IT Security Vulnerability Specialist (0036)

OCT Consulting, LLC

$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years of experience in Assessment and Authorization (A&A) support
  • Proficient in the NIST Risk Management Framework (RMF)
  • Knowledge of NIST special publications 800-53 and 800-53A
  • Bachelor's degree or equivalent experience
  • Hands-on experience with vulnerability scanning platforms including STIG and CIS benchmarks
  • MS Excel proficiency
  • Relevant industry certification (e.g., GIAC GEVA, CASP, CISSP) required
  • Must be a US Citizen and hold SECRET clearance

Responsibilities

  • Lead remediation efforts to improve vulnerability management processes
  • Articulate risks and impacts of vulnerabilities to business leaders
  • Conduct internal vulnerability assessments and analyze external reports
  • Monitor and maintain vulnerability management tools
  • Develop and recommend security policies related to vulnerability management
  • Participate in security audits to ensure regulatory compliance
  • Perform vulnerability reproduction and validation

Benefits

  • Medical, Dental, and Vision insurance
  • Retirement savings 401K plan with 3% employer contributions
  • Paid Time Off
  • Life Insurance and Short- and Long-Term Disability benefits
  • Training benefits
Full Job Description
Associate / IT Security Vulnerability Specialist (0036)

OCT is currently looking for an Associate to join our growing Cybersecurity practice. This position will primarily support a federal client as an IT Security Vulnerability Specialist, which is a hybrid position requiring at least 3 days per week onsite in Suitland, MD. The ideal candidate will be proficient in key areas of security such as: Vulnerability Management, Intrusion Prevention and Detection, Access Control and Authorization, Policy Enforcement, Application Security, Protocol Analysis, Firewall Management, Incident Response, Data Loss Prevention (DLP), Encryption, Two-Factor Authentication, Web filtering, and Advanced Threat Protection.

Responsibilities will include, but are not limited to:
  • Lead and drive remediation efforts within government environment to increase the efficiency of vulnerability management processes.
  • Articulate risk and impact to product, engineering and other business leaders with the ability to convey the urgency and need to remediate a vulnerability commensurate with the risk it presents to the enterprise.
  • Conduct internal vulnerability assessments and vulnerability analysis upon external vulnerability reports, zero-day announcements, security incidents etc.
  • Monitor and maintain vulnerability and code scanning, security configuration and other vulnerability management tools.
  • Develop, maintain, and recommend security policies, procedures, and standards related to vulnerability management.
  • Participate in security audits and assessments to ensure compliance with regulatory requirements and industry standards.
  • Perform vulnerability re-production and fix validation of vulnerabilities where required.
  • Maintain strong knowledge of ongoing security threats, remediations and operational best practices in the threat and vulnerability management.
  • Create reports and dashboards to drive vulnerability remediation efforts and process improvements.
  • Drive regular operational and business reviews for threat and vulnerability management activities.
  • Support other security operation activities as needed (e.g. detection and response).
  • Participate in the Security Incident response.
  • Review, evaluate, refine, release and maintain Configuration Management Plans in support of program requirements.
  • Provide recommendations and guidance for the identification of Configuration Items (CI) and Computer Software Configuration Items (CSCI).
  • Provide guidance and expertise in the establishment, monitoring and maintenance of configuration baselines on assigned programs.
  • Monitor effectiveness and compliance on assigned programs.

Requirements

Requirements:
  • 7+ years of experience with A&A support.
  • Proficient in all steps in the NIST RMF framework
  • Knowledgeable in NIST special publications such as 800-53 & 800-53A
  • Bachelor's degree or equivalent experience
  • In-depth understanding and hands-on experience with multiple vulnerability scanning platforms, to include scanning with Security Technical Information Guides (STIG) and CIS benchmarks.
  • MS Excel proficiency.
  • A related industry certification such as GIAC GEVA, CASP, CAP, CISSP, CISM, GSEC, GMON, Security+.
  • Must be a US Citizen.
  • SECRET clearance required

Benefits

Benefits

The position includes competitive compensation and a full suite of benefits:
  • Medical, Dental, and Vision insurance
  • Retirement savings 401K plan provided by an industry-leading provider with 3% employer contributions.
  • Paid Time Off
  • Life Insurance, Short- and Long-Term Disability benefits
  • Training Benefits


Salary: $110,000-$130,000 to commensurate with experience, education, etc.

Similar Jobs

More Jobs at OCT Consulting, LLC

More Information Technology Jobs

Find similar IT Security Vulnerability Specialist (0036) jobs: