See more Collapse

IT Specialist

1 month ago


Gaithersburg, United States National Institute Of Standards And Technology Full time

The Engineering Laboratory (EL) promotes U.S. innovation and industrial competitiveness by advancing measurement science, standards, and technology for engineered systems, which enhances economic security and improves quality of life.

The EL's Data, Security, and Technology Group is looking for an Information Technology Specialist (Security) to join our team

If selected, your responsibilities will include:

Continuous Monitoring and Security SupportProcess:
Implement ongoing continuous monitoring for EL Information Technologist Security Officers (ITSO's).
Review daily reports, prioritize findings, and plan mitigation based on impact and criticality.
Write procedures for researchers and staff to follow to self-mitigate specific vulnerabilities.
Collaborate with researchers and staff to apply necessary patches or updates, ensuring compliance with DOC mandates.
Collaborate with other support groups to recommend security improvements.
Provide technical support to researchers trying to follow mitigation procedures.
Identify false positives and potential accepted risks and report to ITSOs for formal reporting.
Provide progress updates to ITSOs for reporting to the CISO.

Implementation of Vulnerability and Configuration Management:

Address vulnerabilities across Windows, Mac, Linux, and research devices by working with researchers to determine appropriate mitigation actions.
Provide security upport for laboratory video endpoints, video conferencing systems, printers, and other networked devices.
Support configuration management based on NIST requirements for all hardware and software types.
Develop and execute remediation strategies with the technical team.
Patch and update software and operating systems.
Provide scanning support to update reports and remove findings.
Address vulnerabilities on both on-premises and AWS server systems.
Remediate vulnerabilities in client, server, and specialized research hardware, including legacy systems and localized networking.