Senior Threat Validation Specialist

State of MontanaHelena, MT
Hybrid

About The Position

This career opportunity is with the State Information Technology Services Division - Office of Information Security, which provides security services and support to all state government agencies with the mission to protect citizen’s data. The Senior Threat Validation Specialist position is primarily responsible for vulnerability assessments, vulnerability consultation, red teaming, and penetration testing. This role will involve using artificial intelligence (AI) and large language model (LLM) tools to work faster and dig deeper across engagements, accelerating reconnaissance, code and log analysis, tooling and script development, and reporting, while rigorously validating AI-generated output and safeguarding sensitive state data. The position offers the opportunity to telework with required weekly in-office days in Helena, Montana.

Requirements

  • Associates degree in Information Security or Technology; AND 6 years’ experience in a security-related role
  • Knowledge of Cyber threats and vulnerabilities.
  • Knowledge of Network traffic analysis methods.
  • Knowledge of Database, Cloud, and/or Web Application Security.
  • Knowledge of Vulnerability assessment.
  • Knowledge of Cyber-attack stages (e.g., reconnaissance, scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks).
  • Knowledge of Website types, administration, functions, and content management system (CMS).
  • Knowledge of Attack methods and techniques (DDoS, brute force, spoofing, etc.).
  • Knowledge of Host-based security products and how those products affect exploitation and reduce vulnerability.
  • Knowledge of Internal tactics to anticipate and/or emulate threat capabilities and actions.
  • Knowledge of Network protocols such as TCP/IP, Dynamic Host Configuration, Domain Name System (DNS), and directory services.
  • Knowledge of Intrusion detection methodologies and techniques for detecting host and network-based intrusions.
  • Knowledge of Web Application Security Risks (e.g., Open Web Application Security Project Top 10 list).
  • Knowledge of Generative AI and large language model (LLM) fundamentals and architecture, including models and model selection, tokens and context windows, prompting, retrieval-augmented generation (RAG), agentic (tool-using) AI, the Model Context Protocol (MCP), and the trade-offs between cloud-hosted and locally hosted models.
  • Knowledge of How AI and LLM-assisted capabilities apply across the penetration testing lifecycle, including reconnaissance and open-source intelligence (OSINT) synthesis, code and configuration review, script and exploit development, log and data analysis, and reporting, as well as AI-augmented and semi-autonomous testing platforms.
  • Knowledge of Limitations and risks of generative AI in security work, including hallucination and the need to independently verify output, data-handling and confidentiality constraints, tool licensing, and applicable law and policy.
  • Knowledge of How threat actors use AI to accelerate their own operations, such as generating phishing and social-engineering content, developing or obfuscating malware, and automating reconnaissance.
  • Skill in Conducting research using our threat intelligence tools.
  • Skill in Social engineering techniques.
  • Skill in Defining and characterizing all pertinent aspects of the operational environment.
  • Skill in Evaluating information for reliability, validity, and relevance.
  • Skill in Identifying cyber threats which may jeopardize organization and/or partner interests.
  • Skill in Using security event correlation tools.
  • Skill in Detecting host and network-based intrusions via intrusion detection technologies.
  • Skill in Conducting trend analysis.
  • Skill in Reading, interpreting, developing, and deploying signatures.
  • Skill in Prompt engineering and integrating AI and LLM tools into offensive security workflows to improve speed, coverage, and quality.
  • Skill in Critically evaluating and validating AI-generated code, findings, and recommendations before acting on them or including them in deliverables.
  • Skill in Using AI tools without exposing sensitive, confidential, or regulated state data to unauthorized or third-party services.
  • Ability to Communicate complex information, concepts, or ideas in a confident and well-organized manner through verbal, written, and/or visual means.
  • Ability to Accurately and completely source all data used in intelligence, assessment and/or planning products.
  • Ability to Evaluate, analyze, and synthesize large quantities of data (which may be fragmented and contradictory) into high quality, fused targeting/intelligence products.
  • Ability to Function in a collaborative environment, seeking continuous consultation with other analysts and experts—both internal and external to the organization—to leverage analytical and technical expertise.
  • Ability to Think critically.
  • Ability to Think like threat actors.
  • Ability to Develop or recommend analytic approaches or solutions to problems and situations for which information is incomplete or for which no precedent exists.
  • Ability to Apply techniques for detecting host and network-based intrusions using intrusion detection technologies.
  • Ability to Conduct forensic analyses in and for both Windows and Unix/Linux environments.
  • Ability to Interpret the information collected by network tools.
  • Ability to Apply AI and LLM-assisted techniques to accelerate offensive security work while maintaining accuracy, scope discipline, and data protection.

Nice To Haves

  • Bachelors degree in Information Security or Technology; AND 4 years’ experience in a security-related role
  • OSCP, Pentest+, KLCP, GCFE, GCFA, E|CIH, or CISSP
  • CPENT AI, Offsec OSAI, CompTIA SecAI+, or comparable AI-integrated offensive security training

Responsibilities

  • Conduct vulnerability assessments.
  • Provide vulnerability consultation.
  • Perform red teaming.
  • Conduct penetration testing.
  • Lead the team in offensive security tactics.
  • Teach efficient techniques for responding to threat actors.
  • Facilitate attack/defense exercises within the Bureau.
  • Recommend controls to reach desired security posture.
  • Analyze malware.
  • Provide subject matter expertise to agencies.
  • Substantially impact enterprise security.
  • Use artificial intelligence (AI) and large language model (LLM) tools to work faster and dig deeper across engagements—accelerating reconnaissance, code and log analysis, tooling and script development, and reporting—while rigorously validating AI-generated output and safeguarding sensitive state data.
  • Evaluate, pilot, and responsibly adopt emerging AI-assisted offensive security tools, and advise the team on appropriate and authorized use.
  • Explain AI and LLM capabilities, limitations, and risks to both technical and non-technical audiences.

Benefits

  • Work/life Balance
  • Health Coverage
  • Retirement plans
  • Paid Vacation and Sick Leave and Holidays
  • Public Service Loan Forgiveness (PSLF) – Employment with the State of Montana may qualify you to receive student loan forgiveness under the PSLF.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service