DoD 8570.01-M compliant with IAT Level II (Sec+) or IASAE Level 1 (CASP/CISSP)
Experience as an ISSE on similar Federal Government programs desirable
Bachelor's degree in Computer Science, Information Assurance, or related field required
Associate's degree with technical certification plus 2 years of IT experience accepted
High school diploma with 4 years of IT experience, including security experience, considered.
Responsibilities
Configure and maintain Tenable.sc and Nessus for vulnerability tracking.
Troubleshoot scanning issues and coordinate solutions with stakeholders.
Conduct STIG compliance scans and assist in validating system hardening.
Analyze vulnerabilities and trends, creating actionable findings for remediation.
Integrate vulnerability data into Splunk for analysis and reporting.
Develop dashboards and reports to visualize system risks and remediation progress.
Support RMF activities and assist in audits with detailed vulnerability reporting.
Benefits
Opportunities for professional growth and development
Supportive team environment fostering collaboration
Exposure to advanced security tools and technologies
Flexibility with work location for certain duties
Assistance with continuing education and certifications
Full Job Description
Responsibilities:
Configure, operate, and maintain Tenable.sc and Nessus to identify and track vulnerabilities across all environments.
Troubleshoot scans and/or coordinate with customer or program resources to resolve scanning issues.
Conduct STIG compliance scans and interpret results to assist system administrators and ISSEs to validate system hardening and control effectiveness.
Analyze vulnerability data and trends; create actionable findings and coordinate remediation efforts with system administrators and ISSEs.
May be required to perform job duties/responsibilities outside of normal work location.
Integrate vulnerability and compliance data into Splunk for correlation, trend analysis, and automated compliance reporting.
Develop dashboards and reports to visualize system risk posture and track remediation progress.
Support RMF (Risk Management Framework) activities, providing technical input for security controls (e.g., Tenable results).
Assist in developing or refining scanning policies, baselines, and SOPs to improve security posture and compliance consistency.
Support audits and assessments by providing detailed vulnerability data, remediation evidence, and STIG compliance documentation.
Implementing security vulnerability testing tools to provide continuous monitoring and patch verification.
Test and evaluate configurations in a lab environment.
Knowledge of servers, virtualization, routers, switches, and firewalls as well as VLANS, routing and network segmentation.
Working knowledge of DoD STIGs, and RMF process (NIST 800-53).
Experience using Splunk for data ingestion, search queries, correlation, and report creation.
Provide security operations support as needed.
Candidates should possess excellent communication and teamwork skills.
Competitive candidates are results oriented, high energy, and self-motivated.
Candidate may be required to respond to after-hours requests as required in a 24 x 7 environment.
Requirements
Active and current TS.SCI w FSP through MD
Active DoD 8570.01-M compliance with Information Assurance Technical (IAT) Level II (Sec+) or Information
Assurance Systems Architect and Engineer (IASAE) Level 1 (CASP or CISSP) is required
Experience as an ISSE on programs and contracts of similar scope, type, and complexity within the Federal Government is desirable. Bachelor's degree in Computer Science, Information Assurance, Information Security System Engineering, or related discipline from an accredited college or university is required.
Education:
An Associate's degree in Computer Science, Information Assurance, Information Security System Engineering, or a related discipline from an accredited college or university and a technical certification such as Security + plus two (2) years of general IT experience.
Highschool Diploma/GED and four (4) years of general IT experience, at least one (1) of which must be information systems security experience.