Essential Duties and Responsibilities:
- Performs application vulnerability assessments to identify application vulnerabilities.
- Performs network vulnerability assessments to identify host vulnerabilities.
- Identifies, analyzes, and prioritizes vulnerability findings.
- Analyzes system configurations to identify possible security gaps and\or compliance violations.
- Establishes collaborative working relationships with internal resources to provide security assessments, reports, and recommendations.
- Performs other related duties as assigned.
- Please refer to the additional information section of the job requisition for this opening to determine clearance eligibility required.
- Bachelor's Degree
- 7-10 years of security or technology related experience
- Professional certifications, such as Security+, CEH, or CISSP, desirable • Knowledge of IPv4 network architecture and core services
- Knowledge of web application development and architecture
- Knowledge of network security controls
- Knowledge of vulnerability management
- Experience with dynamic application security testing (DAST) tools
- Experience with vulnerability management (VM) tools
- Familiarity with OWASP Top 10
- Familiarity with WASC Threat Classification • Familiarity with CVE
- Familiarity with NIST SP 800-53
- Experience with automated service ticketing systems
- Excellent analytical, decision-making, and problem-solving skills
- Ability to communicate technical information in understandable business terms
- Excellent interpersonal skills, presentation skills, and verbal / written communication skills
- Strong customer service abilities required.
- Ability to work collaboratively with a broad range of staff. Skilled in Microsoft Office software including Word, Excel, Visio, MS Project, and PowerPoint
- Ability to perform comfortably in a fast-paced, deadline-oriented work environment
- Ability to execute many complex tasks simultaneously, and work as a team member as well as independently
- Strong understanding of federal and DoD requirements to include but not limited to applicable Executive Orders, FISMA, FIPS, CMMC, NIST 800-171, NIST 800-60, NIST 800-65, SCRM, FedRAMP, DODI 8500s, 8500.2s, and 8510s.
- Experience with GRC tools (eMASS, CFACTS, CSAM).
- Develops solutions to a variety of complex problems.
- Work requires considerable judgment and initiative.






