Research & Development Specialist

Conducts software and systems engineering and software systems research to develop new capabilities, ensuring cybersecurity is fully integrated. Conducts comprehensive technology research to evaluate potential vulnerabilities in cyberspace systems.

Below are the Knowledge, Skills, Abilities and Tasks identified as being required to perform this work role.

Knowledge of computer networking concepts and protocols, and network security methodologies.
Knowledge of risk management processes (e.g., methods for assessing and mitigating risk).
K0003Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.
K0004Knowledge of cybersecurity and privacy principles.
K0005Knowledge of cyber threats and vulnerabilities.
K0006Knowledge of specific operational impacts of cybersecurity lapses.
K0009Knowledge of application vulnerabilities.
K0019Knowledge of cryptography and cryptographic key management concepts
K0059Knowledge of new and emerging information technology (IT) and cybersecurity technologies.
K0090Knowledge of system life cycle management principles, including software security and usability.
K0126Knowledge of Supply Chain Risk Management Practices (NIST SP 800-161)
K0169Knowledge of information technology (IT) supply chain security and supply chain risk management policies, requirements, and procedures.
K0170Knowledge of critical infrastructure systems with information communication technology that were designed without system security considerations.
K0171Knowledge of hardware reverse engineering techniques.
K0172Knowledge of middleware (e.g., enterprise service bus and message queuing).
K0174Knowledge of networking protocols.
K0175Knowledge of software reverse engineering techniques.
K0176Knowledge of Extensible Markup Language (XML) schemas.
K0179Knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
K0202Knowledge of the application firewall concepts and functions (e.g., Single point of authentication/audit/policy enforcement, message scanning for malicious content, data anonymization for PCI and PII compliance, data loss protection scanning, accelerated cryptographic operations, SSL security, REST/JSON processing).
K0209Knowledge of covert communication techniques.
K0267Knowledge of laws, policies, procedures, or governance relevant to cybersecurity for critical infrastructures.
K0268Knowledge of forensic footprint identification.
K0269Knowledge of mobile communications architecture.
K0271Knowledge of operating system structures and internals (e.g., process management, directory structure, installed applications).
K0272Knowledge of network analysis tools used to identify software communications vulnerabilities.
K0288Knowledge of industry standard security models.
K0296Knowledge of capabilities, applications, and potential vulnerabilities of network equipment including hubs, routers, switches, bridges, servers, transmission media, and related hardware.
K0310Knowledge of hacking methodologies.
K0314Knowledge of industry technologies?? potential cybersecurity vulnerabilities.
K0321Knowledge of engineering concepts as applied to computer architecture and associated computer hardware/software.
K0342Knowledge of penetration testing principles, tools, and techniques.
K0499Knowledge of operations security.
S0005Skill in applying and incorporating information technologies into proposed solutions.
S0017Skill in creating and utilizing mathematical or statistical models.
S0072Skill in using scientific rules and methods to solve problems.
S0140Skill in applying the systems engineering process.
S0148Skill in designing the integration of technology processes and solutions, including legacy systems and modern programming languages.
S0172Skill in applying secure coding techniques.
A0001Ability to identify systemic security issues based on the analysis of vulnerability and configuration data.
A0018Ability to prepare and present briefings.
A0019Ability to produce technical documentation.
A0170Ability to identify critical infrastructure systems with information communication technology that were designed without system security considerations.
T0064Review and validate data mining and data warehousing programs, processes, and requirements.
T0249Research current technology to understand capabilities of required system or network.
T0250Identify cyber capabilities strategies for custom hardware and software development based on mission requirements.
T0283Collaborate with stakeholders to identify and/or develop appropriate solutions technology.
T0284Design and develop new tools/technologies as related to cybersecurity.
T0327Evaluate network infrastructure vulnerabilities to enhance capabilities being developed.
T0329Follow software and systems engineering life cycle standards and processes.
T0409Troubleshoot prototype design and process issues throughout the product design, development, and pre-launch phases.
T0410Identify functional- and security-related features to find opportunities for new capability development to exploit or mitigate vulnerabilities.
T0411Identify and/or develop reverse engineering tools to enhance capabilities and detect vulnerabilities.
T0413Develop data management capabilities (e.g., cloud-based, centralized cryptographic key management) to include support to the mobile workforce.
T0547Research and evaluate available technologies and standards to meet customer requirements.