The Cybersecurity Engineer – Offensive Security, Penetration Testing & Vulnerability Management plays a critical role in identifying, validating, and reducing cybersecurity risk across mission-critical systems delivered by Rohde & Schwarz North America. This position will serve as a versatile member of the U.S. cybersecurity organization while providing primary expertise in vulnerability management, penetration testing, security assessment, and offensive security.
The engineer will evaluate systems, networks, products, and COTS components for security weaknesses; determine the applicability and impact of vulnerabilities; validate security controls; and work directly with engineering teams to develop practical remediation strategies.
While Offensive Security and Vulnerability Management will be the position's primary area of specialization, the successful candidate will also support broader cybersecurity activities including secure architecture, compliance, system hardening, product security, security testing, documentation, patch management, and customer/program support.
Initially, the position will support Air Traffic Control (ATC) programs, with the opportunity to support additional Rohde & Schwarz products, programs, and business areas as the North American cybersecurity capability grows. This role requires being on site in our Frederick, MD facility and requires US citizenship.
Your tasks
- Perform vulnerability assessments of systems, networks, applications, operating systems, COTS products, appliances, and embedded devices.
- Plan, coordinate, and perform authorized penetration testing and security validation activities within controlled laboratory and customer environments.
- Identify security weaknesses, attack paths, insecure configurations, exposed services, and potential control deficiencies.
- Perform vulnerability scanning using tools such as Nessus, Nmap, and other approved security assessment tools.
- Analyze CVEs and vendor security advisories to determine applicability, exploitability, operational impact, and remediation requirements.
- Develop vulnerability assessment reports, technical findings, risk ratings, remediation recommendations, and supporting evidence.
- Maintain and improve vulnerability tracking and remediation processes throughout the system lifecycle.
- Validate remediation activities and verify that identified vulnerabilities have been appropriately mitigated.
- Perform network and protocol analysis using tools such as Wireshark and related diagnostic/security tools.
- Support security testing of IP networks, firewalls, switches, routers, Linux and Windows systems, VoIP systems, applications, and embedded devices.
- Evaluate system attack surfaces, trust boundaries, data flows, interfaces, authentication mechanisms, and externally accessible services.
- Participate in threat modeling, attack-path analysis, misuse-case development, and security architecture reviews.
- Work with engineering and R&D teams to reproduce security findings and develop practical remediation solutions.
- Support incident response, forensic analysis, and investigation activities when required.
- Contribute to System Security Plans, security assessment reports, risk assessments, customer documentation, and other cybersecurity deliverables.
- Support Factory Acceptance Testing (FAT), Site Acceptance Testing (SAT), customer deployments, onsite assessments, and witness testing.
- Develop scripts, tools, and repeatable methodologies to improve vulnerability assessment, security testing, evidence collection, and reporting.
- Research emerging threats, vulnerabilities, exploitation techniques, and defensive technologies relevant to Rohde & Schwarz products and customer environments.
- Collaborate with cybersecurity, product, and engineering teams in Europe and North America.
- Support the broader cybersecurity organization as priorities, programs, and customer requirements evolve.