Cybersecurity Vulnerability Scanning Analyst

Summit Technologies, Inc.

$80K — $95K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Minimum 4 years of Cybersecurity experience.
  • Proficient in using BURP Suite (Enterprise Edition).
  • Experience with payload injection techniques (e.g., SQL injection, XSS).
  • Familiar with STIGs and associated analytic processes.
  • Skilled in developing mitigation strategies from scan results.
  • Proficient with MS Office Suite and SharePoint tools.
  • Strong communication skills, both oral and written.

Responsibilities

  • Operate and manage approved security scanners for vulnerability assessments.
  • Develop and manage a schedule for vulnerability scans.
  • Monitor and address issues impacting scan performance.
  • Ensure compliance with best practices for scans and configurations.
  • Analyze feedback to enhance scan results and tool effectiveness.
  • Create and deliver detailed vulnerability scan reports.
  • Assist clients with questions and reporting issues as needed.

Benefits

  • Hybrid work model with on-site requirements in Chambersburg, PA.
  • Opportunity to work within government contracting frameworks.
  • Involvement in enhancing the cybersecurity posture of the DoD.
  • Exposure to advanced vulnerability scanning tools and methodologies.
Full Job Description
Cybersecurity Vulnerability Scanning Analyst to maintain compliance with DoD vulnerability identification requirements for whitelisted websites and public-facing web presence. You will work as a team member to enhance the security posture of the DoD DMZ whitelisted websites, by conducting Web Vulnerability Scans (WVS) to identify and document gaps; and mitigate vulnerability. This hybrid position requires you to reside within 60 miles of Chambersburg, PA and be on site periodically. You must be a US citizen, as this is part of a government contract that requires a Secret security clearance.

Duties and Responsibilities:

  • Operate, maintain, and administer approved security scanners to plan, create, manage, and retire scheduled or ad hoc scan and scan groups for workloads across NIPRNet and SIPRNet.
  • Develop, distribute, and manage execution against the schedule of vulnerability scans.
  • Monitor, identify, report, and facilitate the resolution of scan performance impacting issues.
  • Maintain and ensure scans, accounts, and configurations are set in accordance with best practice guides and privileged access policies and procedures.
  • Analyze mission requirements and organizational feedback to create, maintain, and improve scan results.
  • Test and evaluate scanning tools and configurations.
  • Maintain client point of contact information, Internet Protocol (IP) ranges, and website/Universal Resource Locator (URL) information on the Data site via SharePoint.
  • Create and deliver a Collective Trend Analysis Report and trend analysis including resolution data aimed at influencing the development of security strategies.
  • Schedule, coordinate and perform vulnerability scans.
  • Determine Ports/Protocols and Services Management (PPSM) compliance; provide mitigations, strategies, and false positive determinations.
  • Create and deliver vulnerability scan reports, no later than two weeks after the scan is complete. Reports must include identified vulnerabilities, recommended resolutions/ mitigations, and trend analysis.
  • When initiated by the client, assist with a review of the report (i.e., answer questions, identify what was scanned, assist if assets were skipped).
  • Communicate and validate scan results in accordance with policies and procedures.
  • Help with vulnerability scan related issues/problem resolution with applicable Service desks.

Required Experience and Skills:

  • Minimum 4 years of Cybersecurity experience.
  • Experience utilizing BURP Suite (Enterprise Edition).
  • Experience configuring web browsers (e.g. Chrome, Firefox, etc.).
  • Experience injecting payloads to trigger vulnerabilities (e.g. SQL injection; XSS, Command Injection, Path Traversal, CSRF, IDOR).
  • Skilled at reviewing, interpreting, documenting, and developing mitigation strategy from the scan results.
  • Experience with STIGs and by-product analysis.
  • Proficiency in MS Office Suite products and SharePoint collaborative tools.
  • Working knowledge of government cybersecurity policies and procedures.
  • Strong interpersonal and communication skills (oral and written).

Education:

  • A Bachelor's degree in fields such as Information Technology, Cybersecurity, or Computer Science; Or CEH certification.

Certification:

  • 8570 IAT Level II (CCNA Security, CySA+, GICSP, GSEC, Security+ CE, CNS, SSCP).

Security Clearance:

  • DoD Secret security clearance

If you feel you are qualified and want to be considered for this position, please supply the following to: [redacted], and please put the job number '6781' in the subject line:

  • Updated resume including MM/YYYY for each employer.
  • Best times/dates to interview (plus phone # you can best be contacted at).
  • Availability to start once given formal offers.

Summit Technologies Inc. appreciates your interest. We will contact the best matching prospects and will consider you for future opportunities. We will not submit your resume without your prior knowledge and consent.

Similar Jobs

More Jobs at Summit Technologies, Inc.

More Information Technology Jobs

Find similar Cybersecurity Vulnerability Scanning Analyst jobs: