Cybersecurity Practitioner
Oklahoma City, OK - USA
Job Summary
Title:
Cybersecurity PractitionerKBR is seeking a Cybersecurity practitioner with experience in software development software assurance and risk management to evaluate and verify third-party software deliverables assess technical compliance reports and provide risk-mitigation recommendations for Information Technology (IT) and Operational Technology (OT) systems. The successful candidate will join a team that evaluates cybersecurity policies and implements the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) to assess authorize and monitor system risks and ultimately ensure mission success for the customer. The successful candidate will conduct Static Application Security Testing (SAST) on source code and static binary analysis on compiled executables assess scan reports to identify software weaknesses and prioritize mitigation plans and maintain various security testing tools. The successful candidate will reverse engineer commercial and custom software to identify software flaws logic defects or undocumented embedded objects. The successful candidate will leverage expertise in Development Security and Operations (DEVSECOPS) and secure coding practices to provide technical support that effectively directs system security engineering for acquisition and sustainment programs. The successful candidate will develop and maintain custom software utilities to gather computer system information consolidate logs and Security Content Automation Protocol (SCAP) results generate visual metrics and produce Continuous Monitoring (CONMON) artifacts.
REQUIREMENTS
The position requires at least three (3) years of experience in software engineering software development or a cybersecurity-related field. Candidates must demonstrate an understanding of legacy and modern programming standards secure coding principles and risk management methodologies. Within six (6) months of the assignment the candidate must possess or obtain one of the following certifications: CySA CGRC (formerly CAP) Security CISSP SSCP or CSSLP. The candidate must be familiar with secure coding and cybersecurity practices. Additionally the candidate must be able to obtain and maintain a Secret or Top-Secret security clearance.
PREFERRED: A bachelors degree in Computer Science Computer Engineering Software Engineering or Cybersecurity and at least five (5) years of experience in related engineering or cybersecurity positions. Desired qualifications include hands-on experience with ICS/SCADA systems vulnerability hunting threat analysis software reverse engineering Ghidra Binwalk hardware debugging interfaces (e.g. JTAG UART I2C). Possession of one of the following certifications: CDP CDE CEH CASE GREM or GICSP. Direct experience supporting USAF military service or military weapon systems is highly preferred. Must possess an active Secret or Top-Secret security clearance.
Belong Connect and Grow at KBR
At KBR we are passionate about our people and our Zero Harm culture. These inform all that we do and are at the heart of our commitment to and ongoing journey toward being a People First company. That commitment is central to our team of teams philosophy and fosters an environment where everyone can Belong Connect and Grow. We Deliver Together.
KBR is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race color religion disability sex sexual orientation gender identity or expression age national origin veteran status genetic information union status and/or beliefs or any other characteristic protected by federal state or local law.