Job Requirements
Annapolis Junction, MD
Top Secret/SCI Full Scope Polygraph
Mid Level Career (5+ yrs experience)
Salary not specified
Join Premium to unlock estimated salaries
Job Description
Location: Annapolis Junction, MD
Schedule: Part-Time – Evenings and Weekends
Clearance: Active TS/SCI with Full Scope Polygraph required
Position Overview
Our client is seeking a Vulnerability Assessment Analyst / Information Systems Security Engineer (ISSE) to support vulnerability management and continuous monitoring activities in a highly secure environment. The position will focus heavily on Tenable Security Center, Nessus/ACAS vulnerability scanning, DISA STIG compliance, vulnerability remediation, and Windows/Linux security.
The position is based at a contractor site in Annapolis Junction, Maryland, with a part-time evening and weekend schedule.
Responsibilities
Maintain and optimize the Tenable Security Center infrastructure.
Perform security assessments, patching, and vulnerability scans of Linux Security Center servers using Tenable Nessus.
Identify and mitigate DISA STIG findings and vulnerabilities across Tenable Security Center and Windows/Linux Nessus scanning servers.
Install, configure, maintain, and update Tenable Nessus and Tenable Security Center software.
Configure and fine-tune vulnerability scanning policies and asset lists to ensure comprehensive coverage.
Conduct recurring vulnerability assessments across multiple device types and operating systems.
Use Nessus/ACAS to identify vulnerabilities across customer assets as part of continuous monitoring activities.
Review and analyze Nessus/ACAS scan results and provide remediation guidance.
Analyze vulnerability scan results and develop comprehensive reports.
Monitor and track vulnerability remediation activities through completion.
Coordinate with Information Systems Security personnel and other technical teams to ensure vulnerabilities are addressed in a timely manner.
Communicate security posture, vulnerabilities, and potential risks to technical and management stakeholders.
Maintain accurate documentation and records related to vulnerabilities and security incidents.
Required Qualifications
Active TS/SCI clearance with Full Scope Polygraph.
Hands-on experience with enterprise vulnerability management and scanning solutions such as Tenable Security Center, Tenable Nessus, and/or ACAS.
Familiarity with DISA STIGs, Tenable Audit Files, and/or CIS Benchmarks.
Knowledge of system and application security threats and vulnerabilities.
Working knowledge of:
Linux/Unix administration
Windows administration
Networking
Patch deployment
System configuration
Ability to analyze vulnerability scan results and support remediation efforts.
Education & Experience
Candidates must meet one of the following combinations:
High School Diploma/GED + 11 years of relevant experience, OR
Bachelor's Degree + 7 years of relevant experience.
Certification Requirements
Must meet DoD 8570 IAT Level II requirements.
Acceptable certifications identified for the position include:
CompTIA Security+ CE
CEH
Training alone is not acceptable as a substitute for the required CE certification.
Preferred Qualifications
In-depth knowledge of vulnerability assessment methodologies, tools, and industry best practices.
Strong analytical and problem-solving skills with excellent attention to detail.
Self-starter capable of owning technical tasks from beginning to end.
Ability to work effectively both independently and as part of a technical team.
Strong written and verbal communication skills for presenting vulnerability findings and security risks to stakeholders.
Security Requirements
Candidates must possess an active TS/SCI clearance with Full Scope Polygraph and be able to operate as a privileged user within the supported environment.
Schedule: Part-Time – Evenings and Weekends
Clearance: Active TS/SCI with Full Scope Polygraph required
Position Overview
Our client is seeking a Vulnerability Assessment Analyst / Information Systems Security Engineer (ISSE) to support vulnerability management and continuous monitoring activities in a highly secure environment. The position will focus heavily on Tenable Security Center, Nessus/ACAS vulnerability scanning, DISA STIG compliance, vulnerability remediation, and Windows/Linux security.
The position is based at a contractor site in Annapolis Junction, Maryland, with a part-time evening and weekend schedule.
Responsibilities
Maintain and optimize the Tenable Security Center infrastructure.
Perform security assessments, patching, and vulnerability scans of Linux Security Center servers using Tenable Nessus.
Identify and mitigate DISA STIG findings and vulnerabilities across Tenable Security Center and Windows/Linux Nessus scanning servers.
Install, configure, maintain, and update Tenable Nessus and Tenable Security Center software.
Configure and fine-tune vulnerability scanning policies and asset lists to ensure comprehensive coverage.
Conduct recurring vulnerability assessments across multiple device types and operating systems.
Use Nessus/ACAS to identify vulnerabilities across customer assets as part of continuous monitoring activities.
Review and analyze Nessus/ACAS scan results and provide remediation guidance.
Analyze vulnerability scan results and develop comprehensive reports.
Monitor and track vulnerability remediation activities through completion.
Coordinate with Information Systems Security personnel and other technical teams to ensure vulnerabilities are addressed in a timely manner.
Communicate security posture, vulnerabilities, and potential risks to technical and management stakeholders.
Maintain accurate documentation and records related to vulnerabilities and security incidents.
Required Qualifications
Active TS/SCI clearance with Full Scope Polygraph.
Hands-on experience with enterprise vulnerability management and scanning solutions such as Tenable Security Center, Tenable Nessus, and/or ACAS.
Familiarity with DISA STIGs, Tenable Audit Files, and/or CIS Benchmarks.
Knowledge of system and application security threats and vulnerabilities.
Working knowledge of:
Linux/Unix administration
Windows administration
Networking
Patch deployment
System configuration
Ability to analyze vulnerability scan results and support remediation efforts.
Education & Experience
Candidates must meet one of the following combinations:
High School Diploma/GED + 11 years of relevant experience, OR
Bachelor's Degree + 7 years of relevant experience.
Certification Requirements
Must meet DoD 8570 IAT Level II requirements.
Acceptable certifications identified for the position include:
CompTIA Security+ CE
CEH
Training alone is not acceptable as a substitute for the required CE certification.
Preferred Qualifications
In-depth knowledge of vulnerability assessment methodologies, tools, and industry best practices.
Strong analytical and problem-solving skills with excellent attention to detail.
Self-starter capable of owning technical tasks from beginning to end.
Ability to work effectively both independently and as part of a technical team.
Strong written and verbal communication skills for presenting vulnerability findings and security risks to stakeholders.
Security Requirements
Candidates must possess an active TS/SCI clearance with Full Scope Polygraph and be able to operate as a privileged user within the supported environment.
group id: 91172276