BAE Systems Cybersecurity - Attack Surface Management has an opening for a Red Team Analyst Sr to improve overall security posture through authorized offensive security projects that identify gaps in IT security controls and processes. Position will manage cross functional engagements that include IT service centers, business sectors, and the security operations center. Scope can include the BAE Systems, Inc core network, business/program enclaves, and commercial and custom applications. Position manages engagements from end-to-end to include scope definition, detailed planning, stakeholder coordination, testing, reporting, and remediation coordination. This is an exciting opportunity to build and manage a program and work with a highly motivated team of cyber security professionals.
Required Education, Experience, & Skills
Technical requirements:
- Expertise in attack tools and techniques
- Ability to use and analyze information produced from various commercial and open source tools
- Familiarity with large network infrastructure components (Load balancers, Proxies, hybrid cloud implementations, VPNs)
- Familiarity with network and host-based security system components (Firewalls, Endpoint Protection Solutions)
- Familiarity with modern virtualization platforms and technology.
Required Skills
- Experience managing red team projects from end-to-end (initial planning through remediation coordination)
- Ability to coordinate activities with a wide range of stakeholders
- Experience developing plans, creating reports, presentation, processes, etc.
- Must be able to work across IT organizations to drive successful outcomes of the program
- Ability to produce documentation in support of the program
Preferred Education, Experience, & Skills
Preferred Skills and Education
- Computer Security related degree
- 6+ years in a cybersecurity role, 3+ years in red team
- Certifications related to red team and penetration testing such as OSCP, OSCE, OSWP, OSWE, GPEN, GWAPT, GXPN, GAWN
- Experience with COTS Adversary Emulation tools
Primary Duties and Responsibilities
- Develop standard Red Team practice within ESS Cybersecurity. Define core processes, tools, and deliverables.
- Simulate attacks on the organization's IT systems, networks, applications, and physical security to evaluate its security posture. Identify weaknesses that could be exploited by malicious actors and provide actionable recommendations to improve defenses.
- Work under consultative direction from management within Cybersecurity. Develop and implement plans and work with stakeholders independently to plan and execute activities.
- Develop detailed project plans that define technical approaches as well as impacts and requirements for stakeholders throughout the organization.
- Technical approaches may require a high degree of creativity and flexibility. Problems may be highly complex. Testing may often uncover unknown/unforeseen circumstances that require change in direction or new approaches. Position requires ability to independently make sound decisions to maximize effectiveness of tests.
- Must be able to maintain strong working relationships with stakeholders throughout the organization, including IT Operations, Applications, Network, GSOC, business sectors, etc. Stakeholders may be sensitive that simulated attacks may impact business operations. Position requires careful and responsible decisions regarding test approaches, and frequent and effective communications with stakeholders.
- Consult with stakeholders on findings and required actions to improve defenses. Develop and maintain detailed tracking that identifies scope, tests completed, and findings. Work with stakeholder to ensure findings are remediated.
- Serve as the Team Lead for the Red Team function within ESS Cybersecurity. Provide leadership and support to other Red Team Analysts on the team. Coordinate activities, ensure high quality delivery.
- Promote a culture of ownership, transparency, and results driven- performance.
Pay Information
Full-Time Salary Range: $132962 - $226035
Please note: This range is based on our market pay structures. However, individual salaries are determined by a variety of factors including, but not limited to: business considerations, local market conditions, and internal equity, as well as candidate qualifications, such as skills, education, and experience.
Employee Benefits: At BAE Systems, we support our employees in all aspects of their life, including their health and financial well-being. Regular employees scheduled to work 20+ hours per week are offered: health, dental, and vision insurance; health savings accounts; a 401(k) savings plan; disability coverage; and life and accident insurance. We also have an employee assistance program, a legal plan, and other perks including discounts on things like home, auto, and pet insurance. Our leave programs include paid time off, paid holidays, as well as other types of leave, including paid parental, military, bereavement, and any applicable federal and state sick leave. Employees may participate in the company recognition program to receive monetary or non-monetary recognition awards. Other incentives may be available based on position level and/or job specifics.
About BAE Systems, Inc.
BAE Systems, Inc. is the U.S. subsidiary of BAE Systems plc, an international defense, aerospace and security company which delivers a full range of products and services for air, land and naval forces, as well as advanced electronics, security, information technology solutions and customer support services. Improving the future and protecting lives is an ambitious mission, but it's what we do at BAE Systems. Working here means using your passion and ingenuity where it counts - defending national security with breakthrough technology, superior products, and intelligence solutions. As you develop the latest technology and defend national security, you will continually hone your skills on a team-making a big impact on a global scale. At BAE Systems, you'll find a rewarding career that truly makes a difference.
This position will be posted for at least 5 calendar days. The posting will remain active until the position is filled, or a qualified pool of candidates is identified.
Skills Required
- Expertise in attack tools and techniques
- Experience managing red team projects from end-to-end
- Ability to coordinate activities with a wide range of stakeholders
- Experience developing plans, creating reports and processes
- Familiarity with large network infrastructure components
- Familiarity with network and host-based security system components
- 6+ years in a cybersecurity role, 3+ years in red team
- Certifications related to red team and penetration testing
- Computer Security related degree
What We Do
Improving the future and protecting lives is an ambitious mission, but it’s what we do. As a leading aerospace, defense, and security company, we work together to deliver a full range of products and services for air, land, space, and naval forces, as well as advanced electronics, security, information technology solutions and customer support services. How we work is rooted in purpose – a purpose to protect those who protect us, to unite our community of colleagues and customers, and to drive forward the growth and development of our exceptional team members. It's where purpose connects.
Why Work With Us
We believe your career should be filled with innovation and discovery. And that's exactly what you'll find at BAE Systems. As you work to develop the latest technology and defend national security, you will continually hone your skills and expand knowledge. On a sharp and collaborative team, you will be challenged – and supported – at every turn.
Gallery
BAE Systems, Inc. Teams
BAE Systems, Inc. Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
As the work place continues to evolve, so do we. Remote and hybrid opportunities are available at BAE Systems depending on the nature of the role. Check your job requisition to learn more.

_resizw.jpg)
_resize.jpg)












.png)

.png)






_resizw.jpg)
_resize.jpg)












.png)

.png)














