Vulnerability Assessments Engineer
- Hiring from
- United States
- Work type
- Remote
- Posted
516,491 remote jobs, straight from company career pages
100% free · New jobs every hour
Show job descriptionHide job description
Job Description
This is a remote position.
Vulnerability Assessment Engineer
Location: Remote
Clearance Requirement: Active Secret
Employment Type: Full-Time
About Company
Disruptive Solutions, a Service-Disabled Veteran-Owned Small Business (SDVOSB) delivering mission-focused cybersecurity and technology solutions for federal and commercial clients. We specialize in advanced cybersecurity operations, AI/ML integration, cloud modernization, data governance, and risk management. With a proven track record supporting agencies like the Department of Defense (DoD), Department of Homeland Security (DHS), Cybersecurity and Infrastructure Security Agency (CISA), and the Department of Treasury, we deliver innovative solutions that maximize efficiency and strengthen cyber resilience. At our core, we are dedicated partners committed to securing the mission with innovation, integrity, and measurable impact.
Job Summary
We are seeking a highly skilled Vulnerability Assessment Specialist with extensive experience in conducting vulnerability scanning and assessments. The ideal candidate will possess in-depth knowledge of cybersecurity frameworks specifically NIST SP 800-53, IEC 62443-2-1, and PCI DSS and will play a critical role in ensuring our organization's compliance with regulatory standards while enhancing our overall security posture.
Key Responsibilities
- Conduct comprehensive vulnerability scanning and assessments for both IT systems using tools compliant with NIST SP 800-53, IEC 62443-2-1, and PCI DSS.
- Perform risk assessments in accordance with NIST SP 800-30, tailored to prioritize vulnerabilities based on their potential impact on operations and safety.
- Manage audits and ensure adherence to regulatory standards, reporting on the effectiveness of vulnerability management strategies to executive leadership.
- Collaborate with IT and OT incident response teams to address vulnerabilities that could lead to security incidents, utilizing frameworks such as NIST SP 800-61.
- Stay current with cybersecurity frameworks, including NIST, ISO/IEC 27001, IEC 62443, and PCI DSS, to ensure best practices are implemented.
- Utilize vulnerability assessment tools tailored for IT (e.g., Nessus, ServiceNow) and OT (e.g., Nozomi Networks, Dragos) to identify and remediate vulnerabilities.
- Administer the ServiceNow vulnerability management module, ensuring effective tracking and resolution of identified vulnerabilities.
- Demonstrate expertise in IT operating systems, including Windows and Linux, and possess a basic understanding of industrial control systems (ICS) and their security implications.
- Understand networking concepts and associated protocols to facilitate effective vulnerability assessments.
Required Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, or a related field; advanced degrees or certifications (CISSP, CISM, etc.) are a plus.
- 5+ years of experience in vulnerability assessment and management in IT environments.
- Strong analytical and problem-solving skills with the ability to prioritize tasks and manage multiple projects simultaneously.
- Excellent communication skills, with the ability to convey complex technical information to both technical and non-technical stakeholders.
- Proven track record of successfully managing vulnerability assessments and remediation efforts.
Preferred Qualifications
- CISSP, Associate of ISC2, CGRC, CISA, or other relevant cybersecurity certification.
- Previous experience supporting State.
- Experience with ArchAngel and iPost or comparable GRC and continuous monitoring platforms.
- Experience interpreting Tenable/Nessus, Wiz, STIG, or SCAP vulnerability and compliance results.
- Familiarity with AWS and/or Azure security concepts and environments.
- Familiarity with FedRAMP and cloud security control inheritance.
- Experience supporting High Value Asset (HVA) systems.
- Experience working collaboratively with ISSOs, SCAs, vulnerability management teams, and security engineers.
- Education: Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Systems, or a related field is preferred.
Equal Opportunity Statement
Disruptive Solutions, LLC is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status, sexual orientation, gender identity, or any other characteristic protected by law.