Lead Enterprise Scanning Engineer / Active Secret

Peraton

$104K — $166K *
Aerospace & Defense
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor’s degree and minimum 9 years of experience (7 years with a Master's) or equivalent experience in lieu of a degree.
  • Possession of or ability to obtain a required security certification (CCNA-Security, CND, CySA+, GICSP, GSEC, Security+ CE, or SSCP).
  • Experience in assessing systems and networks for compliance with established configurations and standards.
  • Experienced in conducting enterprise-wide vulnerability assessments and compliance verifications.
  • U.S. Citizenship is required along with an Active Secret clearance, with the ability to obtain Top Secret clearance.

Responsibilities

  • Lead and mentor a team of Enterprise Scanning Engineers focusing on vulnerability and compliance scanning.
  • Develop and implement a strategic plan for enterprise scanning and vulnerability remediation.
  • Conduct regular vulnerability scans to identify deviations and assess risk for corrective measures.
  • Prepare and present reports on security policy effectiveness and vulnerability impact.
  • Collaborate with stakeholders to address vulnerabilities and ensure compliance.
  • Establish a queue management system to meet vulnerability management service needs.
  • Monitor emerging threats and recommend mitigation strategies accordingly.

Benefits

  • On-site work environment in Beltsville, MD.
  • Full-time position with growth opportunities in a collaborative team.
  • Professional development and mentoring opportunities.
  • Engagement in critical national security tasks within the federal sector.
Full Job Description
Responsibilities

Peraton is currently seeking an experienced Lead Enterprise Scanning Engineer to become part of our Federal Strategic Cyber Group.

 

Location: Beltsville, MD. On-Site; Full-time. 

 

Role Description:

 

Leadership and Team Management:

 

  • Lead a team of Enterprise Scanning Engineers responsible for vulnerability, compliance, web application, and database scanning.
  • Mentor and provide guidance to team members, fostering a collaborative and growth-oriented environment.

Strategic Planning and Execution:

 

  • Develop and implement a comprehensive enterprise scanning strategy to ensure timely identification, assessment, and remediation of vulnerabilities across the Department's systems and networks.
  • Oversee the execution of enterprise-wide operating system and application compliance verification, on-site security assessments, web, and database vulnerability scanning, and scanning of other IT assets.
  • Monitor emerging security threats and vulnerabilities and develop appropriate mitigation strategies in collaboration with relevant stakeholders.

Reporting and Communication:

 

  • Prepare and present regular reports on the effectiveness of the Department's security policies, the potential impact of new vulnerabilities upon discovery, and the effectiveness of measures taken to eliminate them.
  • Communicate effectively with various stakeholders, including system owners, administrators, and management, to ensure timely remediation of identified vulnerabilities and compliance issues.

Vulnerability Scanning:

 

  • Perform regular vulnerability scans across the Department's systems and networks, identifying deviations from acceptable configurations and standards.
  • Evaluate and prioritize identified vulnerabilities based on potential impact and risk and recommend remediation strategies and solutions.
  • Collaborate with system owners and administrators to address identified vulnerabilities and ensure timely remediation.

Compliance Scanning:

 

  • Execute enterprise-wide operating system and application compliance verification, assessing adherence to established security policies and best practices.
  • Develop security baseline configuration compliance and vulnerability scan policies for Department-hosted operating system platforms (e.g., Windows, UNIX, Linux, Cisco, Juniper, etc.).
  • Prepare audit reports identifying technical and procedural findings, providing recommended remediation strategies and solutions.

Web Application Scanning:

 

  • Conduct web application vulnerability scanning to identify potential security risks and weaknesses in web applications and services.
  • Collaborate with web developers and application owners to address identified vulnerabilities and ensure the implementation of secure coding practices.
  • Monitor emerging web application vulnerabilities and threats and recommend appropriate mitigation strategies.

Database Scanning:

 

  • Perform database vulnerability scanning to identify potential security risks and weaknesses in database management systems and configurations.
  • Collaborate with database administrators to address identified vulnerabilities and ensure the implementation of secure database practices.
  • Monitor emerging database vulnerabilities and threats and recommend appropriate mitigation strategies.

Additional Responsibilities:

  • Establish a queue management function to meet the Department's vulnerability management support service needs.
  • Track and report on service request metrics, such as ticket volume, ticket volume by category, response time, and resolution time by category.
  • Analyze the organization's cyber defense policies and configurations, evaluating compliance with regulations and organizational directives.
  • Maintain a list and schedule of all Information Systems (IS) requiring Enterprise Scanning (ES) assessments to support continuous monitoring and expeditious processing of ES assessments.
  • Develop, update, and maintain System Design and Operations documentation.
Qualifications

Basic Qualifications: 

  • Bachelor’s degree and a minimum of 9 years of experience; 7 years with a Masters.
    • An additional 4 years of experience will be considered in lieu of degree/education.
  • Possess and maintain, or be able to obtain before start date, one of the following professional certifications: 
    • CCNA-Security
    • CND
    • CySA+
    • GICSP
    • GSEC
    • Security+ CE
    • SSCP
  • Experience assessing systems and networks to identify where systems/networks deviate from acceptable configurations and standards.
  • Experience executing enterprise-wide both operating system and application compliance verification, vulnerability assessments, on-site security assessments, web, and database vulnerability scanning, and scanning of other IT assets.
  • U.S Citizenship required. 
  • Active Secret clearance.
    • Ability to obtain Top Secret clearance.
Target Salary Range$104,000 - $166,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual’s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

Similar Jobs

More Jobs at Peraton

More Aerospace & Defense Jobs

Find similar Lead Enterprise Scanning Engineer / Active Secret jobs: