The Opportunity
The Junior Offensive Cyber Security Specialist supports cybersecurity assessments of organizational and third-party environments by evaluating technology architectures, infrastructure, applications, and security controls to identify vulnerabilities, assess risk, and support improvements to overall security posture. Performs cybersecurity activities such as vulnerability assessments, penetration testing, threat hunting, adversary emulation, security validation, and basic incident identification and analysis under the guidance of senior team members. Utilizes established tools, methodologies, and threat intelligence to identify potential threats, document findings, and contribute to the development of effective security recommendations. Supports senior cybersecurity personnel as a technical team member by assisting with risk assessments, technical reporting, briefings, and security recommendations for leadership, stakeholders, and vendors. Collaborates with team members and other organizational stakeholders to execute cybersecurity assessments, maintain established methodologies and procedures, and support the development of security improvements. Responsible for accurately documenting assessment results, communicating technical findings, completing assigned tasks, and contributing to the successful delivery of cybersecurity objectives within established contractual and organizational timelines.
Key Responsibilities (Principal Duties and Accountabilities *Essential Functions)
-
Support end-to-end security assessments of vendor and organizational environments, including data architecture, supporting technology stacks, and external-facing infrastructure, utilizing advanced analysis techniques, tools, tactics, and procedures (TTPs) derived from both publicly available and proprietary intelligence sources.
-
Coordinate and participate in vendor and stakeholder engagements to evaluate security posture, including existing protocols, processes, mitigation strategies, and overall risk exposure, with particular attention to foreign infrastructure presence or dependencies.
-
Perform cybersecurity activities such as threat hunting, adversary emulation, penetration testing, and vulnerability management, to assess system resilience, identify misconfigurations, and uncover exploitable weaknesses across networks, systems, and applications.
-
Monitor internal and external environments for security anomalies, suspicious activity, and indicators of compromise; Assist with incident response and forensic analysis to determine root cause, scope, and adversary TTPs using a broad technical skill set (e.g., networking, systems, malware analysis, and coding).
-
Research, analyze, and operationalize intelligence on emerging threats, vulnerabilities, exploits, and attack trends to proactively enhance organizational security posture and defensive capabilities.
-
Support the development, implementation, and continuously improve threat detection, monitoring, and response capabilities, incorporating insights from threat intelligence and incident response activities to strengthen security controls and reduce risk exposure.
-
Produce comprehensive technical reports, risk assessments, and executive-level briefings that clearly document findings, threat analyses, and actionable recommendations for remediation, mitigation, and strategic decision-making.
-
Support senior cybersecurity personnel as a technical resource during stakeholder discussions, leadership briefings, and cross-functional initiatives involving cybersecurity, vulnerability management, security assessments, and risk management.
-
Collaborate with internal teams to design, refine, and advance security methodologies, tools, and TTPs, contributing to the development and execution of long-term security initiatives.
-
Assist in Identifying, assessing, and recommending mitigations to cybersecurity risks associated with business operations, ensuring risks are effectively measured, monitored, controlled, and aligned with organizational risk tolerance and compliance requirements.
-
Follow established cybersecurity frameworks, risk management processes, regulatory requirements, and internal security policies and procedures when conducting assessments, handling security information, and performing assigned cybersecurity activities.
-
Fluency in English (written and spoken)
-
The ability to obtain Secret or higher security clearance; preference will be given to candidates with active Secret or higher security clearance
Education
-
Bachelor’s degree in cybersecurity or computer science required, related field, or equivalent work experience
Required Skills, Experience & Abilities
-
3+ years of demonstrated security experience, with 2+ years of professional experience in conducting PAI/ business intelligence, investigative work, penetration testing, and vulnerability assessments or offensive cyber operations
-
Knowledge of network protocols & security, operating systems security, firewalls, database infrastructure, scripting, and other network technologies and tools.
-
Exceptional communication skills, capable of effectively conveying complex information to various stakeholders
-
Knowledge of open-source research methodologies, including source evaluation, data verification, and responsible use of publicly available information
-
Candidate must demonstrate trustworthiness and responsible behavior
-
Strong communication, presentation, and team building skills
Preferred Qualifications
-
Exposure to Open-Source Intelligence (OSINT) or publicly available information (PAI) research through coursework, internships, or professional experience.
eJPT, eCPPT, PNPT, GPEN, OSCP, cRTO.
Physical Demands & Work Environment
The physical demands and work environment described are representative of those that an employee encounters while performing the essential functions of this job.
-
Prolonged periods of sitting at a desk and working on a computer.
-
Ability to lift up to 50 lbs. and work in austere field conditions.
-
Ability to lift up to 15 pounds on occasion (e.g., transporting laptop, presentation materials, or small equipment).
-
Frequent use of hands and fingers for typing, writing, and handling documents.
-
Clear vision and hearing required for meetings, presentations, and communication.
-
Ability to travel domestically and internationally up to 25% of the time, which may include extended periods of standing, walking, or navigating airports and government facilities.
-
Ability to sit or stand for long periods of time.
-
The noise level in the work environment is usually moderate.
-
Professional office environment with standard office equipment (computers, phones, printers).
-
Frequent interaction with clients, executives, and government officials in both in-person and virtual settings.
-
Regular travel to customer sites, government facilities, and industry events.
-
Fast-paced, deadline-driven environment requiring adaptability and responsiveness.
-
Work may occasionally be performed in secure government facilities, requiring adherence to security protocols.
-
This position may involve OCONUS travel for short periods of time.
Exciting opportunities like this are better when shared. Send this role to someone you know: Junior Offensive Cyber Security Specialist
Equal Opportunity
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. NTS will also consider qualified applicants with criminal histories consistent with relevant laws for employment.
For individuals with disabilities that need additional assistance at any point in the application and interview process, please email [email protected]