Vulnerability Management Security Engineer

3 weeks ago


Washington, United States Coalfire Federal Full time

Coalfire Federal is a market leading cybersecurity consultancy that provides independent and tailored advice, assessments, technical testing, and a full suite of cybersecurity engineering services to Federal agency customers. Coalfire Federal along with its parent company, Coalfire, has an unparalleled client list with deep customer relationships with leading cloud and technology providers including Amazon, Microsoft, IBM, Google and Oracle and Federal agencies. Coalfire has been a cybersecurity thought leader for over 20 years and has offices throughout the United States and Europe and is committed to making the world a safer place by solving our clients' toughest security challenges.

But that's not who we are - that's just what we do.

We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team of passionate problem-solvers who are hungry to learn, grow, and make a difference.

We're on the lookout for a Vulnerability Management Security Engineer (VSE) to support our Federal team.

Location

Our clientele is largely in the government space, primarily within the Washington, D.C. / Maryland / Northern Virginia (DMV) areas. While we do offer opportunities that are remote, hybrid, or on-site - a position location and travel may vary based on client needs, and so local candidates may be preferred.

WHAT YOU'LL DO

  • Assist in developing and maintaining security policies and standards, and ensuring compliance throughout the organization.
  • Support the planning and implementation of VM Tools in the detection and tracking of security vulnerabilities.
  • Monitors availability of system updates, and assists with their installation on security tools.
  • Assist with investigations of security issues, collect Incident Response data, and summarize report findings.
  • Analyze processes and technologies to ensure comprehensive protection exists on computer systems to prevent unauthorized entry to computer systems or compromise of data integrity or confidentiality.
  • Provide up-to-date working knowledge in areas such as computer viruses, intrusion detection systems, encryption systems, firewalls, etc.
  • Configure agency Vulnerability Management tools
  • Generate, Analyze and Report on existing vulnerabilities and recommend mitigations.
  • Monitoring of US-Cert, SANS and additional sources focused on new and evolving vulnerabilities affecting IT security

WHAT YOU'LL BRING

  • Demonstrated experience working with and securing Cisco, ESXi, Linux, Solaris and Windows operating systems based on defined policy guidance.
  • Experience with regex, bash, PowerShell, and VBScript scripting languages.
  • Ability to explain events and produce reports based on the data generated in vulnerability tools.
  • A solid understanding of the current threats and tactics being used to attack systems.
  • Experience providing similar service to other clients.
  • Prior experience working with MS SQL Server.
  • A strong knowledge of vulnerability management tools and methodologies such as Tenable Nessus, Qualys WAS, Nexpose, Burp Suite Pro
  • A strong appetite to learn and ability to translate evolving threats and mitigations to real world recommendations.
  • Ability to recognize and escalate risks, issues, and concerns when necessary.

Education

Completed Bachelor's degree from an accredited university in an IT related field.

Clearance / Suitability

Ability to obtain a clearance or a Public Trust is preferred, however all clearance levels and non-cleared applicants will also be considered.

Certifications

Our aim is to build a technologically diverse team - so while we don't have a set list, there may be certain benchmarks we look for that apply to your expertise. We recommend checking out the DoD Approved 8570 Baseline Certifications as an example.

Preferred certifications typical for roles in our federal delivery services include: Security+, CEH, CISA, CISSP, CISM, or other industry recognized certification(s).

Years of Experience

  • At least three (3) to five (5) years of demonstrated experience implementing, configuring, and maintaining vulnerability management tools in an enterprise environment (i.e., Tripwire, Nessus, MS Defender, etc.).

WHY JOIN US

Our people make Coalfire Federal great. We work together on interesting things and achieve exceptional results. We act as trusted advisors to our customers and are committed to client-focused innovation as well as innovation in the industries that we serve.

Coalfire offers our people the chance to grow professionally with colleagues they like and respect while tackling challenges that stretch their minds and expand their skill sets. Regardless of location, you'll experience a company that prioritizes connection and wellbeing and be part of a team where people care about each other and our communities. You'll have opportunities to join employee resource groups, participate in in-person and virtual events, and more.

And you'll enjoy competitive perks and benefits to support you and your family, like paid parental leave, flexible time off, certification and training reimbursement, digital mental health and wellbeing support membership, and comprehensive insurance options.

Coalfire is an EEO employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.



  • Washington, United States META Full time

    Summary: The Meta Security Organization is seeking a passionate and experienced Security Engineer to help us mature Meta’s security posture through our vulnerability management program. Our team strives to go beyond identifying vulnerabilities by preventing security problems during the development process to eliminate entire classes of vulnerabilities.Do...


  • Washington, United States META Full time

    Summary: The Meta Security Organization is seeking a passionate and experienced Security Engineer to help us mature Meta’s security posture through our vulnerability management program. Our team strives to go beyond identifying vulnerabilities by preventing security problems during the development process to eliminate entire classes of vulnerabilities.Do...


  • washington, United States Coalfire Federal Full time

    Coalfire Federal is a market leading cybersecurity consultancy that provides independent and tailored advice, assessments, technical testing, and a full suite of cybersecurity engineering services to Federal agency customers. Coalfire Federal along with its parent company, Coalfire, has an unparalleled client list with deep customer relationships with...


  • Washington, United States Coalfire Federal Full time

    Coalfire Federal is a market leading cybersecurity consultancy that provides independent and tailored advice, assessments, technical testing, and a full suite of cybersecurity engineering services to Federal agency customers. Coalfire Federal along with its parent company, Coalfire, has an unparalleled client list with deep customer relationships with...


  • washington, United States Coalfire Federal Full time

    Coalfire Federal is a market leading cybersecurity consultancy that provides independent and tailored advice, assessments, technical testing, and a full suite of cybersecurity engineering services to Federal agency customers. Coalfire Federal along with its parent company, Coalfire, has an unparalleled client list with deep customer relationships with...


  • Washington, United States Fiserv Full time

    Calling all innovators - find your future at Fiserv. We're Fiserv, a global leader in Fintech and payments, and we move money and information in a way that moves the world. We connect financial institutions, corporations, merchants and consumers to one another millions of times a day - quickly, reliably, and securely. Any time you swipe your credit card,...


  • Washington, United States TechnoGen Full time

    I am Kishore from TechnoGen Inc., I am currently looking for Security Vulnerability Engineer - Windows forone of our clients. Below is the job description for your review...Please let me know if you would be interested and please attach your updated resume at kishore.b@technogeninc.com We are seeking a highly skilled Security Vulnerability Engineer with deep...


  • Washington, United States TechnoGen Full time

    I am Kishore Mandaloju from TechnoGen Inc., I am currently looking for Security Vulnerability Engineer - Windows forone of our clients. Below is the job description for your review...Please let me know if you would be interested and please attach your updated resume at kishore.m@technogeninc.com We are seeking a highly skilled Security Vulnerability Engineer...


  • Washington, United States General Dynamics Information Technology Full time

    Type of Requisition:RegularClearance Level Must Currently Possess:NoneClearance Level Must Be Able to Obtain:NonePublic Trust/Other Required:NoneJob Family:Information SecurityJob Qualifications:Skills:Information Technology Security, Remediation, Vulnerability ManagementCertifications:NoneExperience:5 + years of related experienceUS Citizenship...


  • Washington, United States General Dynamics Information Technology Full time

    Type of Requisition:RegularClearance Level Must Currently Possess:NoneClearance Level Must Be Able to Obtain:NoneSuitability:Public Trust/Other Required:NoneJob Family:Information SecurityJob Qualifications:Skills:Information Technology Security, Remediation, Vulnerability ManagementCertifications:Experience:5 + years of related experienceUS Citizenship...


  • washington, United States Serigor Inc Full time

    Job Title: Apps and Server Vulnerability Engineer (Onsite)Location: Washington, DCDuration:12 Months+Job Description:We are looking for a talented and experienced Application and Server Vulnerability Assessment Engineer to join our team. The ideal candidate will be responsible for performing comprehensive security assessments of web applications, mobile...


  • Washington, United States Serigor Inc Full time

    Job Title: Apps and Server Vulnerability Engineer (Onsite)Location: Washington, DCDuration:12 Months+Job Description:We are looking for a talented and experienced Application and Server Vulnerability Assessment Engineer to join our team. The ideal candidate will be responsible for performing comprehensive security assessments of web applications, mobile...


  • Washington, United States h3 Technologies Full time

    Job Title: Apps and Server Vulnerability Engineer (Onsite) Location: Washington, DC Duration: 12 Months+ Additionally, please send me scanned copies of your consultant's Driver's License, H1B copy, i94, and travel history to this email. Job Description: We are looking for a talented and experienced Application and Server Vulnerability Assessment Engineer to...


  • Washington, United States Coalfire Federal Full time

    Cybersecurity Specialist - Vulnerability ManagementCoalfire Federal is a leading cybersecurity consultancy that provides independent and tailored advice, assessments, technical testing, and a full suite of cybersecurity engineering services to Federal agency customers. With an unparalleled client list and deep customer relationships with leading cloud and...


  • Washington, United States VISTRADA Full time

    Job Posting: Security System Engineer (Junior/Intermediate/Senior Level) Vistrada is currently seeking highly skilled and motivated Security System Engineers to join our esteemed team. As a Security System Engineer, you will play a crucial role in identifying and mitigating vulnerabilities, ensuring the secure integration and operation of systems, and...

  • Security Engineer

    4 weeks ago


    Washington, United States Expedite Technology Solutions LLC Full time

    Education: Bachelor's Clearance Required: Public Trust Role Title Security Engineer Start Date for assignment 06/12/2024 End Date for assignment 03/25/2025 # of Resources Needed 2 Hours per Week 40 Job Description This work is Sold Unsold Specialization : Technical Skills : Skill Years/Level of Experience Amazon Web Services (AWS) Security P2 -...


  • Washington, DC, United States Serigor Inc Full time

    Job Title:Apps and Server Vulnerability Engineer (Onsite)Location:Washington, DCDuration:12 Months+Job Description:We are looking for a talented and experienced Application and Server Vulnerability Assessment Engineer to join our team. The ideal candidate will be responsible for performing comprehensive security assessments of web applications, mobile...


  • Washington, United States Global Solutions Consulting (GSC) Full time

    Job DescriptionJob DescriptionPosition Title: Senior Application Security EngineerLocation: Washington, DC (Hybrid)Job Requirements:Strong written and verbal communication skills· Must have GitLab CI/CD pipeline experience· Assist in the development and implementation of the DevSecOps strategy to include the definition and goals of the over-arching...


  • Washington, United States SourcePro Search, LLC Full time

    Our top rated global client is looking for an experienced Senior Application Security Engineer for their Washington, DC office. The ideal candidate will serve as subject matter expert integrating secure design for applications and services within the system development lifecycle. This position collaborates with business units, project management, and...

  • Security Engineer

    3 weeks ago


    Washington, United States GLO Comms Full time

    Overview: A leading global provider of information and analytics in the real estate sector is seeking Security Engineers to join an innovative team. This position focuses on ensuring the security of web applications and offers both onsite and remote opportunities, ranging from Associate to Lead Architect levels.Responsibilities:Develop and maintain a...