IT Security Vulnerability Specialist (0036)

OCT Consulting, LLC

Suitland-Silver Hill, MD

JOB DETAILS
SALARY
$110,000–$130,000
SKILLS
Acquisitions Management, Benchmarking, Best Practices, Business Operations, CISM - Certified Information Security Manager, CISSP - Certified Information Systems Security Professional, Change Management, Communication Skills, CompTIA Security+, Computer Security, Computer Software, Configuration Management, Consulting, Data Analysis, Dental Insurance, Federal Government, GIAC - Global Information Assurance Certification, GSEC - GIAC Security Essentials Certification, Government, IT Procurement, Incident Response, Industry Standards, Information Technology & Information Systems, Internet Security, Maintain Compliance, Management Consulting, Microsoft Excel, Multiplatform/Cross-Platform, Operational Audit, Operational Support, Operations Management, People Management, Process Improvement, Product Engineering, Professional Services, Program Planning, Project/Program Management, Publications, Regulatory Compliance, Regulatory Requirements, Reporting Dashboards, Reporting Skills, Risk, Secret Clearance, Security Analysis, Security Attacks, Security Auditing, Small Business, Software Configuration Management, Systems Administration/Management, U.S. National Institute of Standards and Technology (NIST), United States Citizen, Vision Plan, Vulnerability Scanners
LOCATION
Suitland-Silver Hill, MD
POSTED
1 day ago

Associate / IT Security Vulnerability Specialist (0036)

OCT Consulting is a management and technology consulting firm that supports Federal Government clients. We provide consulting services in the areas of Data Analytics, Change Management, Program and Project Management, Acquisition/Procurement, and Information Technology.

OCT is currently looking for an Associate to join our growing Cybersecurity practice. This position will primarily support a federal client as an IT Security Vulnerability Specialist, which is a hybrid position requiring at least 3 days per week onsite in Suitland, MD. The ideal candidate will be proficient in key areas of security such as: Vulnerability Management, Intrusion Prevention and Detection, Access Control and Authorization, Policy Enforcement, Application Security, Protocol Analysis, Firewall Management, Incident Response, Data Loss Prevention (DLP), Encryption, Two-Factor Authentication, Web filtering, and Advanced Threat Protection.

Responsibilities will include, but are not limited to:

  • Lead and drive remediation efforts within government environment to increase the efficiency of vulnerability management processes.
  • Articulate risk and impact to product, engineering and other business leaders with the ability to convey the urgency and need to remediate a vulnerability commensurate with the risk it presents to the enterprise.
  • Conduct internal vulnerability assessments and vulnerability analysis upon external vulnerability reports, zero-day announcements, security incidents etc.
  • Monitor and maintain vulnerability and code scanning, security configuration and other vulnerability management tools.
  • Develop, maintain, and recommend security policies, procedures, and standards related to vulnerability management.
  • Participate in security audits and assessments to ensure compliance with regulatory requirements and industry standards.
  • Perform vulnerability re-production and fix validation of vulnerabilities where required.
  • Maintain strong knowledge of ongoing security threats, remediations and operational best practices in the threat and vulnerability management.
  • Create reports and dashboards to drive vulnerability remediation efforts and process improvements.
  • Drive regular operational and business reviews for threat and vulnerability management activities.
  • Support other security operation activities as needed (e.g. detection and response).
  • Participate in the Security Incident response.
  • Review, evaluate, refine, release and maintain Configuration Management Plans in support of program requirements.
  • Provide recommendations and guidance for the identification of Configuration Items (CI) and Computer Software Configuration Items (CSCI).
  • Provide guidance and expertise in the establishment, monitoring and maintenance of configuration baselines on assigned programs.
  • Monitor effectiveness and compliance on assigned programs.

Requirements

Requirements:

  • 7+ years of experience with A&A support.
  • Proficient in all steps in the NIST RMF framework
  • Knowledgeable in NIST special publications such as 800-53 & 800-53A
  • Bachelor's degree or equivalent experience
  • In-depth understanding and hands-on experience with multiple vulnerability scanning platforms, to include scanning with Security Technical Information Guides (STIG) and CIS benchmarks.
  • MS Excel proficiency.
  • A related industry certification such as GIAC GEVA, CASP, CAP, CISSP, CISM, GSEC, GMON, Security+.
  • Must be a US Citizen.
  • SECRET clearance required

Benefits

Benefits

 The position includes competitive compensation and a full suite of benefits:

  • Medical, Dental, and Vision insurance
  • Retirement savings 401K plan provided by an industry-leading provider with 3% employer contributions.
  • Paid Time Off
  • Life Insurance, Short- and Long-Term Disability benefits
  • Training Benefits

Salary: $110,000-$130,000 to commensurate with experience, education, etc. 

About OCT Consulting

OCT Consulting LLC is a Small Business (SB) providing professional services and information technology solutions to the Federal government and commercial clients. Founded in 2013, we bring the agility of operations and a management team with a track record of leading successful engagements at major Federal government agencies.

At OCT we believe in creating a work environment where employees can thrive based on their abilities, skills, and achievements. We are dedicated to providing career growth and professional development based on individual merit and fostering a workplace where everyone’s contributions are valued and recognized.

About the Company

O

OCT Consulting, LLC