OCT Consulting, LLC logo

IT Security Vulnerability Specialist (0036)

OCT Consulting, LLC

Suitland, MDHybridJob$110–130K/yrPosted 3mo agoSeen in employer's feed 3 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
$110–130K/yr
Location
Suitland, MDHybrid
Work Authorization
US work authorization required

Requirements

Credentials this posting asks for.

GIAC GEVACASPCAPCISSPCISMGSECGMONSecurity+Secret clearanceBachelor's degree

Job overview

OCT Consulting, LLC is hiring an IT Security Vulnerability Specialist (0036). OCT Consulting is seeking an IT Security Vulnerability Specialist to join its growing Cybersecurity practice. This hybrid position supports a federal client, requiring at least three days per week onsite in Suitland, MD. The specialist will lead remediation efforts, conduct vulnerability assessments, and develop security policies, procedures, and standards related to vulnerability management.

Key focus areas include Lead and drive remediation efforts within government environment., Articulate risk and impact to product, engineering and other business leaders., and Conduct internal vulnerability assessments and vulnerability analysis..

Successful candidates bring 7+ Years A&A Support Experience, Bachelor's Degree Or Equivalent Experience, and GIAC GEVA. Important skills include Vulnerability Management, Intrusion Prevention And Detection, Access Control And Authorization, Policy Enforcement, Application Security, and Protocol Analysis. Preferred (not required): Articulate Risk And Impact, Vulnerability Assessments, Vulnerability Analysis, and Vulnerability And Code Scanning.

Skills & qualifications

RequiredNice to have

Skills

Vulnerability ManagementIntrusion Prevention and DetectionAccess Control and AuthorizationPolicy EnforcementApplication SecurityProtocol AnalysisFirewall ManagementIncident ManagementData Loss Prevention (DLP)CryptographyMFAWeb FilteringAdvanced Threat ProtectionNIST RMF FrameworkNIST 800-53NIST 800-53AVulnerability Scanning PlatformsSecurity Technical Information Guides (STIG)CIS BenchmarksExcelArticulate Risk and ImpactVulnerability AssessmentsVulnerability AnalysisVulnerability and Code ScanningSecurity ConfigurationSecurity Policies DevelopmentSecurity Procedures DevelopmentSecurity Standards DevelopmentSecurity AuditsSecurity AssessmentsVulnerability Re-ProductionFix ValidationReports and Dashboards CreationSecurity OperationsConfiguration Management Plans

Qualifications

7+ Years a&a Support ExperienceBachelor's Degree or Equivalent ExperienceGIAC GEVACASPCAPCISSPCISMGSECGMONSecurity+US CitizenSECRET Clearance

Benefits

Medical Insurance
Dental Insurance
Vision Insurance
401(k) Match
Paid Time Off

Full job description

Associate / IT Security Vulnerability Specialist (0036)

OCT Consulting is a management and technology consulting firm that supports Federal Government clients. We provide consulting services in the areas of Data Analytics, Change Management, Program and Project Management, Acquisition/Procurement, and Information Technology.

OCT is currently looking for an Associate to join our growing Cybersecurity practice. This position will primarily support a federal client as an IT Security Vulnerability Specialist, which is a hybrid position requiring at least 3 days per week onsite in Suitland, MD. The ideal candidate will be proficient in key areas of security such as: Vulnerability Management, Intrusion Prevention and Detection, Access Control and Authorization, Policy Enforcement, Application Security, Protocol Analysis, Firewall Management, Incident Response, Data Loss Prevention (DLP), Encryption, Two-Factor Authentication, Web filtering, and Advanced Threat Protection.

Responsibilities will include, but are not limited to:

  • Lead and drive remediation efforts within government environment to increase the efficiency of vulnerability management processes.

  • Articulate risk and impact to product, engineering and other business leaders with the ability to convey the urgency and need to remediate a vulnerability commensurate with the risk it presents to the enterprise.

  • Conduct internal vulnerability assessments and vulnerability analysis upon external vulnerability reports, zero-day announcements, security incidents etc.

  • Monitor and maintain vulnerability and code scanning, security configuration and other vulnerability management tools.

  • Develop, maintain, and recommend security policies, procedures, and standards related to vulnerability management.

  • Participate in security audits and assessments to ensure compliance with regulatory requirements and industry standards.

  • Perform vulnerability re-production and fix validation of vulnerabilities where required.

  • Maintain strong knowledge of ongoing security threats, remediations and operational best practices in the threat and vulnerability management.

  • Create reports and dashboards to drive vulnerability remediation efforts and process improvements.

  • Drive regular operational and business reviews for threat and vulnerability management activities.

  • Support other security operation activities as needed (e.g. detection and response).

  • Participate in the Security Incident response.

  • Review, evaluate, refine, release and maintain Configuration Management Plans in support of program requirements.

  • Provide recommendations and guidance for the identification of Configuration Items (CI) and Computer Software Configuration Items (CSCI).

  • Provide guidance and expertise in the establishment, monitoring and maintenance of configuration baselines on assigned programs.

  • Monitor effectiveness and compliance on assigned programs.

Requirements

Requirements:

  • 7+ years of experience with A&A support.

  • Proficient in all steps in the NIST RMF framework

  • Knowledgeable in NIST special publications such as 800-53 & 800-53A

  • Bachelor's degree or equivalent experience

  • In-depth understanding and hands-on experience with multiple vulnerability scanning platforms, to include scanning with Security Technical Information Guides (STIG) and CIS benchmarks.

  • MS Excel proficiency.

  • A related industry certification such as GIAC GEVA, CASP, CAP, CISSP, CISM, GSEC, GMON, Security+.

  • Must be a US Citizen.

  • SECRET clearance required

Benefits

Benefits

The position includes competitive compensation and a full suite of benefits:

  • Medical, Dental, and Vision insurance

  • Retirement savings 401K plan provided by an industry-leading provider with 3% employer contributions.

  • Paid Time Off

  • Life Insurance, Short- and Long-Term Disability benefits

  • Training Benefits

Salary: $110,000-$130,000 to commensurate with experience, education, etc.

About OCT Consulting

OCT Consulting LLC is a Small Business (SB) providing professional services and information technology solutions to the Federal government and commercial clients. Founded in 2013, we bring the agility of operations and a management team with a track record of leading successful engagements at major Federal government agencies.

At OCT we believe in creating a work environment where employees can thrive based on their abilities, skills, and achievements. We are dedicated to providing career growth and professional development based on individual merit and fostering a workplace where everyone’s contributions are valued and recognized.

You've read the whole posting — now see how you match it.