Systems Security Engineer
ELEVI Associates · Annapolis Junction, MD · 1 wk ago
On-siteInformation TechnologyFull-time
Requirements
- Must be willing to work in the Annapolis Junction, MD area
- Must have a current and active security clearance with polygraph
- Four (4) years of experience as an SWE in programs and contracts of similar scope, type, and complexity
- Bachelor's degree in a technical discipline from an accredited college or university required (five (5) years of additional system administration experience may be substituted)
- Sec+ or higher required
- Familiarity with DISA STIGs, Tenable Audit files, and/or CIS Benchmarks
- Hands-on operational experience with enterprise vulnerability management and scanning solutions, such as Tenable
- Knowledge of system and application security threats and vulnerabilities
- Working knowledge of networking, Linux/Unix, Windows administration, patch deployment and system configuration
Schedule
- PT - Evenings and weekends
Responsibilities
- Maintain and optimize the Tenable Security Center infrastructure
- Conduct regular security patching, assessments and scans on Linux Security Center servers using Tenable Nessus
- Mitigate STIGS/Vulnerabilities on Tenable Linux Security Center Servers and Windows/Linux Nessus Scanning Servers
- Install and update Tenable Nessus Software on Linux/Windows Scanning Servers
- Install and update Tenable Security Center Software on Linux Servers
- Configure and fine-tune scanning policies and asset lists to ensure thorough vulnerability coverage
- Keep abreast of the latest Tenable Security Center features and updates
- Perform regular vulnerability assessments of multiple device types and Operating Systems using Tenable Security Center
- Utilize Nessus Scanning Tool to identify vulnerabilities across customer assets on a Continuous Monitoring basis
- Review Nessus/ACAS scan results and provide direction where required
- Recognize potential, successful, and unsuccessful scan results for efficiency in reporting compromises through thorough reviews and analyses of relevant event detail and summary information
- Analyze scan results and generate comprehensive vulnerability reports
- Monitor and track vulnerability remediation progress
- Collaborate with ISS and other teams to ensure timely vulnerability remediation
- Communicate effectively with stakeholders about the security posture and potential risks
- Prepare and deliver clear and concise reports to management and stakeholders
- Maintain accurate records of security incidents and vulnerabilities
Pay
The proposed salary range for this position is 65,000-150,500.
Benefits
- Healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits
- Work/life benefits
- Flexible time off policy ("No need to keep track or save up")
- Competitive compensation and learning and development opportunities