What are the responsibilities and job description for the Cybersecurity Testing and Evaluation Specialist position at National Security Agency?
Cybersecurity testers at NSA play a vital role in the security of NSA's mission by conducting both security controls and adversarial testing against our state-of-the-art Information Technology (IT) systems executing NSA's SIGINT and Cybersecurity missions. NSA is advancing technology to deliver mission outcomes. As such, Cybersecurity testers have the opportunity to work across a broad set of technologies including commercial cloud fabrics, artificial intelligence, high performance computing, and advanced cryptographic systems. These personnel are involved in both developmental and operational testing so NSA systems can be protected from the most sophisticated nation state adversaries. Some examples of tasks include: - Conducting security controls testing of NSA systems to ensure controls are properly implemented by system owner(s) - Conducting testing against cloud fabrics, including various security configuration options of cloud services and a wide variety of different security configurations - Assessing the effectiveness of security solutions against cybersecurity frameworks (e.g. MITRE Attack Framework) - Operating within teams focused on implementing and evolving cybersecurity testing procedures and implementing automation to reduce testing time and improve consistent analysis - Operating within a cybersecurity team for each of the life cycle steps of the Federal Government's Risk Management Framework (RMF), as maintained by the National Institute of Standards and Technology (NIST 800-53) - Implementing automation across the cybersecurity testing processes Depending on their education, training, and experience, Cybersecurity testers are hired into positions as a Testing and Evaluation Specialist and placed into functional positions performing cybersecurity testing functions commensurate with their skills. Entry-level cybersecurity professionals will take on the front-line control testing of our systems while beginning to learn the intricacies of secure system design. The most experienced testing personnel will have opportunities to formulate unconstrained cybersecurity testing to emulate cybersecurity adversary and rogue system administrator threats. Please attach a copy of your transcripts from all schools attended when applying for this position. Providing a copy of your transcripts is especially critical since the minimum qualifications for this position require a degree that demonstrates a concentration of Computer Science (CS) courses in foundational CS areas.
Job Summary
As a Cybersecurity Testing Specialist, you will apply your cybersecurity expertise to perform formal assessments mimicking real-world attacks to identify methods for circumventing security features of applications, systems, and networks. This fact-based testing, leveraging cutting-edge methodologies, will give you the unique opportunity to identify flaws and vulnerabilities in system design and influence remediations. As a Cybersecurity Testing Specialist, you will optimize and influence improvements to the protection of national security interests as part of the world's most advanced team of cybersecurity professionals. Please attach a copy of your transcripts from all schools attended when applying for this position. Providing a copy of your transcripts is especially critical since the minimum qualifications for this position require a degree that demonstrates a concentration of Computer Science (CS) courses in foundational CS areas.
Qualifications
The qualifications listed are the minimum acceptable to be considered for the position. Degree must be in Computer Science (CS) or related field (e.g., Engineering, Mathematics). Degrees in Information Technology, Information Systems, Information Security, Networking (Systems Administration), Information Assurance, and Cybersecurity may be considered relevant if the programs contain, at minimum, a concentration of courses in the following foundational CS areas: algorithms; computer architecture (not network architecture); programming methodologies and languages; data structures; logic and computation; and upper-level mathematics. Relevant experience must be in engineering of computer or information systems over their lifecycle (i.e., requirements analysis, design, development, implementation, testing, integration, deployment/installation, and maintenance), programming, vulnerability analysis, penetration testing, computer forensics, and/or systems engineering. Completion of military training in a relevant area such as JCAC (Joint Cyber Analysis course) will be considered towards the relevant experience requirement (i.e., 24-week JCAC course will count as 6 months of experience). ENTRY/DEVELOPMENTAL Entry is with a Bachelor's degree and no experience. An Associate's degree plus 2 years of relevant experience may be considered for individuals with in-depth experience that is clearly related to the position. FULL PERFORMANCE Entry is with a Bachelor's degree plus 3 years of relevant experience or a Master's degree plus 1 year of relevant experience or a Doctoral degree and no experience. An Associate's degree plus 5 years of relevant experience may be considered for individuals with in-depth experience that is clearly related to the position.
Competencies
Skills: We're looking for someone with knowledge, skills, and experience in one or more of the following: - Cloud Security Knowledge for commercial cloud environments such as Amazon Web Services, Microsoft Azure, Oracle or Google cloud environments - Knowledge of or experience with penetration testing or ethical hacking methodologies - Knowledge of network attacks based on MITRE Attack Framework - Familiarity with exploitation techniques and frameworks (network firewalls, intrusion detection systems, networks) - Familiarity with various exploitation frameworks (e.g. Metasploit) - Understanding of shell scripting for the development of network attack tools and techniques (e.g. Python, Perl, or Ruby) - Knowledge of vulnerability identification, mitigations, and countermeasures - Understanding of network protocols - Knowledge of Windows / Linux network programming - Knowledge of network architecture, network and IT infrastructure devices, physical and virtual - Understanding of tools (nmap, nessus, dsniff, libnet, netcat, network sniffers) and techniques (e.g. fuzzing) - Understanding of threat modeling and development of test scenarios - Critical thinking and ability to break large complex problems into manageable parts Experience and knowledge of computer security tools, vulnerability analysis, systems architecture, systems engineering, test and evaluation tradecraft, and software engineering is helpful. Working knowledge of automation tools and Linux is helpful. The ideal candidate is someone with a desire for experiential learning and strong problem-solving, analytic and interpersonal skills who is: - willing to take the initiative - innovative - able to work effectively across several different functional areas in a collaborative environment - able to communicate effectively (both orally and written) - well-organized and able to handle multiple assignments.
Pay, Benefits, & Work Schedule
Pay: Salary offers are based on candidates' education level and years of experience relevant to the position and also take into account information provided by the hiring manager/organization regarding the work level for the position. Salary Range: $86,498 - $151,570 (Entry/Developmental, Full Performance) Salary range varies by location, work level, and relevant experience to the position. Training will be provided based on the selectee's needs and experience. Benefits: NSA offers a comprehensive benefits package. Work Schedule: This is a full-time position, Monday - Friday, with basic 8hr/day work requirement between 6:00 a.m. and 6:00 p.m. (flexible). DCIPS Trial Period: If selected for this position, you will be required to serve a two-year DCIPS trial period, unless you are a veterans' preference-eligible employee, in which case you are required to serve a one-year trial period. This trial period runs concurrently with your commitment to the position, if applicable. Before finalizing your appointment at the conclusion of your trial period, NSA will determine whether your continued employment advances the public interest. This decision will be based on factors such as your performance and conduct; the Agency's needs and interests; whether your continued employment would advance the Agency's organizational goals; and whether your continued employment would advance the efficiency of the Federal service. Upon completion of your trial period, your employment will be terminated unless you receive certification, in writing, that your continued employment advances the public interest. If you do not receive certification for continued employment, you should receive written notice prior to the end of your trial period that your employment will be terminated and the effective date of such termination.
How to apply
The following four narrative questions provide an opportunity for you to highlight your dedication to public service for the hiring manager and agency leadership (or designee(s)). While your responses are not required and will not be scored, we encourage you to thoughtfully address each question. Please provide a response of 200 words or less to each question. You will be asked to certify that you are using your own words and did not use a consultant or artificial intelligence (AI) such as a large language model (LLM) like ChatGPT or Copilot. (Please attach in application)
1. How has your commitment to the Constitution and the founding principles of the United States inspired you to pursue this role within the Federal government? Provide a concrete example from professional, academic, or personal experience.
2. In this role, how would you use your skills and experience to improve government efficiency and effectiveness? Provide specific examples where you improved processes, reduced costs, or improved outcomes.
3. How would you help advance the President's Executive Orders and policy priorities in this role? Identify one or two relevant Executive Orders or policy initiatives that are significant to you, and explain how you would help implement them if hired.
4. How has a strong work ethic contributed to your professional, academic or personal achievements? Provide one or two specific examples, and explain how those qualities would enable you to serve effectively in this position.
Apply soonest, as job postings can close earlier than stated end dates due to changes in requirements. It is important to review and note the minimum qualifications, as only those applicants who meet the required qualifications will be contacted to continue the employment process. Please populate the resume tool to showcase any relevant work experience and education related to the position and answer any applicable screening questions. Information collected will be used to determine eligibility, and failure to provide accurate information may result in disqualification for this position.
A confirmation email will be sent after submission of the first application and also after any future updates to submitted applications. **Due to time sensitive communications regarding applications, please ensure your spam filters are configured to accept email from noreply@intelligencecareers.gov. For job vacancies that include stated testing requirements, also include the following: @uwe.nsa.gov, @nsa.gov, and @pearson.com**
U.S. Citizenship is required for all applicants. NSA is an equal opportunity employer and abides by applicable employment laws and regulations. All applicants and employees are subject to random drug testing in accordance with Executive Order 12564. Employment is contingent upon successful completion of a security background investigation and polygraph. Reasonable accommodations may be provided to applicants with disabilities during the application and hiring process where appropriate.
DCIPS Disclaimer
**VETERANS AND TRANSITIONING SERVICE MEMBERS** Thank you for your service! The National Security Agency (NSA) is part of the Defense Civilian Intelligence Personnel System (DCIPS). All positions at NSA are in the Excepted Service under Title 10, United States Codes (U.S.C.), Section 1601 appointment authority. Veterans' Preference In accordance with the procedures provided in DoD Instruction 1400.25, Volume 2005, "DoD Civilian Personnel Management System: Defense Civilian Intelligence Personnel System Employment and Placement," NSA applies veterans' preference, as defined by Section 2108 of Title 5, U.S.C., to eligible candidates. If you are claiming veterans' preference, you are required to provide acceptable documentation of your preference eligibility upon application. Acceptable documentation includes: - DD-214: "Certificate of Release or Discharge from Active Duty," which shows dates of service and discharge under honorable conditions (Copy 4); OR - Certification of Service: A written document on letterhead from the appropriate branch of the armed forces that certifies the service member is expected to be discharged or released from active duty service in the armed forces under honorable conditions not later than 120 days after the date the certification is signed. The certification should include the military service dates, including the expected discharge or release date; AND - Standard Form 15 (SF-15) Application for 10-point Veteran Preference (http://www.opm.gov/forms/pdf_fill/sf15.pdf). If you are claiming a service-connected disability of 30 percent or more, the documentation you provide must specifically demonstrate this level of disability; AND - VA Letter of Disability (for 10pt and Sole Survivorship rating) You may obtain a letter from the Department of Veterans Affairs reflecting your level of disability for preference eligibility by visiting a VA Regional Office, contacting a VA call center, or online (https://www.ebenefits.va.gov/). **Failure to provide sufficient documentation of veterans' preference eligibility may preclude NSA from identifying you as a preference eligible candidate during the hiring selection process.
Salary : $86,498 - $151,570