IT Security Vulnerability Specialist (0036)

OCT Consulting, LLC

Maryland

On-site

USD 110,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, Dental, Vision insurance
401K with employer contributions
Paid Time Off
Life Insurance
Disability benefits
Training Benefits

Job summary

OCT Consulting, LLC is seeking an Associate to join our Cybersecurity practice as an IT Security Vulnerability Specialist, based in Suitland, MD. The role supports a federal client in a hybrid model, requiring at least three days onsite per week. Responsibilities include remediation leadership, vulnerability assessments, and policy development.

The ideal candidate has 7+ years in A&A, strong NIST RMF knowledge, and certifications such as CISSP or GIAC, with a US citizenship and SECRET clearance.

Qualifications

  • 7+ years of experience with A&A support.
  • Proficient in all steps in the NIST RMF framework.
  • Knowledgeable in NIST SP 800-53 & 800-53A.
  • Bachelor's degree or equivalent experience.
  • Hands-on with multiple vulnerability scanning platforms, including STIG and CIS benchmarks.
  • MS Excel proficiency.
  • GIAC GEVA, CASP, CAP, CISSP, CISM, GSEC, GMON, or Security+ certification.
  • Must be a US Citizen.
  • SECRET clearance required.

Responsibilities

  • Lead and drive remediation efforts within government environments to improve vulnerability management efficiency.
  • Articulate risk and impact to product and leadership to justify remediation priorities.
  • Conduct internal vulnerability assessments and analyze external reports, zero-day events, and security incidents.
  • Monitor vulnerability management tools, scans, and configurations.
  • Develop, maintain, and enforce security policies and standards for vulnerability management.
  • Participate in audits and assessments to ensure regulatory compliance.
  • Create reports and dashboards to drive remediation efforts and improvements.
  • Support security operations including detection and response.
  • Contribute to Security Incident response and configuration management guidance.

Skills

Vulnerability Management
Intrusion Detection
Access Control
Policy Enforcement
Application Security
Incident Response
Data Loss Prevention
Encryption
Two-Factor Authentication

Education

Bachelor's degree or equivalent

Tools

Vulnerability Scanners
STIG
CIS Benchmarks

Job description

Associate / IT Security Vulnerability Specialist (0036)

OCT Consulting is a management and technology consulting firm that supports Federal Government clients. We provide consulting services in the areas of Data Analytics, Change Management, Program and Project Management, Acquisition/Procurement, and Information Technology.

OCT is currently looking for anAssociate to join our growing Cybersecurity practice.This position will primarily support a federal client as an IT Security Vulnerability Specialist, which is a hybrid position requiring at least 3 days per week onsite in Suitland, MD. The ideal candidate will be proficient in key areas of security such as: Vulnerability Management, Intrusion Prevention and Detection, Access Control and Authorization, Policy Enforcement, Application Security, Protocol Analysis, Firewall Management, Incident Response, Data Loss Prevention (DLP), Encryption, Two-Factor Authentication, Web filtering, and Advanced Threat Protection.

Responsibilities will include, but are not limited to:

  • Lead and drive remediation efforts within government environment to increase the efficiency of vulnerability management processes.
  • Articulate risk and impact to product, engineering and other business leaders with the ability to convey the urgency and need to remediate a vulnerability commensurate with the risk it presents to the enterprise.
  • Conduct internal vulnerability assessments and vulnerability analysis upon external vulnerability reports, zero-day announcements, security incidents etc.
  • Monitor and maintain vulnerability and code scanning, security configuration and other vulnerability management tools.
  • Develop, maintain, and recommend security policies, procedures, and standards related to vulnerability management.
  • Participate in security audits and assessments to ensure compliance with regulatory requirements and industry standards.
  • Perform vulnerability re-production and fix validation of vulnerabilities where required.
  • Maintain strong knowledge of ongoing security threats, remediations and operational best practices in the threat and vulnerability management.
  • Create reports and dashboards to drive vulnerability remediation efforts and process improvements.
  • Drive regular operational and business reviews for threat and vulnerability management activities.
  • Support other security operation activities as needed (e.g. detection and response).
  • Participate in the Security Incident response.
  • Review, evaluate, refine, release and maintain Configuration Management Plans in support of program requirements.
  • Provide recommendations and guidance for the identification of Configuration Items (CI) and Computer Software Configuration Items (CSCI).
  • Provide guidance and expertise in the establishment, monitoring and maintenance of configuration baselines on assigned programs.
  • Monitor effectiveness and compliance on assigned programs.

Requirements:

  • 7+ years of experience with A&A support.
  • Proficient in all steps in the NIST RMF framework
  • Knowledgeable in NIST special publications such as 800-53 & 800-53A
  • Bachelor's degree or equivalent experience
  • In-depth understanding and hands-on experience with multiple vulnerability scanning platforms, to include scanning with Security Technical Information Guides (STIG) and CIS benchmarks.
  • MS Excel proficiency.
  • A related industry certification such as GIAC GEVA, CASP, CAP, CISSP, CISM, GSEC, GMON, Security+.
  • Must be a US Citizen.
  • SECRET clearance required

Benefits

The position includes competitive compensation and a full suite of benefits:

  • Medical, Dental, and Vision insurance
  • Retirement savings 401K plan provided by an industry-leading provider with 3% employer contributions.
  • Paid Time Off
  • Life Insurance, Short- and Long-Term Disability benefits
  • Training Benefits

Salary: $110,000-$130,000 to commensurate with experience, education, etc.

About OCT Consulting

OCT Consulting LLC is a SmallBusiness (SB) providing professional services and information technology solutions to the Federal government and commercial clients. Founded in 2013, we bring the agility of operations and a management team with a track record of leading successful engagements at major Federal government agencies. At OCT we believe in creating a work environment where employees can thrive based on their abilities, skills, and achievements. We are dedicated to providing career growth and professional development based on individual merit and fostering a workplace where everyone’s contributions are valued and recognized.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Federal IT Vulnerability & Remediation Lead
Federal IT Vulnerability & Remediation Lead

OCT Consulting, LLC • Maryland

On-site
USD 110,000 - 130,000
Medical, Dental, Vision insurance
401K with employer contributions
Paid Time Off
+3
Vulnerability Assessment Specialist (Senior)
Vulnerability Assessment Specialist (Senior)

FedTec • Woodlawn (MD)

On-site
USD 80,000 - 110,000
Medical, dental, and vision coverage
401(k) retirement plan with company  匹
Paid time off and holidays
+1
Senior Security Analyst Vulnerability Management
Senior Security Analyst Vulnerability Management

Compass Pointe Consulting, LLC • Bethesda (MD)

On-site
USD 110,000 - 140,000
Vulnerability Management Specialist- Mid Level
Vulnerability Management Specialist- Mid Level

BOOST LLC • Quantico (VA)

On-site
USD 70,000 - 80,000
Cyber Security Analyst
Cyber Security Analyst

22nd Century Technologies Inc. • Lexington Park (MD)

On-site
USD 80,000 - 120,000
Senior Program Manager (15.46)
Senior Program Manager (15.46)

OCT Consulting, LLC • Washington

On-site
USD 110,000 - 140,000
Medical, Dental, Vision insurance
401K with 3% employer contributions
Paid Time Off and Holidays
+1
Systems Security Administration (SSA) Management Team Lead (0043)
Systems Security Administration (SSA) Management Team Lead (0043)

OCT Consulting LLC • Washington

On-site
USD 150,000 - 175,000
Medical, Dental, and Vision insurance
Retirement savings 401K with employer contribution
Paid Time Off
+2
Vulnerability Assessment Analyst with Security Clearance
Vulnerability Assessment Analyst with Security Clearance

ShorePoint, LLC • Albuquerque (NM)

On-site
USD 90,000 - 130,000
PTO 144 hours per year
11 holidays
Health insurance 85% premium covered
+2
Information Assurance/Security Engineer (15.34)
Information Assurance/Security Engineer (15.34)

OCT Consulting LLC • Washington

On-site
USD 55,000 - 75,000
Medical, Dental, and Vision insurance
401K plan with employer contributions
Paid Time Off
+2
Compliance and Continuous Monitoring Engineer - Vulnerability Management (Top Secret Clearance)
Compliance and Continuous Monitoring Engineer - Vulnerability Management (Top Secret Clearance)

ShorePoint • Washington

On-site
USD 120,000 - 170,000
PTO 144 hours
11 holidays
Insurance coverage 85%
+2