VULNERABILITY ASSESSMENT ANALYST
Quantum Research International, Inc. (Quantum) is a certified DoD Contractor providing services and products to U.S./Allied governments and industry in cybersecurity, high performance computing systems, cloud services, space and ground support systems, aviation systems, missile systems, artificial intelligence/machine learning systems, and audio-visual systems and services. Quantum’s Corporate Office is in Huntsville, AL, with physical locations in Aberdeen, MD; Colorado Springs, CO; Orlando, FL; Crestview, FL; Madison, AL; and Tupelo, MS.
About the Role
As a member of the NGA Defender Cybersecurity Vulnerability Management team, the contractor executes the Vulnerability Management aspect of the Risk Management Framework (RMF) in accordance with NIST SP 800-37 R2 (or subsequent versions) and National Geospatial-Intelligence Agency's (NGA) RMF Implementation Guide (RIG) for all NGA-authorized systems. This position supports NGA in Springfield, VA and is on-site only. No remote/hybrid work.
Responsibilities
- Perform assessments of systems and networks within the network environment or enclave and identify where systems/networks deviate from acceptable configurations, enclave policy, or local policy.
- Review, promulgate, and track Cyber Task Orders.
- Coordinate and assist the relevant information system owners to resolve findings.
- Develop measures of effectiveness for defense-in-depth architectures against known vulnerabilities.
- Identify systemic security issues based on the analysis of vulnerability and configuration (STIG) data.
- Prioritize vulnerability reduction activities based on threat data, vulnerability severity, and mission criticality.
- Conduct vulnerability scans and mitigate vulnerabilities in security systems.
- Analyze web application vulnerability assessments to recommend remediation action for known web application vulnerabilities and misconfigurations.
- Apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).
Requirements
- Bachelor’s degree (technically relevant degree preferred). In lieu of degree, candidates may qualify with experience combined with one of the following certifications: Security+, PenTest+, GSEC, GICSP, GCSA, GCIH, GCED, FITSP-A, CPTE, Cloud+, RCCE Level 1, CEH (Practical).
- TS/SCI eligible, subject to CI Polygraph.
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or other relevant fields.
- Experience in vulnerability management using tools such as Nessus, ACAS, Tenable, etc.
- Knowledge of computer networking concepts and protocols, and network security methodologies.
- Understanding of risk management processes (e.g., methods for assessing and mitigating risk).
- Familiarity with laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.
- Knowledge of cyber threats and vulnerabilities, and operational impacts of cybersecurity lapses.
- Knowledge of cryptography and cryptographic key management concepts.
- Knowledge of applicable cyber defense policies, regulations, and compliance documents specifically related to cyber defense auditing.
- Knowledge of what constitutes a network attack and a network attack’s relationship to both threats and vulnerabilities.
- Ability to collaborate with IT asset owners to create vulnerability remediation plans using a positive customer service mindset.
Skills
- Experience with vulnerability and/or threat data visualization (Tableau, etc).