System Administrator 3
ACS Professional Staffing · Vancouver, WA · 1 wk ago
Information Technology$43.36–$61.95/hrContract
ACS Professional Staffing is looking for an on-site System Administrator 3 to perform vulnerability scanning and security assessments across networks, systems, and applications, analyze and remediate threats, and maintain security tools and reporting.
About the role
This full-time position is located in Vancouver, WA. The role requires hands-on experience in enterprise vulnerability management, secure configurations, and 24/7 high-availability environments. Candidates will support compliance, develop SOPs, automate processes, and collaborate with stakeholders to resolve risks.
Responsibilities
- Perform Control Center Cyber Vulnerability Scanning: define, identify, and classify security vulnerabilities in computer, network, or communications infrastructure.
- Interact with business units to discover, triage, and resolve security vulnerabilities using manual and automated tools as part of a Secure Development Life Cycle.
- Research and investigate new and emerging vulnerabilities; analyze vulnerabilities to characterize threats and provide remediation recommendations.
- Forecast the effectiveness of proposed countermeasures and evaluate their actual effectiveness after implementation.
- Conduct vulnerability assessments (application and/or infrastructure) and articulate security issues to technical and non-technical audiences using tools such as NMAP, Nessus, or related tools.
- Operate and analyze results of open-source security tools and vulnerability scanners including Wireshark, ngrep, nmap, and Snort.
- Analyze network and wireless traffic, reporting abnormal activity to management.
- Compile vulnerability data from multiple sources and track technical resolution and mitigation times.
- Report findings and maintain ongoing assessments for regulatory reporting; collaborate with internal groups to develop remediation recommendations.
- Present recommended remediation plans for management/stakeholder review and approval; track and follow through to completion assigned remediation activities.
- Assist with vulnerability assessments of network devices, operating systems, and network-enabled software applications on both Windows and Linux platforms; perform network discovery and comparison with known cyber assets.
- Configure vulnerability assessment tools, perform scans, research and analyze vulnerabilities, identify relevant threats, and provide corrective action recommendations.
- Identify critical flaws in applications and systems that cyber attackers could exploit; conduct vulnerability assessments for networks, applications, and operating systems.
- Use automated tools (e.g., Nessus) to pinpoint vulnerabilities and reduce time-consuming tasks; apply manual testing techniques to reduce false negatives.
- Develop, test, and modify custom scripts and applications for vulnerability testing; manually validate report findings to reduce false positives.
- Compile and track vulnerabilities over time for metrics purposes; write and present comprehensive Vulnerability Assessments on new systems.
- Review and define requirements for information security solutions; supply hands-on training to network and system administrators on the vulnerability scanning program.
- Develop and maintain a vulnerability assessment database; perform trend and analysis of vulnerability scan data.
- Generate reports identifying security posture (e.g., deficiencies, history of repeats); develop Transmission Operations Standard Operating Procedures (SOPs), checklists, guides, best practices, and procedures for conducting vulnerability assessments.
- Automate procedures using scripts, SQL/database administration, or other available technology; report repeat high vulnerabilities to the communications unit monthly.
- Maintain functionality of vulnerability management tools including configuration and maintenance of applications (e.g., Nessus, Tenable Security Center).
- Perform information system security vulnerability scanning to discover and analyze vulnerabilities and characterize risks to networks, operating systems, applications, databases, and other information system components.
- Perform compliance scanning to analyze configurations and facilitate implementation of hardening settings for networks, operating systems, applications, databases, and other information system components.
- Engage with stakeholders, including IT professionals, management, and auditors, to facilitate vulnerability discovery and remediation.
- Communicate security and compliance issues effectively to management, customers, and stakeholders; recommend remedial actions to mitigate risks.
- Analyze Vulnerability scan results and engage with customers to resolve identified vulnerabilities; validate remedial actions and verify compliance with information security policy and regulatory requirements.
- Assist in development and implementation of information security vulnerability management policies, procedures, and standards based on NIST 800-53 standards, best practices, and compliance requirements.
- Maintain filing systems, files, emails, and records in accordance with compliance requirements; validate official records are accurately maintained for auditing purposes.
Requirements
- 2 years’ experience with:
- Classes of vulnerabilities, appropriate remediation, and industry standard classification schemes (CVE, CVSS, CPE).
- Linux and Windows operating systems, including common programming or scripting languages.
- Devising methods to automate testing activities and streamline testing processes.
- Security vulnerabilities, application analysis, and protocol analysis.
- Setting up and administering an enterprise cyber-vulnerability scanning and assessment infrastructure.
- A degree in Computer Science, Information Technology, or a directly related technical discipline is preferred.
- 8 years of experience is required with an applicable associate or bachelor’s degree; 10 years of experience is required without an applicable degree or with no degree.
- Experience includes a minimum combination of work-related experience, on-the-job training, and/or vocational training, progressively more technical in nature.
- Knowledge of:
- Patching programs of major hardware/software manufacturers.
- Secure configuration and hardening of systems.
- Methods for ongoing evaluation of the effectiveness and applicability of information security controls (e.g., vulnerability testing and assessment tools).
- Network topology, communication protocols, firewalls, proxies, and IDS systems to effectively configure scanning software.
- Experience administering computer systems in a 24/7 high-availability operational environment; experience using specific technologies such as Splunk.
- Experience administering Tenable.sc and Nessus.
- Valid U.S. Driver’s License is required; U.S. citizenship is required for this position.
Benefits
- Paid holidays: 11
- PTO: Starting at 10 days
- Sick Leave: Up to 56 hours per year (prorated based on start date)
- Employee Assistance Program (EAP)
- Benefit Options Available:
- Medical, Dental, Vision
- FSA, DCA, LPFSA, HSA
- Group Life/AD&D, Voluntary Life/AD&D
- Voluntary Short-Term Disability, Voluntary Long-Term Disability
- Voluntary Critical Illness, Voluntary Accident, Hospital Indemnity
- 401k (immediately eligible for employee and employer contributions - employer match up to 4%)
- Other benefits:
- Calm App
- LifeBalance Discount Program
Pay
$43.36 - $61.95 per hour