Quantum Research International, Inc

VULNERABILITY ASSESSMENT ANALYST

Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, or related field (or equivalent experience with certifications)
  • TS/SCI eligibility, subject to CI Polygraph
  • Proficiency in vulnerability management tools like Nessus, ACAS, and Tenable
  • Strong understanding of networking concepts, security methodologies, and risk management processes
  • Familiarity with cyber threats, vulnerabilities, and their operational impacts
  • Knowledge of cryptographic principles and key management strategies
  • Ability to develop and implement effective vulnerability remediation plans

Responsibilities

  • Perform assessments on systems and networks to identify configuration deviations
  • Coordinate with system owners on Cyber Task Orders to resolve findings
  • Develop metrics to measure defense effectiveness against known vulnerabilities
  • Identify systemic security issues through vulnerability and configuration analysis
  • Prioritize vulnerability reduction efforts considering threat data and mission criticality
  • Conduct vulnerability scanning and mitigate identified security weaknesses
  • Analyze and recommend remediation for web application vulnerabilities

Benefits

  • On-site work environment in Springfield, VA only
  • Opportunity to work as part of the NGA's Cybersecurity Vulnerability Management team
  • Involvement in critical national security initiatives in cybersecurity
  • Access to cutting-edge vulnerability management technologies
  • Professional development opportunities in cybersecurity compliance and risk management
Full Job Description
Mission:

As a member of the NGA Defender Cybersecurity Vulnerability Management team, the contractor executes the Vulnerability Management aspect of the Risk Management Framework (RMF) in accordance with NIST SP 800-37 R2 (or subsequent versions) and National Geospatial-Intelligence Agency's (NGA) RMF Implementation Guide (RIG) for all NGA-authorized systems. This position supports NGA in Springfield, VA and is on-site only. No remote/hybrid work.

Responsibilities:
  • Perform assessments of systems and networks within the network environment or enclave and identify where systems/networks deviate from acceptable configurations, enclave policy, or local policy.
  • Review, promulgate, and track Cyber Task Orders. Coordinate and assist the relevant information system owners to resolve findings.
  • Develop measures of effectiveness for defense-in-depth architectures against known vulnerabilities.
  • Identify systemic security issues based on the analysis of vulnerability and configuration (STIG) data.
  • Prioritize vulnerability reduction activities based on threat data, vulnerability severity, and mission criticality.
  • Conduct vulnerability scans and mitigate vulnerabilities in security systems.
  • Analyze web application vulnerability assessments to recommend remediation action for known web application vulnerabilities and misconfigurations.
  • Apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).


Requirements:

  • Bachelor's degree (technically relevant degree preferred). In lieu of degree, candidates may qualify with experience combined with one of the following: Security+, PenTest+, GSEC, GICSP, GCSA, GCIH, GCED, FITSP-A, CPTE, Cloud+, RCCE Level 1, CEH (Practical).
  • TS/SCI eligible, subject to CI Polygraph.
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology or other relevant fields.
  • Experience in vulnerability management using tools such as Nessus, ACAS, Tenable, etc.
  • Knowledge of computer networking concepts and protocols, and network security methodologies, risk management processes (e.g., methods for assessing and mitigating risk), and laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.
  • Knowledge of cyber threats and vulnerabilities, and operational impacts of cybersecurity lapses.
  • Knowledge of cryptography and cryptographic key management concepts
  • Knowledge of applicable cyber defense policies, regulations, and compliance documents specifically related to cyber defense auditing.
  • Knowledge of what constitutes a network attack and a network attack's relationship to both threats and vulnerabilities.
  • Ability to collaborate with IT asset owners to create vulnerability remediation plans using a positive customer service mindset.


Desired/Preferred Skills:

  • Experience with vulnerability and/or threat data visualization (Tableau, etc).


#LI-Onsite #LI-JL1

About Quantum Research International, Inc

Quantum Research International, Inc. provides engineering, software development, and cybersecurity services to the U.S. Department of Defense and other government agencies. The company offers services in the areas of missile defense, space operations, intelligence, surveillance, and reconnaissance. Quantum Research International also provides software engineering, modeling and simulation, and systems engineering services. The company was founded in 1987 and is headquartered in Huntsville, AL.
Learn more about Quantum Research International, Inc
Size
1,000 employees
Industry
Net Income
$10 million
Founded
1987
5 Year Trend
+20%
Revenue
$100 million

Similar Jobs

More Jobs at Quantum Research International, Inc

More Information Technology Jobs

Find similar VULNERABILITY ASSESSMENT ANALYST jobs: