Security Vulnerability Engineer

2 weeks ago


McLean, United States Eliassen Group Full time

Description:

The Security Vulnerability Engineer will provide critical support in identifying, analyzing, and remediating vulnerabilities across an infrastructure consisting of over 2000 windows servers. This will include analyzing reports from multiple streams and sources as well as remediating and assigning to other members of the team when needed. This position requires a mixture of engineering, operations, hands on technical and support skills. Qualified candidates should have excellent troubleshooting and analytical skills. The individual will work closely with technical leads, infrastructure and operations teams and other cross-department teams to evaluate business needs and provide end-to-end technical solutions and manage, operate, monitor, audit, secure server assets.

Due to federal security clearance requirements, applicant must be a United States Citizen or Permanent Resident with an active Public Trust clearance.

This is a contract to hire opportunity. Applicants must be willing and able to work on a w2 basis and convert to FTE following contract duration. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance.

Rate: $55 - $50 / hr. w2

Responsibilities:

This position requires a minimum 2x/week onsite.

Once every 2-3 months support server infrastructure in a 24x7 on-call escalation capacity as part of a team rotation.

Performs security hardening, patching and server certificate updates.

Run system scans and analyze reports on system vulnerabilities on over 2000 windows servers in the enterprise.

Maintain and update environmental documentation, standard Operating Procedures, and engineering documentation.

Provide support to system administrators to resolve issues when required provide support in response to outages including conducting root cause analysis.

Recognize and escalate risks, issues, and concerns when necessary.

Analyze vulnerability reports identify areas of responsibility for remediation.

Resolve known exploited vulnerabilities, prioritizing critical and highs.

Facilitate coordination of vulnerability remediations across the team.

Develop and provide recommendations and remediations for vulnerabilities.

Harden Windows OS with secure versions of Transport Layer Security (TLS), and cipher suites according to NIST policy.

Assist Security Operations personnel in developing Plan of Action & Milestones (POAM's) for vulnerabilities requiring long-lead time resolve.

Work closely with the SCCM/Deployment team to perform routine and bulk patching as well as reporting.

Provide on-call support and manage ticket queue.

Demonstrate a strong appetite to learn and translate evolving threats into real world recommendations.

Demonstrate strong knowledge of vulnerability management tools such as Tenable Nessus, Qualys WAS, Inviciti, and BigFix.

Have a solid understanding of IPV4 and IPV6 networking.

Experience Requirements:

Expert-level knowledge of Windows OS-based computer devices (Windows 10, Windows 11)

Demonstrate expert knowledge of Windows OS to include W2K12R2, W2K16, W2k19, W2k22.

Expert knowledge and troubleshooting skills to resolve failed update installation in Windows OS.

Expert knowledge of AD Group policy and applying security posture via GPO's.

Strong knowledge of System Center Configuration Manager (SCCM).

Experience with performing root cause analysis, risk identification, and risk mitigation

Understanding of FIPS 140-3 or cryptographic modules and how they are used.

Must be a self-started with strong problem solving and communication skills.

Strong knowledge of NIST-800 framework and security guidelines for windows servers and clients including DISA STIG

Strong knowledge of CIS Benchmark guidelines for Microsoft Windows servers

Experience with scripting tools such as, PowerShell, Azure CLI, AWS CLI, Python, and VBScript.

Experience with Nessus Tenable scanning tools and reporting.

Expert level experience with MS Office tools such as Excel, PowerPoint, Vizio, Word.

Experience with installing hardware drivers, firmware, bios, and other hardware upgrades for Dell servers.

Demonstrate knowledge of common ports and protocols used by Windows servers and clients.

Preferred

Security certification(s) highly preferred such as Security+, CISSP, CASP+, CISA, CISM etc.

Experience Linux/Ansible, and/or Unix experience are a plus.

Experience with Dell Open Manage Enterprise is a plus.

Experience with PowerBI is a plus.

Experience with Microsoft Intune is a plus.


  • Security Engineer

    2 weeks ago


    McLean, United States Alarm.com Full time

    As a Cloud Security Engineer, the primary role is to support the security of our cloud environments across AWS, GCP, and Azure. This involves assisting in identifying and mitigating security risks, using cloud-native security tools, and helping manage security solutions. The engineer will work with various teams to incorporate security into the software...


  • McLean, United States Diverse Lynx Full time

    Technical expertise in JAVA Perform regular vulnerability scans and assessments of IT infrastructure and applications Analyze vulnerability scan results, prioritize risks and coordinate remediation efforts with relevant teams Collaborate with incident response team to identify root causes and implement preventive measure Develop and maintain a comprehensive...


  • McLean, United States ManTech Full time

    Description & Requirements ManTech is seeking a highly skilled and motivated Cyber Detection and Response Analyst to join our dynamic Cyber Incident Response Team.  As a key member of the team, you will be responsible for proactively monitoring, detecting, analyzing, and responding to cybersecurity incidents within our large enterprise network. Your...


  • McLean, United States MITRE Full time

    Why choose between doing meaningful work and having a fulfilling life? At MITRE, you can have both. That's because MITRE people are committed to tackling our nation's toughest challenges—and we're committed to the long-term well-being of our employees. MITRE is different from most technology companies. We are a not-for-profit corporation chartered to work...


  • McLean, United States The Metamorphosis Group, Inc. Full time

    Cyber Security Project Engineer TS/SCI Clearance with FSP REQUIRED McLean, VA · Government/Military Apply Now Description: MUST BE US CITIZEN MUST POSSESS ACTIVE TS/SCI with FSP - candidates without required clearances cannot be considered TMG is the proud recipient of the Employer Support of Guard and Reservists by the SECDEF. TMG is an Equal...


  • McLean, United States Alarm.com Full time

    The Senior Cloud Security Engineer will identify security risk in the corporate network, communicate those risks to management and assist with the mitigation efforts. Common technologies this position will need to work with include vulnerability scanning, intrusion detection, SIEM, database monitoring, and file integrity monitoring. The Senior Security...


  • McLean, United States McIntire Solutions, LLC Full time

    Required Skills • Ability to create queries and alerts that feed into a dashboard for monitoring and analysis of various logs • Experience with creating Splunk dashboards • Provide analysis and review of Splunk audit logs to include OS, database, and application logs • Experience in evaluating query results and reporting results to the customer...

  • DevOps Engineer

    3 weeks ago


    McLean, Virginia, United States TheIncLab Full time

    About TheIncLabTheIncLab is a human-centered artificial intelligence (AI+X) lab that engineers and delivers advanced systems to revolutionize how our customers, the Department of Defense, and mission-critical teams achieve success.We are looking for a talented DevOps Engineer - Cloud Security Specialist to join our team.Key ResponsibilitiesDevelop and...


  • McLean, United States Appian Corporation Full time

    Job DescriptionJob DescriptionHere at Appian, our core values of Respect, Work to Impact, Ambition, and Constructive Dissent & Resolution define who we are. In short, this means we constantly seek to understand the best for our customers, we go beyond completion in our work, we strive for excellence with intensity, and we embrace candid communication. These...


  • McLean, United States Pyramid Consulting Full time

    Immediate need for a talented Security Engineer Specialist. This is a 06+months contract opportunity with long-term potential and is located in U.S(Remote). Please review the job description below and contact me ASAP if you are interested. Job ID:24-24372 Pay Range: $70 - $75/hour. Employee benefits include, but are not limited to, health insurance (medical,...


  • McLean, United States Booz Allen Hamilton Full time

    Vulnerability Management and Attack Surface Reduction LeadKey Role:Work as a Vulnerability Management Lead, including leading and supporting the development and delivery of a diverse range of attack surface reduction consulting and operations service programs to a portfolio of our commercial and government clients. Operate as a part of a team that delivers...


  • McLean, United States MITRE Full time

    Why choose between doing meaningful work and having a fulfilling life? At MITRE, you can have both. That's because MITRE people are committed to tackling our nation's toughest challenges—and we're committed to the long-term well-being of our employees. MITRE is different from most technology companies. We are a not-for-profit corporation chartered to work...


  • McLean, United States Booz Allen Hamilton Full time

    Information Security Engineer, Senior The Opportunity: Are you looking for an opportunity to share your experience in network security, DNS, IPAM, and security analysis to support an enterprise level business? As an Information Security Engineer, you can identify the requirements needed to assess vulnerabilities and recommend the best solution and...


  • McLean, United States MITRE Full time

    Why choose between doing meaningful work and having a fulfilling life? At MITRE, you can have both. That's because MITRE people are committed to tackling our nation's toughest challenges—and we're committed to the long-term well-being of our employees. MITRE is different from most technology companies. We are a not-for-profit corporation chartered to work...


  • McLean, United States Arcfield Full time

    OverviewArcfield was purpose-built to protect the nation and its allies through innovations in digital transformation, space mission engineering and launch assurance, miniaturized sensors and satellites, advanced modeling and simulation, cybersecurity, and conventional and hypersonic missile support. Headquartered in Chantilly, VA with 16 global offices,...


  • McLean, Virginia, United States NODAL EXCHANGE Full time

    Nodal Exchange Job DescriptionJob Title: Senior Cybersecurity EngineerJob Summary: Nodal Exchange, a leader in innovation, is seeking a talented Cybersecurity Engineer to join our team in the DC Metro area. As a Cybersecurity Engineer, you will be responsible for assessing and mitigating security risks, ensuring the confidentiality, integrity, and...


  • McLean, United States Booz Allen Hamilton Full time

    Information Systems Security EngineerThe Opportunity:Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming. In all of this “cyber noise,” how can these organizations understand their risks and how to mitigate them? The answer is you—an information security risk specialist who...


  • McLean, United States Vets Hired Full time

    We are seeking a Information Assurance Security Advisor that provides technical and programmatic information assurance services to internal and external customers in support of network and information security systems. Designs develops and implements security requirements within an organizations business processes.Prepares documentation from information...


  • McLean, Virginia, United States Alarm Full time

    The Senior Cloud Security Engineer will identify security risks in the corporate network, communicate those risks to management, and assist with mitigation efforts. Common technologies this position will need to work with include vulnerability scanning, intrusion detection, SIEM, database monitoring, and file integrity monitoring. The Senior Security...


  • McLean, Virginia, United States Steampunk Full time

    About the RoleWe are seeking a highly skilled Cloud Security Architect to join our team at Steampunk. As a key member of our DevSecOps practice, you will be responsible for delivering features to support developing, testing, and monitoring secure cloud architectures for cloud migration, cloud optimization, and cloud deployment.Key ResponsibilitiesDesign and...