Security Engineer - Vulnerability Management

accenturefederalservices

United States

On-site

USD 110,000 - 150,000

Full time

6 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Accenture Federal Services is seeking a Security Engineer - Vulnerability Management Specialist to lead and mature our vulnerability program across systems, networks, and cloud environments. You will work with IT, ISSOs, and assessors to validate RMF artifacts and ensure accurate security controls and documentation.

You will help implement best practices for patching, hardening, and incident response, driving continuous improvement to meet Authority to Operate readiness and federal standards.

Qualifications

  • 4–6 years of experience in vulnerability management or related security role.
  • Expertise with vulnerability scanning, assessment, and risk prioritization.
  • Familiarity with NIST 800‑53, CVSS, OWASP Top 10.

Responsibilities

  • Lead and mature the vulnerability management program across systems.
  • Identify, assess, and prioritize vulnerabilities across apps, networks, and cloud.
  • Collaborate with ISSOs and Assessors to validate RMF artifacts and controls.
  • Refine Control Statements and ensure proper hardening and accurate assessment docs.
  • Support compliance with NIST, FISMA, SOX; implement vulnerability patching and hardening practices.
  • Assist in incident response for exploited vulnerabilities, with risk guidance.
  • Establish repeatable workflows to support ATO readiness for new systems.
  • Communicate risk and mitigation strategies to stakeholders.

Skills

Vulnerability management
Security tools
Risk assessment
NIST frameworks
Cloud security

Education

Bachelor's degree

Tools

Tenable Nessus
Qualys
Rapid7
OpenVAS
SCAP

Job description

At Accenture Federal Services, nothing matters more than helping the US federal government make the nation stronger and safer and life better for people. Our 13,000+ people are united in a shared purpose to pursue the limitless potential of technology and ingenuity for clients across defense, national security, public safety, civilian, and military health organizations.

Join Accenture Federal Services, a technology company within global Accenture. Recognized as a Glassdoor Top 100 Best Place to Work, we offer a collaborative and caring community where you feel like you belong and are empowered to grow, learn and thrive through hands‑on experience, certifications, industry training and more.

Join us to drive positive, lasting change that moves missions and the government forward!

The work

As a Security Engineer - Vulnerability Management Specialist, you will be responsible for managing and enhancing the organization's vulnerability management program and supporting IT systems in achieving compliance necessary to pass formal Controls Assessments. You will identify, assess, prioritize, and mitigate security vulnerabilities across systems, networks, cloud platforms, and applications.

This role requires close collaboration with IT, ISSOs, Controls Assessors, development teams, and security stakeholders to strengthen the organization's security posture and ensure alignment with federal and industry standards.

You will support the collection and validation of RMF artifacts, review and refine Control Statements for accuracy, ensure systems are properly hardened, and verify that assessor documentation reflects the true vulnerability state of evaluated systems. Additionally, you will enable continuous improvement by establishing repeatable processes that help new systems achieve Authority to Operate (ATO) readiness.

Key responsibilities:
  • Manage and mature the organization's vulnerability management program
  • Identify, assess, and prioritize vulnerabilities across applications, networks, endpoints, cloud environments, and enterprise systems
  • Collaborate with ISSOs and Controls Assessors to capture RMF artifacts and validate security control effectiveness
  • Review, advise, and refine security Control Statements to ensure systems are hardened and accurately represented in assessment documentation
  • Support compliance with federal frameworks including NIST 800‑53, FISMA, and SOX
  • Implement best practices for vulnerability management, patching, configuration hardening, and risk reduction
  • Assist in incident response activities involving exploited vulnerabilities, providing risk assessment and remediation guidanceActually, I had to fix the break incorrectly. Sorry. Let me correct it. The correct line is: *Assist in incident response activities involving exploited vulnerabilities, providing risk assessment and remediation guidance*.
  • Establish repeatable vulnerability workflows and processes to support ATO readiness for new systems
  • Communicate risk clearly to stakeholders and recommend effective mitigation strategies
  • Contribute to the continuous improvement of security processes and controls
Here’s what you need :
  • 4-6 years of experience in vulnerability management or a related information security role
  • Advanced knowledge of vulnerability management tools such as Tenable Nessus, Qualys, Rapid7, or OpenVAS
  • Strong understanding of vulnerability scanning, assessment, and risk prioritization
  • Familiarity with CVSS, NIST 800‑53, and OWASP Top 10
  • Understanding of OS‑level vulnerabilities (Windows, Linux, macOS)
  • Knowledge of core network protocols and components (TCP/IP, DNS, firewalls, routers, switches)
  • Experience with Cloud Service Providers (AWS, Azure, GCP) and cloud‑native policies
  • Experience configuring and working with Identity Providers (IdP)
  • Experience with patch management tools and processes
  • Basic understanding of compliance requirements such as FISMA and SOX
  • Familiarity with NIST CSF, ISO 27001, CIS Controls
  • Ability to assess vulnerabilities, identify risks, and support incident response
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field (or equivalent experience)
Preferred qualifications:
  • Advanced skills in vulnerability exploitation and proof‑of‑concept (PoC) development
  • Familiarity with exploit frameworks such as Metasploit
  • Experience working with cloud security tools (AWS Inspector, Azure Security Center, GCP Security Command Center)
  • Experience identifying and mitigating high‑impact vulnerabilities in complex environments
  • Experience with configuration assessment tools such as SCAP or CIS‑CAT
  • Knowledge of threat intelligence processes and correlating vulnerabilities with real‑world threats
  • Understanding of threat modeling and attack surface analysis
  • Experience with SIEM tools (Splunk, QRadar) and integrating them with vulnerability processes
  • Ability to analyze logs, alerts, and correlation events
Bonus Points:
  • - GIAC Certified Vulnerability Analyst (GCVA)
  • - Offensive Security Certified Professional (OSCP)
  • - CISSP
  • - CISM
Eligibility requirements:
  • U.S. Citizenship required
  • Eligible to obtain a Public Trust security clearance
  • As required by local law, Ac
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer - Vulnerability Management
Security Engineer - Vulnerability Management

Fortis Industries, Inc. DBA - LTS, Inc. • Atmore (AL)

On-site
USD 100,000 - 140,000
Senior Vulnerability Assessment Analyst
Senior Vulnerability Assessment Analyst

Base One Technologies • Washington

Hybrid
USD 120,000 - 180,000
Senior Security Analyst Vulnerability Management
Senior Security Analyst Vulnerability Management

Compass Pointe Consulting, LLC • Bethesda (MD)

On-site
USD 110,000 - 140,000
Security Engineer - Vulnerability Management
Security Engineer - Vulnerability Management

Socket.dev • Washington

On-site
USD 106,000 - 221,000
Compliance and Continuous Monitoring Engineer - Vulnerability Management (Top Secret Clearance)
Compliance and Continuous Monitoring Engineer - Vulnerability Management (Top Secret Clearance)

ShorePoint • Washington

On-site
USD 120,000 - 170,000
PTO 144 hours
11 holidays
Insurance coverage 85%
+2
Vulnerability Manager
Vulnerability Manager

Search Services • Houston (TX)

On-site
USD 110,000 - 170,000
Security Engineer - Vulnerability Management
Security Engineer - Vulnerability Management

Accenture Federal Services • Washington

On-site
USD 106,000 - 221,000
Vulnerability Management Engineer
Vulnerability Management Engineer

Jobtailor • Washington

On-site
USD 110,000 - 150,000
Cybersecurity Analyst
Cybersecurity Analyst

Jobtailor • Fort Meade (MD)

On-site
USD 85,000 - 135,000
Senior System Security Specialist
Senior System Security Specialist

Compunnel, Inc. • Baltimore (MD)

On-site
USD 120,000 - 150,000