About the Company Tesla Laboratories is a Service-Disabled Veteran Owned Small Business (SDVOSB) providing Cyber Security, Intelligence Analysis, Financial Management, Facilities Engineering Services, and Program Management support to the Intelligence Community (IC), the Department of Defense (DoD), and other federal government customers. We take pride in fostering a culture that values family, professional growth, and long-term career development—setting us apart from other services companies.
Cyber Penetration Testing
The team provides a highly technical and in-depth penetration testing service, in support of enterprise cyber security equities. The areas of focus for Sponsor’s requirement are not just Enterprise networks and applications, but also includes cloud environments in AWS, Oracle, Azure and Google. The team requires support specializing in penetration testing and ethical hacking, to target, assess, and exploit risk and vulnerabilities of information systems. The ability to test the communication between multiple systems and networks is vital to the protection and security of the enterprise and its data. The intent is to provide senior decision makers with documented and actionable data to aid in making strategic investment decisions.
The Contractor shall perform analyses of vulnerabilities identified during testing.
The Contractor shall review program-level documentation (e.g., requirements specification, system architecture, design documents, test plans, security plans, etc.).
The Contractor shall create and document penetration testing plans and procedures.
The Contractor shall, with Sponsor oversight, identify ways to incorporate Artificial Intelligence (AI) into current testing techniques and methodologies.
The Contractor shall conduct hands-on penetration testing by leveraging approved testing plans and procedures.
The Contractor shall analyze penetration test results, document risks, and recommend countermeasures to uncovered risks.
The Contractor shall participate or lead technical exchange meetings and application review boards.
The Contractor shall document action items and results from technical exchange meetings and application review boards.
The Contractor shall brief management on the status of action items and results of activities.
The Contractor shall be required to travel or report to varied work locations within the Washington Metropolitan Area (WMA) as part of daily work duties.
The Contractor shall execute work schedules to ensure that necessary planning, coordination, approvals, negotiations, and other contract requirements are completed in a timely manner so as not to negatively impact the program.
Cyber Penetration Testing
In depth knowledge of Penetration testing or ethical hacking. Experience circumventing or defeating security features or security control mechanisms of an information system through reconnaissance and active testing. Providing vulnerability assessments of a system’s susceptibility to attack.
Ability to understand and replicate or anticipate the types of attacks that could be mounted to discover the ways in which a system could be compromised by a potential attacker.
Demonstrated work experience in cyber security or related IT field.
Demonstrated experience with cyber penetration testing.
Demonstrated experience leveraging adversarial tactics to conduct hands-on security testing.· Demonstrated experience applying computer attack methods and system exploitation techniques.
Demonstrated working knowledge of cyber security principles for Linux, Windows, and virtual platforms.
Demonstrated experience designing, testing, or implementing IT security architecture.
Demonstrated experience performing network security analysis.
Demonstrated experience analyzing network architectures.
Demonstrated experience using network management tools.
Demonstrated experience developing risk management methodologies.
Demonstrated experience analyzing test results to develop risk and threat mitigation plans.
Demonstrated experience testing or reviewing system configuration, development, and design specifically around enterprise systems and hypervisors.
Demonstrated experience designing, testing, or implementing complex Windows installations.
Demonstrated experience with understanding Cloud Providers designs and services.
Experience Skills and demonstrated knowledge that are highly desired but not required to perform the work include:· Demonstrated experience participating in public and private information security groups and organizations.
Demonstrated experience communicating vulnerability results and risk posture to senior executives.
Demonstrated experience performing complex technical tasks with minimal direction.
Demonstrated experience with penetration testing within Sponsor Cloud Services.
Demonstrated experience with using AI in penetration testing.
Bachelor's degree in Computer Science, Information Systems, Engineering, or other related scientific or technical discipline.
One or more of the relevant certifications:
o Certified Ethical Hacker (CEH)
o Offensive Security Certified Professional (OSCP)
o Global Information Assurance Certification Penetration Tester (GPEN)