This is a full-time position, and requires a TS/SCI/Full Scope Polygraph Clearance.
2HB Incorporated is seeking a Software Engineer to support its government customer in Annapolis Junction, MD.
- The ideal candidate will perform Software Engineering and vulnerability research with a focus on OCO (Offensive Cyber Operations) and DCO (Defensive Cyber Operations) activities.
- Work with customers directly performing full cycle system engineering, gathering requirements and source code, to technical documentation and specifications.
- Performing long term, in depth vulnerability assessments using reverse engineering, kernel debugging, and exploitation technologies.
- Engineers are encouraged to be creative and exhaust every technical avenue to uncover weaknesses of the system and exploit them.
- Performs software development tasks and assists in the design and architecture of software applications individually or as a team member
- Develops production quality software based on pre-defined software requirements and designs
- Reviews, analyzes, and modifies programming systems to include coding, testing, debugging, installing, and documenting to support organizations software applications
- Implements software development process improvement activities in accordance with organizational procedures
- Develops unit and integration tests and test plans for software applications and prepares software test reports
- Writes documentation for software and software interfaces
Required Qualifications
- High School and Seven [7] years experience in software development technologies and methodologies.
- Or BS in STEM field (Electrical/Computer/Software Engineering, Computer Science, Math or Information Systems) and Three (3) year of experience in software development technologies and methodologies.
- C/C++ Software development skills
- Experience in x86/x64 assembly, software reverse engineering, kernel debugging, and protocol stacks
- Experience developing computer exploits
- TS/SCI with Full Scope Polygraph, current CI under 6 yrs
Preferred Technical Skills:
- Experience in Software Reverse Engineering with at least 1 of the following tool or an equivalent: IDAPro, GDB, WinDbg, Immunity/OllyDbg
- Experience in malware analysis and mitigation techniques
- Strong understanding of the Windows and Linux Operating System internals and APIs
- Knowledge of analyzing shellcode, packed and obfuscated and the associated algorithms a plus
- Experience with scripting languages such as Python, Bash, Pearl, etc
- Experience in host and network analysis to identify and characterize anomalies and vulnerabilities in the platform
- Experience documenting findings in reports and briefing
- Provide systems engineering/cybersecurity support to weapons and space cybersecurity assessments
- Agnostic of threat, help translate adversarial mindset, threat intelligence into actionable mitigations within possible areas of CNO and CND (Computer Network Defense), System design, Network architecture / administration, Continuity of Operations.
- Evaluate different vulnerability findings and determine conceptual mitigations / next steps
- Support Risk Management and other business process frameworks to close the gap between technical and non-technical understanding of threats/vulnerabilities
- Ensure that evaluation/mitigation techniques are technically sound. Ensure the technical solution articulates the mission impact and threat effectively
Qualifications
- The System Engineer shall have a minimum of eight [8] years of experience (BS in STEM related field will account for 4 years)
- Experience with Cybersecurity / System Engineering and vulnerability analysis.
- Experience with prioritization of vulnerabilities and understanding of mission impacts
- System Engineering of DoD command, control, communications and intelligence (C3I) systems
- Analyzing needs, deriving system level requirements, and contributing to the design, development, and implementation and maintenance of computer networks and systems
Preferred
- Familiarity with weapons systems or large scale systems
- Working knowledge of the DoD Information Network (DODIN), DoD IT system and network certification and accreditation processes (i.e., RMF), to include system security authorization agreements and current and emerging cybersecurity threats
- Zero Trust preferred
- Possess working knowledge of DoD’s IT systems and network certification and accreditation processes to include system security authorization agreements
This is a full-time position, and requires a TS/SCI/Full Scope Polygraph Clearance.