Listing Description
Overview Our mission at Dragos is to protect the world’s most critical infrastructure from adversaries who wish to do it harm. We help defend industrial organizations that provide us with the necessities of modern civilization: running water, functioning electricity, and safe industrial working environments. We are practitioners who have lived through and solved real security challenges. Our team members have responded to incidents including the 2015 Ukraine power grid attack, analyzed the CRASHOVERRIDE malware identified in the 2016 Ukraine electric grid attack, analyzed the TRISIS malware discovered in the petrochemical facility attack in 2017, built and led the National Security Agency (NSA) mission to identify nation-states targeting critical infrastructure, and performed assessments on hundreds of assets around the world. The Dragos Professional Services team serves as the boots-on-the-ground industry experts in solving industrial control system (ICS) security challenges. We then bring current operational insights back from the field and integrate them into our software technology: The Dragos Platform. We're looking for individuals who are passionate about safeguarding civilization, with hands-on experience in performing architecture reviews, vulnerability assessments, and penetration tests (network, device, and application). Candidates will be working directly with U.S. and international customers and directly contributing to R&D efforts. Responsibilities Execute customer engagements performing architecture reviews, vulnerability assessments, and penetration tests in industrial environments. These engagements include various tasks, including reviewing documentation, conducting gap analysis, and actively exploiting customer-owned hardware and software. Perform Scope of Work (SOW) reviews, Rules of Engagement (ROE) development, and other documentation-related tasks requiring meticulous attention to detail and technical accuracy. Deliver findings and recommendations documents, including verbal presentations and addressing of customer questions. Transform insights from customer engagements into research and innovation projects to advance Dragos technology. This involves analyzing packet captures (PCAP) and other data types to create protocol dissectors, characterizations, signatures, and other analytics. Contribute to the broader community by representing Dragos through outreach efforts such as white papers, webinars, and conference presentations, featuring original content and innovative ideas. Qualifications Minimum of 5 years of hands-on cybersecurity experience. Proven ability to perform penetration testing and threat emulation using known/expected tactics employed by nation states and other advanced threat actors. Extensive hands-on experience with common assessment and pen testing tools including Windows (LOTL), Kali, Python, C2 Platforms, Ansible, Docker, AWS, etc. Thorough understanding of cyber threats, common attack vectors, exploits, and adversary tactics, techniques, and procedures (TTP’s). Ability to calculate the operational or safety impact of exploited vulnerabilities and recommend mitigations or controls. Ability to collect and analyze network data in a cybersecurity context. Capable of establishing excellent rapport with customers across different levels, from practitioners to senior management, including the ability to facilitate training and present complex information to various audiences. Willingness to travel up to 30% (on average) for on-site customer engagements. Compensation Base Salary: $140,000 Competitive equity package Comprehensive benefits plan (medical, dental, vision, disability, life insurance, 401K with match) About Dragos Dragos is the Industrial Cybersecurity expert on a relentless mission to safeguard civilization. In a world of rising cybersecurity threats, Dragos protects the most critical infrastructure – those that provide us with the tenets of modern civilization – from increasingly capable adversaries who wish to do it harm. Devoted to codifying and sharing our in-depth industry knowledge of ICS/OT systems, Dragos arms industrial defenders around the world with the knowledge and tools to protect their systems as effectively and efficiently as possible. Founded by world-class industrial intelligence experts, Dragos has the industry’s largest team of ICS/OT practitioners who have been on the front lines of the world’s most significant industrial cyber-attacks. Diversity, Equity, and Inclusion are core values at Dragos, and we are passionate about building and sustaining an inclusive and equitable working environment for all. We know that every member of our team enriches our diversity by exposing us to a broad range of ways to understand and engage with the world, identify challenges, and discover, design, and deliver solutions. Not only does a Diversity, Equity, and Inclusion focus enrich our environment and teams, but it is also critical to our success as we defend against adversaries all over the world. The broad range of ideas, experiences, and perspectives is critical to our success. Dragos is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics, or any other basis forbidden under federal, state, or local laws. All new hires must pass a background check as a condition of employment. #LI-JF1 #LI-REMOTEResponsibilities: schema['responsibilities']Qualifications: schema['qualifications']
Listing Details
- Salary: $140000 - $140000
- Citizenship: Not Provided
- Incentives: Bonus
- Education: Not Provided
- Travel: Not Provided
- Telework: Full Telecommute