INFO SECURITY ANALYST IV (STIG Compliance/Vulnerability Management SME)

ABBTECH Professional Resources, Inc.

This program requires US Citizenship

An active DoD Top Secret clearance

Fairmont, WV or Boulder, CO

5 days a week in Office with the possibility of 2 days remote

This position is part of the NOAA Cyber Security Center (NCSC) Security Operations Center (SOC) that executes 24×7 cybersecurity monitoring and incident response for NOAA networks. The STIG Compliance/Vulnerability Management Subject Matter Expert (SME) will work on the ISSO team to help manage the Vulnerability Management plan as well as institute a STIG compliance program. Additionally, as part of the Information Assurance team, develops assessment and validation strategies to ensure compliance. As STIG Compliance/Vulnerability Management SME be capable of understanding a multitude of different technologies, including but not limited to, Windows (workstations and desktops), Linux, Juniper, Cisco, appliances like iDrac, and other applications. Additionally, they need to not only be able to use Tenable/ ACAS, but also should be familiar with EvaluateSTIG, Compliance Viewer and other tools.

As the STIG Compliance/Vulnerability Management SME, you will work either independently or as part of a team to achieve critical mission objectives, ensuring smooth operations for the customer.

What Will You Do

• Evaluate security risks on systems

• Evaluate STIG compliance

• Execute and manage the NCSC Vulnerability Management Plan

• Create and maintain compliance scan policies

• Maintain a master asset list

• Troubleshoot scan issues and coordinate with appropriate team members

• Continuously research emerging threats to the environment in order to disseminate the information to all stakeholders, immediately assess the known environment for presence of the vulnerability, and work with the SOC and SE&O to protect the NOAA environment

• Ensure system compliance against federal, DOC, NOAA policies

• Identify & document all non-compliant areas

• Support Assessment and Authorization activities

• Conduct, operate, and maintain vulnerability/compliance assessments and the resulting data and reports

• Author and maintain SOPs and runbooks

• Other duties as assigned

Job Qualifications

• Bachelors degree in Information Technology, Cybersecurity, or related field with 8 or more years of STIG Compliance/Vulnerability Management experience to including implementing and evaluating STIG controls and security baselines; additional years of experience required in lieu of a Bachelors degree.

• Significant experience with NIST Cybersecurity Framework and/or risk management within the Intelligence Community.

• 2 years of project management experience.

• Experience being part of a high performing A&A teams and adapting standards to create “best practices”.

• Demonstrate knowledge of ports and protocols

• Demonstrate knowledge of DISA STIGs and related tools

• Possess the knowledge of security best practices, security solutions, and methodologies for risk management per NIST Cybersecurity Framework guidelines.

• Deep technical understanding of core current cybersecurity technologies as well as emerging capabilities.

•Familiar with the management, operational, and technical aspects of IT Security in a complex environment.

Position Details:

Pay Rate / Range:$60-$74.50

The above salary range represents the range expected for the position; however, final salary offers are based on a number of factors such as the position’s responsibilities; the candidate’s experience, education, and skills; location; travel required; and current market conditions.

Benefits (Regular, Full Time Employees):

1. Medical, Dental, and Vision offerings

2. Weekly Direct Deposit

3. Paid Holidays and Personal Time Off

4. 401(k) with match

5. Voluntary Life and AD&D, Short / Long Term Disability, plus other voluntary coverages

6. Pre-Paid Legal and Employee Assistance Programs

7. Northwest Federal Credit Union Membership

8. BB&T @ Work Program

ABBTECH is an EOE/Minorities/Women/Disabled Individuals/Veterans

tag#IND1

Show Full Vacancy