Jobs and Careers
GU

Cybersecurity Subject Matter Expert (Pen-Testing, Red Team, Purple Team)

Guidehouse
GH Office: Tysons Corner, VA (Headquarters), United States, United Statesfull_timeVerifiedPosted 6 Feb 2025
šŸ’° $216,000/yr($130,000/yr – $216,000/yr)

About the role

Job Family:

Cyber Consulting


Travel Required:

Up to 10%


Clearance Required:

None

This posting is not for immediate hire. Seeking prospective candidate to be considered under Proposal to be award in late Q1 2025 or early Q2 2025.

What You Will Do:

We are seeking a highly skilled and experienced Cybersecurity Subject Matter Expert (SME) to join our dynamic team. The ideal candidate will have a strong background in penetration testing, red teaming, and purple teaming. This role requires a proactive individual who can identify vulnerabilities, simulate cyber-attacks, and enhance our security posture through comprehensive testing strategies.

Key Responsibilities:

Penetration Testing:

  • Conduct thorough penetration tests on networks, applications, and systems to identify security weaknesses.
  • Develop and execute test plans, document findings, and provide actionable recommendations for remediation.
  • Utilize various tools and techniques to simulate real-world attacks and assess the effectiveness of security measures.

Red Team Operations:

  • Plan and execute red team exercises to simulate advanced persistent threats (APTs) and other sophisticated attack scenarios.
  • Collaborate with blue team members to test and improve detection and response capabilities.
  • Document and present findings to stakeholders, highlighting potential risks and mitigation strategies.

Purple Team Collaboration:

  • Work closely with both red and blue teams to facilitate purple team exercises aimed at improving overall security posture.
  • Share insights and knowledge to enhance the effectiveness of defensive measures and incident response plans.
  • Foster a culture of continuous improvement and knowledge sharing within the cybersecurity team.

Security Assessments and Audits:

  • Perform regular security assessments and audits to ensure compliance with industry standards and best practices.
  • Identify and prioritize security risks, and work with relevant teams to implement corrective actions.
  • Stay up-to-date with the latest cybersecurity threats, trends, and technologies.


What You Will Need:

  • An ACTIVE and MAINTAINED Department of Energy (DOE) Q-Sensitive security clearance
  • Bachelor's degree in Computer Science, Information Security, or a related field AND FIVE (5+) plus years of post-graduation work experience in cybersecurity, with a focus on penetration testing, red teaming, and purple teaming; Or Master's degree in Computer Science, Information Security, or a related field AND THREE (3+) plus years of post-graduation work experience in cybersecurity, with a focus on penetration testing, red teaming, and purple teaming;
  • Ā Relevant certifications such as OSCP, CEH, CISSP, or similar.
  • Strong knowledge of cybersecurity frameworks, standards, and best practices (e.g., NIST, ISO 27001).
  • Proficiency with penetration testing tools (e.g., Metasploit, Burp Suite, Nmap) and red team tools (e.g., Cobalt Strike, Empire).
  • Excellent problem-solving skills and the ability to think like an attacker.
  • Strong communication and presentation skills, with the ability to convey complex technical concepts to non-technical stakeholders.
  • Ability to work independently and as part of a team in a fast-paced environment.
  • Ability to travel as required
  • Currently reside in the contiguous United States
  • This is a Hybrid role that requires the ability to work onsite in a core Guidehouse Office or Client Office location.Ā 

What Would Be Nice To Have:

  • Preference will be given to candidates within 60 miles of a core Guidehouse office or Client Office location.
  • Experience with threat hunting and threat intelligence.
  • Knowledge of scripting languages (e.g., Python, PowerShell) for automation and tool development.
  • Familiarity with cloud security (e.g., AWS, Azure) and container security (e.g., Docker, Kubernetes).

This posting is not for immediate hire. Seeking prospective candidate to be considered under Proposal to be award in late Q1 2025 or early Q2 2025.

#LI-RE1

The annual salary range for this position is $130,000.00-$216,000.00. Compensation decisions depend on a wide range of factors, including but not limited to skill sets, experience and training, security clearances, licensure and certifications, and other business and organizational needs.


What We Offer:

Guidehouse offers a comprehensive, total rewards pack

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Guidehouse

View company profile →