Guidehouse

IT Vulnerability Management Lead – Senior Security Analyst

Guidehouse

full-time

Posted on:

Location Type: Hybrid

Location: Rockville • Maryland • 🇺🇸 United States

Visit company website
AI Apply
Apply

Salary

💰 $98,000 - $163,000 per year

Job Level

Senior

Tech Stack

AWSCloudCyber SecurityGoogle Cloud PlatformLinuxUnix

About the role

  • Work closely with the client Information Systems Security Officer (ISSO) and play a critical part in safeguarding Client's IT infrastructure
  • Lead the agency’s vulnerability management lifecycle using Tenable.sc, Tenable.io, Nessus Manager, and Nessus scanners (on-prem and cloud)
  • Analyze, prioritize, and track remediation of vulnerabilities in coordination with IT operations and system owners
  • Maintain scan schedules, asset groups, scan policies dashboards, and reports tailored to agency infrastructure and communicate risk posture and remediation progress to relevant infrastructure, application, and cloud teams to remediate vulnerabilities
  • Define the scanner and security center architecture, refine data flows and synchronizations, tune scanning configurations to minimize false positives and ensure the best coverage
  • Develop and maintain documentation for system setup, operation, vulnerability management processes, exceptions, and remediation tracking
  • Support implementation of security projects that require compliance with relevant government policies or standards
  • Act as SME (subject matter expert) for vulnerability management tools and processes
  • Ensure systems and practices comply with FISMA and FedRAMP related Security Assessment and Authorization (SA&A) and compliance for client IT programs
  • Assist client in coordination, implementation, communication, and enforcement of the Agency IT security policies
  • Support incident response

Requirements

  • Bachelor’s degree in computer science, cybersecurity, information technology, or related field OR an additional FOUR (4) years of experience
  • Expert knowledge of IT security vulnerabilities and risk assessments with the ability to explain the risks associated with them to executives, program & technology staff
  • Minimum of FIVE (5) years of progressive experience in IT security, with a minimum of THREE (3) years in vulnerability management
  • Strong knowledge of vulnerability management lifecycle, patch management, and risk scoring (e.g., CVSS2)
  • Familiarity with cloud platforms (AWS and GCP) and hybrid environments
  • Understanding of Windows, Linux/Unix, and network devices security hardening
  • Ability to work with program staff, executives, security application vendors and technology staff to achieve IT security goals and objectives
  • Experience developing and maintaining Security Assessment and Authorization (SA&A) documentation for large IT systems for the Federal Government
  • Excellent working experience in applying FISMA, and FedRAMP processes and policies to information systems
  • Strong communication skills (both technical and non-technical) and ability to collaborate across IT, security, and business units
  • Certifications: CISSP (or ability to obtain within 6 months)
Benefits
  • Medical, Rx, Dental & Vision Insurance
  • Personal and Family Sick Time & Company Paid Holidays
  • Parental Leave
  • 401(k) Retirement Plan
  • Group Term Life and Travel Assistance
  • Voluntary Life and AD&D Insurance
  • Health Savings Account, Health Care & Dependent Care Flexible Spending Accounts
  • Transit and Parking Commuter Benefits
  • Short-Term & Long-Term Disability
  • Tuition Reimbursement, Personal Development, Certifications & Learning Opportunities
  • Employee Referral Program
  • Corporate Sponsored Events & Community Outreach
  • Care.com annual membership
  • Employee Assistance Program
  • Supplemental Benefits via Corestream (Critical Care, Hospital Indemnity, Accident Insurance, Legal Assistance and ID theft protection, etc.)

Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard skills
vulnerability managementrisk assessmentspatch managementrisk scoringsecurity hardeningcloud platformsWindows securityLinux securitynetwork devices securitydocumentation development
Soft skills
communication skillscollaborationleadershipproblem-solvinganalytical skillsorganizational skillsinterpersonal skillsability to explain riskscoordinationenforcement of policies
Certifications
CISSP
Xcelerate Solutions

Industrial Security Analyst – Top Secret

Xcelerate Solutions
Mid · Seniorfull-timeMaryland · 🇺🇸 United States
Posted: 3 days agoSource: jobs.jobvite.com