Cybersecurity

Cybersecurity

Cybersecurity Engineer – Offensive Security, Penetration Testing & Vulnerability Management

Contact

Your Rohde & Schwarz recruiting team is looking forward to receiving your application.

Info
City/region
Maryland (USA)
Entry level
Professionals
Employment Type
Full-time
Ref. Number
17360
The Cybersecurity Engineer – Offensive Security, Penetration Testing & Vulnerability Management plays a critical role in identifying, validating, and reducing cybersecurity risk across mission-critical systems delivered by Rohde & Schwarz North America. This position will serve as a versatile member of the U.S. cybersecurity organization while providing primary expertise in vulnerability management, penetration testing, security assessment, and offensive security. The engineer will evaluate systems, networks, products, and COTS components for security weaknesses; determine the applicability and impact of vulnerabilities; validate security controls; and work directly with engineering teams to develop practical remediation strategies. While Offensive Security and Vulnerability Management will be the position's primary area of specialization, the successful candidate will also support broader cybersecurity activities including secure architecture, compliance, system hardening, product security, security testing, documentation, patch management, and customer/program support. Initially, the position will support Air Traffic Control (ATC) programs, with the opportunity to support additional Rohde & Schwarz products, programs, and business areas as the North American cybersecurity capability grows. This role requires being on site in our Frederick, MD facility and requires US citizenship.

Your tasks

  • Perform vulnerability assessments of systems, networks, applications, operating systems, COTS products, appliances, and embedded devices.
  • Plan, coordinate, and perform authorized penetration testing and security validation activities within controlled laboratory and customer environments.
  • Identify security weaknesses, attack paths, insecure configurations, exposed services, and potential control deficiencies.
  • Perform vulnerability scanning using tools such as Nessus, Nmap, and other approved security assessment tools.
  • Analyze CVEs and vendor security advisories to determine applicability, exploitability, operational impact, and remediation requirements.
  • Develop vulnerability assessment reports, technical findings, risk ratings, remediation recommendations, and supporting evidence.
  • Maintain and improve vulnerability tracking and remediation processes throughout the system lifecycle.
  • Validate remediation activities and verify that identified vulnerabilities have been appropriately mitigated.
  • Perform network and protocol analysis using tools such as Wireshark and related diagnostic/security tools.
  • Support security testing of IP networks, firewalls, switches, routers, Linux and Windows systems, VoIP systems, applications, and embedded devices.
  • Evaluate system attack surfaces, trust boundaries, data flows, interfaces, authentication mechanisms, and externally accessible services.
  • Participate in threat modeling, attack-path analysis, misuse-case development, and security architecture reviews.
  • Work with engineering and R&D teams to reproduce security findings and develop practical remediation solutions.
  • Support incident response, forensic analysis, and investigation activities when required.
  • Contribute to System Security Plans, security assessment reports, risk assessments, customer documentation, and other cybersecurity deliverables.
  • Support Factory Acceptance Testing (FAT), Site Acceptance Testing (SAT), customer deployments, onsite assessments, and witness testing.
  • Develop scripts, tools, and repeatable methodologies to improve vulnerability assessment, security testing, evidence collection, and reporting.
  • Research emerging threats, vulnerabilities, exploitation techniques, and defensive technologies relevant to Rohde & Schwarz products and customer environments.
  • Collaborate with cybersecurity, product, and engineering teams in Europe and North America.
  • Support the broader cybersecurity organization as priorities, programs, and customer requirements evolve.

Exciting insights into Rohde & Schwarz

Our colleagues provide insider information about:

  • Daily adventures and challenges
  • Our passionate team
  • The technologies behind the innovative projects and solutions

Your qualifications

  • BS degree in Cybersecurity, Computer Science, Engineering, Information Systems, or a related technical field. Master's degree preferred.
  • 7+ years of relevant cybersecurity, penetration testing, vulnerability management, network security, or security engineering experience.
  • Strong understanding of vulnerability assessment, penetration testing, attack methodologies, and remediation practices.
  • Hands-on experience with security tools such as Nessus, Nmap, Wireshark, Burp Suite, Metasploit, or comparable tools.
  • Strong knowledge of TCP/IP networking, routing, switching, VLANs, firewalls, ACLs, network segmentation, and common network protocols.
  • Working knowledge of Linux and Windows security and system hardening.
  • Experience analyzing CVEs, security advisories, vulnerability scan results, and technical security findings.
  • Ability to distinguish theoretical vulnerabilities from vulnerabilities that present meaningful risk within a specific system architecture and operating environment.
  • Experience documenting findings, assigning risk, developing remediation recommendations, and communicating results to engineering teams.
  • Knowledge of NIST SP 800-53, NIST CSF, DISA STIGs, CIS Benchmarks, or similar security frameworks.
  • Strong analytical, troubleshooting, documentation, and technical communication skills.
  • Experience working in laboratory or controlled test environments preferred.
  • Familiarity with mission-critical, safety-critical, aviation, transportation, defense, or critical infrastructure systems preferred.
  • Familiarity with IP networking, VoIP/SIP/RTP, RF communications, embedded systems, PLCs, appliances, and related technologies is beneficial.
  • Cybersecurity certifications such as OSCP, GPEN, GCIH, GWAPT, PNPT, CISSP, Security+, or similar are preferred.
  • Scripting experience using Python, PowerShell, Bash, or similar languages is beneficial.
  • In order to be considered, candidates must be a U.S. citizen or permanent resident able to obtain an interim or final suitability determination, subject to completion and favorable adjudication of the required background investigation.

Interested?

We are looking forward to receiving your application!

The total compensation for this position is $96K-$130K. Total compensation includes base salary, variable pay (when applicable) plus benefits. The range is determined by the position, geographic location and level. Individual pay within the range is determined by several factors including location, education or training, relevant work history, sales incentive structure and job-related skills.

Rohde & Schwarz is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, race, color, religion, national origin, disability, protected Veteran status, age or any other characteristic protected by law.
Rohde & Schwarz is a global technology company with approximately 14,000 employees and three divisions: Test & Measurement, Technology Systems and Networks & Cybersecurity. For 90 years, the company has been developing cutting-edge technology, pushing the boundaries of what is technically possible and enabling customers from various sectors such as business, government and public authorities to maintain their technological sovereignty.

You might find this also interesting