Cyber Security Engineer - Vulnerability Management

May 2, 2023

Apply Now
Logo of TestPros, Inc.

TestPros, Inc.

Software Test & Evaluation • Quality Assurance • Configuration Managment • IV&V • RMF A&A

51 - 200 employees

Founded 1988

📋 Compliance

🔒 Cybersecurity

Description

• Conduct reviews of NIST, OMB, DHS, DoD, FISMA policies, mandates, and vendor publications related to enterprise technologies and recommend changes to organizational policy and procedures affected by new guidance. • Support authoritative order review, research, impact assessment, distribution, compliance determination, tracking, and reporting. • Monitor identified vulnerabilities throughout their lifecycle from discovery to mitigation using ACAS, HBSS, STIG Viewer or other industry tools. • Support the Plan of Actions and Milestones (POA&M) program to ensure customer systems have accurately and fully provided information for POA&M activities. Support the collection and use of data for our critical Information Assurance Vulnerability Management (IAVM) Program using various security tools (i.e. ACAS, HBSS, ADUC, Burp Suite, etc). • Develop and implement hardware and software evaluation (sandboxing) capability and procedures prior to introduction to network computing environment. Support security impact analysis and risk management decision cycle. • Maintain a thorough understanding of computer hardware, network devices, components, security appliances etc. to enable review of vulnerabilities and validate developer mitigation courses of action. • Provide detailed security-related reports including data, analyses, and conclusions upon completion of tests, scans, and assessments, including mitigations and, if indicated, appropriate escalation of identified risks and vulnerabilities. • Lead and/or participate in the development of information system security policy and standards, including writing guidelines, standards, procedures, and other technical documentation (technical roadmaps, project plans, etc.). • Maintain communication with project-level stakeholders and manage project scope and expectation to ensure requirements are understood, enabling swift delivery. • Maintain proficiency of their knowledge of the latest security engineering techniques and technologies, advances in combating unauthorized access to information systems, and industry best practices. Assist CCM team members with keeping up to date on latest security engineering techniques and technologies, advances in combating unauthorized access to information systems, and industry best practices.

Requirements

• U.S. citizenship • Secret Clearance • Bachelor’s degree or higher in an Information Technology field or equivalent work experience. • Possession of one of these IAT Level II Security Certifications: - Cisco Certified Network Associate - Security (CCNA Security) - CompTIA Cybersecurity Analyst (CySA+) - Global Industrial Cyber Security Professional (GICSP) - GIAC Security Essentials (GSEC) - CompTIA Security+ (SEC+ CE) - Certified Network Defender (CND) - ISC2 Systems Security Certified Practitioner (SSCP) • Experience with Security Automation Framework (SAF) tools and scripting in Ruby a plus (but not required).

Benefits

• Competitive salary • Medical/dental/vision insurance • Life insurance • Paid time off • Paid holidays • 401(k) retirement plan with company match • Opportunities for professional growth • Cell phone discounts • TestPros, Inc. is an Equal Opportunity Employer. • All benefits are per TestPros current policies and are subject to change without notice. Benefits are available to full-time employees.

Apply Now
Built by Lior Neu-ner. I'd love to hear your feedback — Get in touch via DM or lior@remoterocketship.com