Company

Xor SecuritySee more

addressAddressWashington, DC
salary Salary$106K - $134K a year
CategoryInformation Technology

Job description

  • Job Title:Vulnerability Management Analyst


    Location: 1155 21st St NW Washington DC, District of Columbia 20036
    Clearance Level: Public Trust
    Required Certification(s):
    Current industry certification such as CASP, CAP, CISSP, CISM, GSEC, GMON, or Security+.
    SUMMARY:
    The Vulnerability Management Analyst will join a team of cross-functional cybersecurity experts in support of a government agency's Governance, Risk and Compliance Program. As a member of this team, the Vulnerability Management Analyst will support ongoing Vulnerability Management activities and future initiatives to achieve the agency's strategic goals and objectives.

    The ideal Vulnerability Management Analyst candidate is an independent, strong problem solver who thrives in fast-paced and evolving security environments. The candidate has a passion for mitigating security risk and isn't deterred by the rapidly evolving nature of the threat landscape. The Vulnerability Management Analyst will join a team of cross-functional cybersecurity experts in the performance of activities, including assessments & authorization (A&A) and ongoing authorization (OA), security engineering, identity and access management (IAM), cloud security architecture, Vulnerability Management, cybersecurity training, and policy development for a government agency. The Vulnerability Management Analyst must have SME knowledge of scanning applications, to include Qualys, a deep understanding of Vulnerability Management, and the ability to implement effective strategies and approaches to communicate, coordinate, and mitigate vulnerability-related security risks.


    JOB DUTIES AND RESPONSIBILITIES
    Leverage enterprise scanning applications or tools approved by the government in support of the Vulnerability Management Program.
    Provide routine and ad-hoc automated vulnerability scans, scans in support of audits, scan result analysis, and validation scans of remediated vulnerabilities identified during vulnerability assessments.
    Support vulnerability scans of information systems for on-premise and hybrid cloud systems, as necessary.
    Support scanning and testing at the application and database level and refine and mature scanning metrics and thresholds to improve program maturity.
    Normalize data and provide results to system owners, system administrators, and Information Systems Security Officers (ISSOs) in support of change requests, ongoing authorizations, or systems undergoing authorizations to operate.
    Analyze weekly DHS Cyber Hygiene reports, facilitate remediation of findings therein, and promote comprehensive scanning coverage of all Internet-reachable IT assets.
    Identify corrective actions, compensating controls, and assist with POA&M development in the government agency's GRC tool.
    Identify mitigations for non-compliance, notify stakeholders of compliance issues and, where required, perform these mitigations.
    Take into account any infrastructure challenges and make recommendations for improvements where needed. This includes third party service provider hosted Software as a Service (SaaS), Platform as a Service (PaaS) instances as well as Infrastructure as a Service (IaaS)
    Provide expertise in the review of new vulnerability technologies and capabilities and interact with other technology divisions to facilitate deployment.
    SUPERVISORY DUTIES
    This is non-supervisory position.
    QUALIFICATIONS
    Required Certifications
    Current industry certification such as CASP, CAP, CISSP, CISM, GSEC, GMON, or Security+.
    Education, Background, and Years of Experience
    Bachelor's Degree in Computer Science, Computer Engineering, Information Systems.
    7 years of experience in Information Assurance (IA) or cybersecurity with at least 3 years of experience in Vulnerability Management.
    ADDITIONAL SKILLS & QUALIFICATIONS
    Required Skills
    Experience with vulnerability scanning applications, to include Qualys and DBProtect.
    Experience analyzing results, normalizing data, and communicating with broad IT/non-IT stakeholder groups.
    Experience with STIG compliance baselines.
    Experience with NIST 800-53 security controls and compliance frameworks, such as NIST CSF and NIST RMF.
    Excellent communication skills, including verbal and written.
    Strong presentation skills required.
    Preferred Skills
    Experience with BurpSuite preferred.
    Experience facilitating and/or participating in risk acceptance reviews and approvals desired.
    WORKING CONDITIONS
    Environmental Conditions
    Contractor site with 0% travel possible. Possible occasional off-hours work to support non-business hours scanning for critical systems. Customer site is a general office environment. Work is generally sedentary in nature but may require standing and walking for up to 10% of the time. The working environment is generally favorable. Lighting and temperature are adequate, and there are not hazardous or unpleasant conditions caused by noise, dust, etc. Work performed at customer site is within an office environment, with standard office equipment available.
    Strength Demands
    Sedentary – 10 lbs. Maximum lifting, occasional lift/carry of small articles. Some occasional walking or standing may be required. Jobs are sedentary if walking and standing are required only occasionally, and all other sedentary criteria are met.
    Physical Requirements
    Stand or Sit; Walk; Repetitive Motion; Use Hands / Fingers to Handle or Feel; See

Closing Statement:

XOR Security, an Agile Defense Company offers a very competitive benefits package including health insurance coverage from the first day of employment, 401k with a vested company match, vacation and supplemental insurance benefits.

XOR Security, An Agile Defense Company is an Equal Opportunity Employer (EOE). M/F/D/V.

Citizenship Clearance Requirement
Applicants selected may be subject to a government security investigation and must meet eligibility requirements - US CITIZENSHIP and PUBLIC TRUST CLEARANCE REQUIRED.

Benefits

Health insurance, 401(k), 401(k) matching
Refer code: 8444219. Xor Security - The previous day - 2024-03-04 02:48

Xor Security

Washington, DC
Popular Management Analyst jobs in top cities
Jobs feed

Associate Manager, Data Engineer

Sc Johnson & Son

Racine, WI

Data Analyst II

Bcforward

Waukesha, WI

Validation Engineer

Triunity Software

Round Lake, IL

Public Relations Specialist

Kennesaw State University

Kennesaw, GA

Test Engineer

Foxconn Industrial Internet

Wisconsin, United States

Yard Spotter

Sysco

Olin, NC

Warehouse Material Handler

Henkel

Chanhassen, MN

Coating Application Engineer

Henkel

Boston, MA

Engineer I

Belcan

Waukesha, WI

Share jobs with friends

Related jobs

Vulnerability Management Analyst - Hybrid

Risk Management Analyst

Sayres Defense

$80k-105k (estimate)

Washington, DC

3 days ago - seen

Management Analyst

Caci

$78k-111k (estimate)

Washington, DC

7 days ago - seen

Management and Program Analyst FOIA

Cape Fox Ss

Washington, DC

a week ago - seen

Management Analyst - Data Analysis (Secret Clearance Required)

One Federal Solution

$34 - $40 an hour

Washington, DC

3 weeks ago - seen

Quality Assurance Analyst

Capstone Management Consulting, Llc

$90,000 - $105,000 a year

Washington, DC

3 weeks ago - seen

Risk Management Analyst

Blue Rose Consulting Group, Inc.

Washington, DC

4 weeks ago - seen

DHCF DCAS – Account Management Analyst (725886)

Barrow Consulting Inc

$74.6K - $94.4K a year

Washington, DC

4 weeks ago - seen

Sr. Ship Acquisition Analyst ? Configuration Manager

The Columbia Group

$96.5K - $122K a year

Washington, DC

4 weeks ago - seen

Senior Management Analyst - Technical Editor

Noblis

$109,100 - $190,900 a year

Washington, DC

4 weeks ago - seen

Supervisory Management and Program Analyst

U.s. Department Of Justice

$163,964 - $191,900 a year

Washington, DC

4 weeks ago - seen

Project Management Consultant / Data Analyst for DHS (95% remote)

Quasars Inc.

$120,000 a year

Washington, DC

4 weeks ago - seen

IT Portfolio Management Analyst II

Centene Corporation

Washington, DC

a month ago - seen

Senior Budget Management Analyst

Metaphase Consulting

$80,000 - $90,000 a year

Washington, DC

a month ago - seen

Risk and Threat Management Analyst #738

Us Senate

$94,500 - $160,000 a year

Washington, DC

a month ago - seen

Management & Program Analyst

Us Internal Revenue Service

$122,198 - $181,216 a year

Washington, DC

a month ago - seen

Cyber Risk Management Analyst

Criterion Systems, Inc.

$104K - $131K a year

Washington, DC

a month ago - seen

Management Analyst

Us Library Of Congress

$99,200 - $128,956 a year

Washington, DC

a month ago - seen

Management & Program Analyst (Data Analytics)

National Transportation Safety Board

Washington, DC

a month ago - seen