- Location
- Alexandria, VA
- Type
- Full-time
- Education
- Certification
- Clearance
- Required
- Source
- ApplicantPro
Description
We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. OneZero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance. Additional details are available on our website: https://www.onezerollc.com/careers/
Position Title: Red Team Operator
Location: Alexandria, VA On Site
Clearance: TS/SCI
Program Overview:
OneZero is looking for a Red Team Operator to join our diverse team supporting the United States Coast Guard in Alexandria, Va. In this role the candidate will be responsible for engaging in Red Team assessments, utilizing Command & Control (C2) frameworks to conduct adversary simulations. This role involves standing up, managing, and maintaining attacker infrastructure, utilizing GitLab for script and tooling repositories, and applying established adversary tactics, techniques, and procedures (TTPs).
Key Responsibilities:
- Adversary Simulation:
- Deploy, configure, and operate C2 frameworks such as Cobalt Strike, Havoc, Mythic, and Sliver.
- Apply TTPs for initial access, lateral movement, privilege escalation, persistence and data exfiltration.
- Leverage proprietary and open-source offensive security tool sets effectively to achieve engagement objectives.
- Execute phishing assessments.
- Infrastructure:
- Monitor, manage, and maintain cloud and on-premise infrastructure used during assessments.
- Understanding the use of Git Repositories for maintaining operational tools and scripts.
- Penetration Testing:
- Internal and external penetration testing.
- Network mapping and enumeration.
- Assess web and mobile applications.
- Perform database scans.
- Assess Active Directory attack paths using tools such as BloodHound.
- Security Assessments:
- Assessing Coast Guard's cyber security posture of operational networks through adversary emulation.
- Develop reports and briefs detailing findings and recommendations for all assessments completed.
- Perform cyber threat emulation during scripted exercises, to train DoD Cyber Protection Teams.
Qualifications
Relevant Years of Experience: 5+
Education: BA/BS or equivalent years of relevant experience
Certifications:
- IAT II or IAT III
- GPEN, Red Team Apprentice Course (RTAC), or equivalent
Skills, & Expertise:
- Hands on experience with computers and network security.
- Experience conducting phishing campaigns or social engineering.
- Hands on experience with red team tasks and pen testing.
- Familiarity with malware development and EDR/AV bypass strategies.
- Experience with PowerShell, C, C++, or Python.
- Hands on experience utilizing Command and Control (C2) Frameworks such as Cobalt Strike, Sliver, Havoc
OneZero Solutions, LLC is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, status as a protected veteran, or any other protected category under applicable federal, state, and local laws.
To request an accommodation, please contact us at [email protected] or call (202) 987-2580.