-term patches.
- Technical documentation and reporting: Prepare comprehensive, clear, and actionable technical reports detailing the vulnerability, root cause, impact, and reproduction steps. Translate complex binary and code-level findings into clear risk assessments for stakeholders and system administrators.
- Other duties consistent with the statement of work.
- This is an on-site position but may be eligible for compressed work schedule.
FILLING THIS POSITION IS CONTINGENT UPON FUNDING
#LI-DH1