Information Security Engineer – Threat and Vulnerability Management

Jobtailor

Washington (District of Columbia)

On-site

USD 120,000 - 180,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Jobtailor in Washington, DC is seeking a cybersecurity professional to conduct vulnerability assessments across servers, workstations, network devices, cloud infrastructure (Azure, Microsoft 365). You will use vulnerability scanning platforms to identify weaknesses, prioritize findings, and present remediation to system owners and the Director.

You will monitor threat intel and inform on emerging threats while supporting high-stakes, client-facing security work.

Qualifications

  • Bachelor’s degree in cybersecurity, information systems, or related field, or equivalent years of experience.
  • Four years or more of relevant information security experience.
  • A Master’s degree in cybersecurity or a related field may be considered in lieu of one year of experience.
  • Hands-on experience with vulnerability management or threat and vulnerability assessment, including scanning, analysis, and risk-based prioritization of findings.
  • Experience with vulnerability scanning platforms such as Tenable, Rapid7, Qualys, or equivalent.
  • Working knowledge of application, operating system, and network security fundamentals, including common monitoring tools.
  • Experience with incident response, digital forensics, and cyber threat intelligence in an operational environment, including analysis of threat actor tactics and indicators of compromise.
  • Thorough understanding of current security principles, techniques, and protocols.
  • Ability to effectively communicate information security issues, risks, and recommendations to both technical and non-technical peers and management, including through well-written reports.
  • Ability to problem-solve.
  • Excellent interpersonal, verbal and written communication skills, including the ability to communicate effectively in a virtual environment.
  • Ability to work calmly and effectively in a high-pressure, deadline-oriented environment.
  • Ability to use good judgment, take initiative, and consult others as appropriate.
  • Willingness to be flexible with time and adjust to a changing work environment.
  • Ability to build and maintain positive relationships while maintaining a client service orientation.
  • Ability to use sound judgment and discretion with highly confidential information.
  • Ability to take direction and accept supervision.
  • Ability to work independently, organize and prioritize work accurately, be detail-oriented, and recognize urgency.
  • Ability to work effectively in a team-oriented collaborative environment.

Responsibilities

  • Conduct ongoing vulnerability assessments across servers, workstations, network devices, cloud infrastructure, Microsoft Azure, and Microsoft 365 environments
  • Use the firm’s vulnerability scanning platform to identify security weaknesses
  • Prioritize findings using exploitability, threat intelligence, asset criticality, and exposure
  • Present remediation recommendations to system owners and the Director
  • Maintain the firm’s threat profile, tracking threat actors, campaigns, and tactics targeting law firms, professional services, clients, and relevant industries
  • Monitor threat intelligence feeds, information-sharing communities, and dark web sources for indicators of compromise, credential exposure, and mentions of the firm, its people, or clients
  • Translate threat intelligence into action by prioritizing actively exploited vulnerabilities and recommending new detections
  • Brief the Director and peers on emerging threats
  • Execute prompt injection and cross-client data isolation test cases as directed
  • Bring emerging AI attack techniques into the testing program
  • Complete special projects and other assigned duties

Skills

Vulnerability Management
Threat Assessment
Incident Response
Threat Intelligence Analysis
Risk-Based Prioritization
Digital Forensics
Security Principles
Communication Skills
Problem-Solving
Team Collaboration
Client Service Orientation
High-Pressure Environment

Education

Bachelor’s Degree in Cybersecurity or related field
Master’s Degree in Cybersecurity (substitute for experience)

Tools

Tenable
Rapid7
Qualys
Microsoft Azure
Microsoft 365

Job description

  • Conduct ongoing vulnerability assessments across servers, workstations, network devices, cloud infrastructure, Microsoft Azure, and Microsoft 365 environments
  • Use the firm’s vulnerability scanning platform to identify security weaknesses
  • Prioritize findings using exploitability, threat intelligence, asset criticality, and exposure
  • Present remediation recommendations to system owners and the Director
  • Maintain the firm’s threat profile, tracking threat actors, campaigns, and tactics targeting law firms, professional services, clients, and relevant industries
  • Monitor threat intelligence feeds, information-sharing communities, and dark web sources for indicators of compromise, credential exposure, and mentions of the firm, its people, or clients
  • Translate threat intelligence into action by prioritizing actively exploited vulnerabilities and recommending new detections
  • Brief the Director and peers on emerging threats
  • Execute prompt injection and cross-client data isolation test cases as directed
  • Bring emerging AI attack techniques into the testing program
  • Complete special projects and other assigned duties
Requirements
  • Bachelor’s degree in cybersecurity, information systems, or a related field, or equivalent years of experience
  • Four years or more of relevant information security experience
  • A Master’s degree in cybersecurity or a related field may be considered in lieu of one year of experience
  • Hands-on experience with vulnerability management or threat and vulnerability assessment, including scanning, analysis, and risk-based prioritization of findings
  • Experience with vulnerability scanning platforms such as Tenable, Rapid7, Qualys, or equivalent
  • Working knowledge of application, operating system, and network security fundamentals, including common monitoring tools
  • Experience with incident response, digital forensics, and cyber threat intelligence in an operational environment, including analysis of threat actor tactics and indicators of compromise
  • Thorough understanding of current security principles, techniques, and protocols
  • Ability to effectively communicate information security issues, risks, and recommendations to both technical and non-technical peers and management, including through well-written reports
  • Ability to problem-solve
  • Excellent interpersonal, verbal and written communication skills, including the ability to communicate effectively in a virtual environment
  • Ability to work calmly and effectively in a high-pressure, deadline-oriented environment
  • Ability to use good judgment, take initiative, and consult others as appropriate
  • Willingness to be flexible with time and adjust to a changing work environment
  • Ability to build and maintain positive relationships while maintaining a client service orientation
  • Ability to use sound judgment and discretion with highly confidential information
  • Ability to take direction and accept supervision
  • Ability to work independently, organize and prioritize work accurately, be detail-oriented, and recognize urgency
  • Ability to work effectively in a team-oriented collaborative environment
Core Competencies

Demonstrates expertise in vulnerability management, threat assessment, and incident response, with a strong ability to communicate security issues and recommendations effectively. Proficient in utilizing vulnerability scanning platforms and analyzing threat intelligence to enhance organizational security posture.

Highest-signal resume keywords
  • Vulnerability Management
  • Threat Assessment
  • Incident Response
  • Vulnerability Scanning Platforms
  • Cyber Threat Intelligence
ATS Optimization Keywords
Hard Skills
  • Vulnerability Assessment
  • Threat Intelligence Analysis
  • Risk-Based Prioritization
  • Incident Response
  • Digital Forensics
  • Security Principles
  • Application Security
  • Network Security
  • Operating System Security
  • Threat Actor Tactics
Soft Skills
  • Effective Communication
  • Problem-Solving
  • Interpersonal Skills
  • Team Collaboration
  • Client Service Orientation
Certifications & Qualifications
  • Bachelor’s Degree in Cybersecurity
  • Master’s Degree in Cybersecurity
Industry Keywords
  • Vulnerability Scanning
  • Threat Profile
  • Indicators of Compromise
  • High-Pressure Environment
  • Confidential Information
Tools & Technologies
  • Microsoft Azure
  • Microsoft 365
  • Tenable
  • Rapid7
  • Qualys
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vulnerability Management Engineer
Vulnerability Management Engineer

Jobtailor • Philadelphia

On-site
USD 100,000 - 140,000
Cybersecurity Manager I
Cybersecurity Manager I

Jobtailor • Colorado

On-site
USD 150,000 - 210,000
Information Security Officer
Information Security Officer

Jobtailor • Massachusetts

On-site
USD 200,000 - 320,000
Cybersecurity Analyst
Cybersecurity Analyst

Jobtailor • Fort Meade (MD)

On-site
USD 85,000 - 135,000
Manager – Cyber Security
Manager – Cyber Security

Jobtailor • Los Angeles (CA)

On-site
USD 140,000 - 190,000
Manager, Physical Security and Risk Mitigation
Manager, Physical Security and Risk Mitigation

Jobtailor • Washington

On-site
USD 140,000 - 180,000
Manager – Cybersecurity Fusion Center
Manager – Cybersecurity Fusion Center

Jobtailor • West Valley City (UT)

On-site
USD 190,000 - 240,000
Senior Associate – Cybersecurity Analyst
Senior Associate – Cybersecurity Analyst

Jobtailor • Town of Florida (NY)

On-site
USD 65,000 - 85,000
Senior Information Technology Security Analyst
Senior Information Technology Security Analyst

Jobtailor • Philadelphia

On-site
USD 110,000 - 160,000
Information Security Specialist – Regional
Information Security Specialist – Regional

Jobtailor • Missouri

On-site
USD 90,000 - 130,000