Cyber Capability Developer, Senior
TekSynapAbout the role
Responsibilities & Qualifications
ACTIVITIES & RESPONSIBILITIES
The Customer Security Assessment Services (CSAS) provides continuous security monitoring, software engineering, and software analysis services for the Government Customer Systems and services. Through Security Assessments & Authorizations and continuous security monitoring, CSAS ensures ongoing awareness of the confidentiality, integrity, and availability of the Government Customer information and the Government Customer information systems. The CSAS conducts comprehensive, formal, independent assessment of the management, operation, and technical security controls of the Government Customer System to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the Government Agency security requirements. These assessments serve as a key input into the Government Agency risk management program and to the continuous monitoring of the security of the Government Customer systems and services. Utilizing an extensive variety of automated vulnerability assessment tools and techniques, CSAS continuously accesses security on large and complex variety of operating systems (OS), databases, web applications and services, appliances, network devices, and numerous other applications and devices. CSAS facilitates security monitoring, software engineering, and software analysis services. CSAS includes a system that consists of multiple cloud-hosted security tools to enable software, platform, and infrastructure security assessments and monitoring. These tools are critical to enabling the CSAS team and CIAU to perform security assessments and continuous monitoring of the Government Customer systems and software including identification of software security vulnerabilities; security analysis of source code and open source software; identification of security misconfigurations; and vulnerability assessment of infrastructure-as-code; and container applications and environments.
CSAS toolset and supporting applications currently includes Tenable Security Center, Microsoft Defender for Endpoint, BigFix, OWASP Zap, BurpSuite, Black Duck, Coverity, Software Risk Manager, Checkov, Trivy, ClamAV, Red Hat Advanced Cluster Security for Kubernetes, Jira, Confluence, Bitbucket, Bamboo, and SharePoint. These tools are subject to change, and Vendors are responsible for supporting these and additional applications and toolsets, as needed.
SKILLS
- Assists Information System Security Officers in evaluations of delivered software
- Conducts static analysis on source code developed in common programming and scripting languages, including, but not limited to, C, C++, Java, C#, Groovy, Python, Perl, Pup, JavaScript, Ruby, Bash, Powershell, and Objective C, and identifying the presence of any vulnerabilities or potentially malicious logic
- Conducts dynamic, manual, and automated binary reverse engineering analysis on developed applications identifying the presence of any vulnerabilities or potentially malicious logic
- Provides technical guidance on typical indications of malicious logic and intent for both source code and compiled binary files
- Performs manual and automatic assessments of code libraries and cross reference them with industry best practices and OWASP Top 10
- Creates frameworks, internal tooling, scripts, and application extensions to support efficient and effective software security analysis processes
- Performs static and dynamic analysis of known malicious and unknown binary files, reverse engineering of compiled software, functional analysis of source code/scripts, and/or hardware/firmware analysis.
- Provides technical guidance on secure software development methodologies, techniques, and best practices
- Provides technical guidance on secure web development techniques, interfaces, and web security best practices
- Assists the Government Customer stakeholders in identifying and evaluating technical and operational security risks, threats, weaknesses, and vulnerabilities of the Government Customer information systems and services
- Provides presentations, briefings, and knowledge transfers as assigned
- Develops applicable reports (e.g. risk, secure code assessment reports), as assigned.
REQUIRED QUALIFICATIONS
- Active Top Secret Clearance required
- 6+ years of experience in IT security or a related field
PREFERRED CERTIFICATIONS
- Master’s degree in IT-related field
- COMPTIA Sec+ or equivalent preferred
Overview
We are seeking an experienced Cyber Capability Developer, Senior in support of a government customer
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s