CLEARANCE LEVEL: TS/SCI
US CITIZENSHIP: Required
JOB CLASSIFICATION: Full-time
LOCATION: Lackland, AFB (San Antonio, TX)
YEARS OF EXPERIENCE: 5-7 years
EDUCATION LEVEL: BS Degree
WHAT MAKES THIS A GREAT OPPORTUNITY:
An exciting opportunity in San Antonio, TX, to work full-time assisting a law enforcement/counterintelligence organization in conducting Interactive On-Net (ION) investigations/operations. The selected candidate will join a small, talented, highly effective performing team providing cyber threat identification and pursuit expertise to address the unique challenges faced in global cyber investigations and operations. GITI is looking for a motivated, talented, and creative ION operator with experience in conducting sophisticated and effective cyber threat cyber threat discovery, collection, analytical, and pursuit operations to join our team!
BRIEFLY DESCRIBE THE WORK:
Global InfoTek Inc., is looking for an experienced Interactive On-Net (ION) Operator to assist in threat discovery and pursuit for a cyber investigations division of a law enforcement/counterintelligence agency. A successful candidate will have experience, skills, and a creative talent to operate effectively alone or within a small team environment to help protect critical cyber infrastructure from evolving cyber threats and nefarious actions from adversaries.
- Conduct interactive on-net operations to gather data from adversary information systems and networks
- Use open-source and proprietary tools for network navigation, tactical forensic analysis, and intelligence collection
- Assist in the development of exploitation capabilities against known and newly identified targets; inform and refine operational requirements for new tools
- Assess multiplex challenges and work with a diverse team to quickly meet evolving mission requirements
- Assess multiplex challenges, develop, and support the development of cyber tools to solve complex problems, support on-net operational needs, and working with a diverse team to quickly meet evolving mission requirements.
- Modify existing tools to fit changing operational needs and achieve highly technical objectives
- Provide full-stack development, build user-facing services, middleware, and backend systems
- Develop documentation and provide training for tool use
REQUIRED SKILLS:
- Graduate of the Future Operator Readiness, Growth and Enrichment (FORGE), or a graduate of the Offensive Security Certified Professional (OSCP), or a graduate of the Remote Interactive Operator Training
- Three years of pen-testing/red teaming experience within the last five years, and at least six years of technical analysis, military intelligence, DNI, SIGINT analysis, or similar
- Strong understanding of system administration (Windows and *nix), analysis, and manipulation, including startup programs, system configuration files, common executable files, and logging capabilities
- Solid familiarity with networking analysis and manipulation, including network stack, ports, protocols, tunneling, routing concepts, firewalls, VPNs, proxy servers, and network mapping
- Established knowledge of hacker and pen-testing methodologies such as host enumeration, exploitation, privilege escalation, persistence, and effects
- Robust understanding of detection evasion (antivirus, IDS/IPS, and other personal security products) and other post-operation steps
- Ability to assist in the development and adaptation of exploits for operating systems, applications, and services to fit operational needs
- Three years of software engineering or programming experience within the last five years, and at least six years of development experience.
- Proficiency in two or more programming or scripting languages such as C, C++, Java, Assembly, Python, Perl, Ruby, Bash, Node.js, Spark, Puppet, SALT, KAFKA, HADOOP, etc.
- Knowledge of x86/64, ARM, and MIPS instruction sets and architectures
- Skilled at simulation/model development and prototyping
- Proficiency with software debuggers using tools such as WinDbg, OllyDbg, GDB, KGDB, NTSD, or other similar tools
- Strong technical writing skills
DESIRED SKILLS:
- Bachelors or master's degree in computer science, software engineering, cybersecurity, or related discipline from an accredited institution in addition to the required experience
- Certifications such as SANS' GXPN, GAWN, GPYC, GIAC's GPEN; Offensive Security OSCP, OSWE, OSCE, OSEE, EC-Council's CEH, APT, LPT, CompTIA's PenTest+, CASP+, Cisco's CyberOps, CCNA, CCNP, or others
- Experience with Python, PowerShell, or other scripting languages to automate operational requirements
- Ability to develop and adapt exploits for operating systems, applications, and services
GLOBAL INFOTEK, INC. is an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.
ABOUT GLOBAL INFOTEK, INC. Reston, VA-based Global InfoTek Inc. is a woman-owned small business with an award-winning track record of designing, developing, and deploying best-of-breed technologies that address the nation's pressing cyber and advanced technology needs. For more than two decades, GITI has merged pioneering technologies, operational effectiveness, and best business practices to rapidly provide low-cost, agile solutions to DoD, DHS, and IC customers. In addition to its Reston office, GITI has operations in San Antonio, TX, Colorado Springs, CO, and Rome, NY.