Omniscius Consulting

Vulnerability Assessment Analyst / Information Systems Security Engineer (ISSE)

Omniscius Consulting Annapolis Junction, Maryland, United States

Business Consulting and Services · 1 employee

Yesterday
security Principal (10+ yrs) Part-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The analyst will maintain and optimize Tenable Security Center infrastructure while performing recurring vulnerability scans and assessments. They are responsible for identifying and mitigating security findings, tracking remediation activities, and reporting the security posture to stakeholders.

What they look for

Tenable Security Center Nessus ACAS DISA STIG Vulnerability Management Linux Administration Windows Administration Networking Patch Deployment System Configuration Continuous Monitoring Security Assessment Vulnerability Remediation Information Systems Security Risk Analysis

Requirements

Candidates must possess an active TS/SCI clearance with Full Scope Polygraph and meet DoD 8570 IAT Level II certification requirements. The role requires either a high school diploma with 11 years of experience or a bachelor's degree with 7 years of experience.

Full description

Location: Annapolis Junction, MD Schedule: Part-Time – Evenings and Weekends Clearance: Active TS/SCI with Full Scope Polygraph required

Position Overview

Our client is seeking a Vulnerability Assessment Analyst / Information Systems Security Engineer (ISSE) to support vulnerability management and continuous monitoring activities in a highly secure environment. The position will focus heavily on Tenable Security Center, Nessus/ACAS vulnerability scanning, DISA STIG compliance, vulnerability remediation, and Windows/Linux security.

The position is based at a contractor site in Annapolis Junction, Maryland, with a part-time evening and weekend schedule.

Responsibilities

  • Maintain and optimize the Tenable Security Center infrastructure.
  • Perform security assessments, patching, and vulnerability scans of Linux Security Center servers using Tenable Nessus.
  • Identify and mitigate DISA STIG findings and vulnerabilities across Tenable Security Center and Windows/Linux Nessus scanning servers.
  • Install, configure, maintain, and update Tenable Nessus and Tenable Security Center software.
  • Configure and fine-tune vulnerability scanning policies and asset lists to ensure comprehensive coverage.
  • Conduct recurring vulnerability assessments across multiple device types and operating systems.
  • Use Nessus/ACAS to identify vulnerabilities across customer assets as part of continuous monitoring activities.
  • Review and analyze Nessus/ACAS scan results and provide remediation guidance.
  • Analyze vulnerability scan results and develop comprehensive reports.
  • Monitor and track vulnerability remediation activities through completion.
  • Coordinate with Information Systems Security personnel and other technical teams to ensure vulnerabilities are addressed in a timely manner.
  • Communicate security posture, vulnerabilities, and potential risks to technical and management stakeholders.
  • Maintain accurate documentation and records related to vulnerabilities and security incidents.

Required Qualifications

  • Active TS/SCI clearance with Full Scope Polygraph.
  • Hands-on experience with enterprise vulnerability management and scanning solutions such as Tenable Security Center, Tenable Nessus, and/or ACAS.
  • Familiarity with DISA STIGs, Tenable Audit Files, and/or CIS Benchmarks.
  • Knowledge of system and application security threats and vulnerabilities.
  • Working knowledge of:• Linux/Unix administration
  • Windows administration
  • Networking
  • Patch deployment
  • System configuration
  • Ability to analyze vulnerability scan results and support remediation efforts.

Education & Experience

Candidates must meet one of the following combinations:

  • High School Diploma/GED + 11 years of relevant experience, OR
  • Bachelor's Degree + 7 years of relevant experience.

Certification Requirements

  • Must meet DoD 8570 IAT Level II requirements.
  • Acceptable certifications identified for the position include:• CompTIA Security+ CE
  • CEH

Training alone is not acceptable as a substitute for the required CE certification.

Preferred Qualifications

  • In-depth knowledge of vulnerability assessment methodologies, tools, and industry best practices.
  • Strong analytical and problem-solving skills with excellent attention to detail.
  • Self-starter capable of owning technical tasks from beginning to end.
  • Ability to work effectively both independently and as part of a technical team.
  • Strong written and verbal communication skills for presenting vulnerability findings and security risks to stakeholders.

Security Requirements

Candidates must possess an active TS/SCI clearance with Full Scope Polygraph and be able to operate as a privileged user within the supported environment.

Similar roles