Jobs · OTHR · Virginia

VULNERABILITY ASSESSMENT ANALYST

Quantum Research International · Springfield, VA · 3 days ago
On-siteOTHRFull-time

Quantum Research International, Inc. (Quantum) is a certified DoD Contractor providing services and products to U.S./Allied governments and industry in cybersecurity, high performance computing systems, cloud services, space and ground support systems, aviation systems, missile systems, artificial intelligence/machine learning systems, and audio-visual systems and services. Quantum’s Corporate Office is in Huntsville, AL, with physical locations in Aberdeen, MD; Colorado Springs, CO; Orlando, FL; Crestview, FL; Madison, AL; and Tupelo, MS.

About the Role

As a member of the NGA Defender Cybersecurity Vulnerability Management team, the contractor executes the Vulnerability Management aspect of the Risk Management Framework (RMF) in accordance with NIST SP 800-37 R2 (or subsequent versions) and National Geospatial-Intelligence Agency's (NGA) RMF Implementation Guide (RIG) for all NGA-authorized systems. This position supports NGA in Springfield, VA and is on-site only. No remote/hybrid work.

Responsibilities

  • Perform assessments of systems and networks within the network environment or enclave and identify where systems/networks deviate from acceptable configurations, enclave policy, or local policy.
  • Review, promulgate, and track Cyber Task Orders.
  • Coordinate and assist the relevant information system owners to resolve findings.
  • Develop measures of effectiveness for defense-in-depth architectures against known vulnerabilities.
  • Identify systemic security issues based on the analysis of vulnerability and configuration (STIG) data.
  • Prioritize vulnerability reduction activities based on threat data, vulnerability severity, and mission criticality.
  • Conduct vulnerability scans and mitigate vulnerabilities in security systems.
  • Analyze web application vulnerability assessments to recommend remediation action for known web application vulnerabilities and misconfigurations.
  • Apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).

Requirements

  • Bachelor’s degree (technically relevant degree preferred). In lieu of degree, candidates may qualify with experience combined with one of the following certifications: Security+, PenTest+, GSEC, GICSP, GCSA, GCIH, GCED, FITSP-A, CPTE, Cloud+, RCCE Level 1, CEH (Practical).
  • TS/SCI eligible, subject to CI Polygraph.
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or other relevant fields.
  • Experience in vulnerability management using tools such as Nessus, ACAS, Tenable, etc.
  • Knowledge of computer networking concepts and protocols, and network security methodologies.
  • Understanding of risk management processes (e.g., methods for assessing and mitigating risk).
  • Familiarity with laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.
  • Knowledge of cyber threats and vulnerabilities, and operational impacts of cybersecurity lapses.
  • Knowledge of cryptography and cryptographic key management concepts.
  • Knowledge of applicable cyber defense policies, regulations, and compliance documents specifically related to cyber defense auditing.
  • Knowledge of what constitutes a network attack and a network attack’s relationship to both threats and vulnerabilities.
  • Ability to collaborate with IT asset owners to create vulnerability remediation plans using a positive customer service mindset.

Skills

  • Experience with vulnerability and/or threat data visualization (Tableau, etc).

Similar jobs

Vulnerability Analyst

Edgewater Federal Solutions, Inc.Bethesda, MD· 3 wk ago
Business Development$70k–$90k/yrapply on careers-edgewaterit.icims.com

Vulnerability Analyst

Y-12 National Security ComplexOak Ridge, TN· 4 wk ago
Salesapply on career-hcm03.ns2cloud.com