Vulnerability Assessment Analyst / Information Systems Security Engineer (ISSE)
Omniscius Consulting Annapolis Junction, Maryland, United States
Business Consulting and Services · 1 employee
About the role
The analyst will maintain and optimize Tenable Security Center infrastructure while performing recurring vulnerability scans and assessments. They are responsible for identifying and mitigating security findings, tracking remediation activities, and reporting the security posture to stakeholders.
What they look for
Requirements
Candidates must possess an active TS/SCI clearance with Full Scope Polygraph and meet DoD 8570 IAT Level II certification requirements. The role requires either a high school diploma with 11 years of experience or a bachelor's degree with 7 years of experience.
Full description
Location: Annapolis Junction, MD Schedule: Part-Time – Evenings and Weekends Clearance: Active TS/SCI with Full Scope Polygraph required
Position Overview
Our client is seeking a Vulnerability Assessment Analyst / Information Systems Security Engineer (ISSE) to support vulnerability management and continuous monitoring activities in a highly secure environment. The position will focus heavily on Tenable Security Center, Nessus/ACAS vulnerability scanning, DISA STIG compliance, vulnerability remediation, and Windows/Linux security.
The position is based at a contractor site in Annapolis Junction, Maryland, with a part-time evening and weekend schedule.
Responsibilities
- Maintain and optimize the Tenable Security Center infrastructure.
- Perform security assessments, patching, and vulnerability scans of Linux Security Center servers using Tenable Nessus.
- Identify and mitigate DISA STIG findings and vulnerabilities across Tenable Security Center and Windows/Linux Nessus scanning servers.
- Install, configure, maintain, and update Tenable Nessus and Tenable Security Center software.
- Configure and fine-tune vulnerability scanning policies and asset lists to ensure comprehensive coverage.
- Conduct recurring vulnerability assessments across multiple device types and operating systems.
- Use Nessus/ACAS to identify vulnerabilities across customer assets as part of continuous monitoring activities.
- Review and analyze Nessus/ACAS scan results and provide remediation guidance.
- Analyze vulnerability scan results and develop comprehensive reports.
- Monitor and track vulnerability remediation activities through completion.
- Coordinate with Information Systems Security personnel and other technical teams to ensure vulnerabilities are addressed in a timely manner.
- Communicate security posture, vulnerabilities, and potential risks to technical and management stakeholders.
- Maintain accurate documentation and records related to vulnerabilities and security incidents.
Required Qualifications
- Active TS/SCI clearance with Full Scope Polygraph.
- Hands-on experience with enterprise vulnerability management and scanning solutions such as Tenable Security Center, Tenable Nessus, and/or ACAS.
- Familiarity with DISA STIGs, Tenable Audit Files, and/or CIS Benchmarks.
- Knowledge of system and application security threats and vulnerabilities.
- Working knowledge of:• Linux/Unix administration
- Windows administration
- Networking
- Patch deployment
- System configuration
- Ability to analyze vulnerability scan results and support remediation efforts.
Education & Experience
Candidates must meet one of the following combinations:
- High School Diploma/GED + 11 years of relevant experience, OR
- Bachelor's Degree + 7 years of relevant experience.
Certification Requirements
- Must meet DoD 8570 IAT Level II requirements.
- Acceptable certifications identified for the position include:• CompTIA Security+ CE
- CEH
Training alone is not acceptable as a substitute for the required CE certification.
Preferred Qualifications
- In-depth knowledge of vulnerability assessment methodologies, tools, and industry best practices.
- Strong analytical and problem-solving skills with excellent attention to detail.
- Self-starter capable of owning technical tasks from beginning to end.
- Ability to work effectively both independently and as part of a technical team.
- Strong written and verbal communication skills for presenting vulnerability findings and security risks to stakeholders.
Security Requirements
Candidates must possess an active TS/SCI clearance with Full Scope Polygraph and be able to operate as a privileged user within the supported environment.
Similar roles
-
Senior Security Engineer - DevSecOps
carsales Sydney, New South Wales, Australia
-
Lead Cloud Security Engineer (DevSecOps)
Bilue Taguig, National Capital District, Philippines
-
Senior Security Engineer - Detection Engineering
LinkedIn United States · $129K–$212K/yr
-
Security Engineer
AlertMedia Austin, Texas, United States
-
F-35 Air Systems Information System Security Engineer | Active Secret clearance
General Dynamics Information Technology Eglin AFB, Florida, United States · $128K–$172K/yr
-
Full-Stack Engineers (Cybersecurity): Feedback On CI/CD Workflows
Terac United States · $218K/yr