Vulnerability Assessment Analyst / Information Systems Security Engineer (ISSE)

Omniscius Consulting

  • Annapolis Junction, MD
  • 4 days ago

    Highlights

    Our client is seeking a Vulnerability Assessment Analyst / Information Systems Security Engineer (ISSE) to support vulnerability management and continuous monitoring activities in a highly secure environment. The position will focus heavily on Tenable Security Center, Nessus/ACAS vulnerability scanning, DISA STIG compliance, vulnerability remediation, and Windows/Linux security.

    Numbers & Facts

    LocationAnnapolis Junction, MD

    Description

    Location: Annapolis Junction, MDSchedule: Part-Time – Evenings and WeekendsClearance: Active TS/SCI with Full Scope Polygraph required

    Position Overview

    Our client is seeking a Vulnerability Assessment Analyst / Information Systems Security Engineer (ISSE) to support vulnerability management and continuous monitoring activities in a highly secure environment. The position will focus heavily on Tenable Security Center, Nessus/ACAS vulnerability scanning, DISA STIG compliance, vulnerability remediation, and Windows/Linux security.

    The position is based at a contractor site in Annapolis Junction, Maryland, with a part-time evening and weekend schedule.

    Responsibilities

    • Maintain and optimize the Tenable Security Center infrastructure.
    • Perform security assessments, patching, and vulnerability scans of Linux Security Center servers using Tenable Nessus.
    • Identify and mitigate DISA STIG findings and vulnerabilities across Tenable Security Center and Windows/Linux Nessus scanning servers.
    • Install, configure, maintain, and update Tenable Nessus and Tenable Security Center software.
    • Configure and fine-tune vulnerability scanning policies and asset lists to ensure comprehensive coverage.
    • Conduct recurring vulnerability assessments across multiple device types and operating systems.
    • Use Nessus/ACAS to identify vulnerabilities across customer assets as part of continuous monitoring activities.
    • Review and analyze Nessus/ACAS scan results and provide remediation guidance.
    • Analyze vulnerability scan results and develop comprehensive reports.
    • Monitor and track vulnerability remediation activities through completion.
    • Coordinate with Information Systems Security personnel and other technical teams to ensure vulnerabilities are addressed in a timely manner.
    • Communicate security posture, vulnerabilities, and potential risks to technical and management stakeholders.
    • Maintain accurate documentation and records related to vulnerabilities and security incidents.

    Required Qualifications

    • Active TS/SCI clearance with Full Scope Polygraph.
    • Hands-on experience with enterprise vulnerability management and scanning solutions such as Tenable Security Center, Tenable Nessus, and/or ACAS.
    • Familiarity with DISA STIGs, Tenable Audit Files, and/or CIS Benchmarks.
    • Knowledge of system and application security threats and vulnerabilities.
    • Working knowledge of:
      • Linux/Unix administration
      • Windows administration
      • Networking
      • Patch deployment
      • System configuration
    • Ability to analyze vulnerability scan results and support remediation efforts.

    Education & Experience

    Candidates must meet one of the following combinations:

    • High School Diploma/GED + 11 years of relevant experience, OR
    • Bachelor's Degree + 7 years of relevant experience.

    Certification Requirements

    • Must meet DoD 8570 IAT Level II requirements.
    • Acceptable certifications identified for the position include:
      • CompTIA Security+ CE
      • CEH

    Training alone is not acceptable as a substitute for the required CE certification.

    Preferred Qualifications

    • In-depth knowledge of vulnerability assessment methodologies, tools, and industry best practices.
    • Strong analytical and problem-solving skills with excellent attention to detail.
    • Self-starter capable of owning technical tasks from beginning to end.
    • Ability to work effectively both independently and as part of a technical team.
    • Strong written and verbal communication skills for presenting vulnerability findings and security risks to stakeholders.

    Security Requirements

    Candidates must possess an active TS/SCI clearance with Full Scope Polygraph and be able to operate as a privileged user within the supported environment.

    Powered by JazzHR