Vulnerability Identification & Management

Fort George G. Meade, MD

Posted: 07/18/2019 Job Number: JN -072019-10968
VULNERABILITY IDENTIFICATION & MANAGEMENT

Location: Fort Meade, MD
Industry: Department of Defense
Employment Type: Direct Hire

Job Duties:
Our Client is looking for an experienced Endpoint Compliance analyst to support Joint Force Headquarters - Department of Defense Information Network (JFHQ-DODIN) in the analysis, implementation and maintenance of DOD endpoint program, policies and standards.
They specialize in software development, satellite/terrestrial communications, cyber security, and network engineering/design and provide support worldwide to DOD, Federal Civilian, and Health IT customers.
  • Establish communications with vendors for the release of newly identified vulnerabilities and to ensure they understand the specialized requirements of DoD information systems.
  • Leverage a specialized understanding of vendor products and fix actions to develop mitigations orders for the identified vulnerabilities.
  • Compile daily, weekly and annual vulnerability metrics associated with affected and non-affected DoD products.
  • Utilize the tracking tools to upload information for DoD component consumption and vulnerability compliance tracking.
  • Develop, staff, and maintain accurate JFHQ-DODIN orders.
  • Create situational awareness products to provide DoD components with detailed information related to vulnerabilities and appropriate mitigation strategies.
  • Identify, analyze, and develop mitigation or remediation actions for system and network vulnerabilities.
  • Prioritize identified vulnerabilities based upon severity, potential operational impact, and other factors for DoD.
  • Conduct open source research to identify and analyze known and unknown vulnerabilities.
  • Analyze issues affecting DoD components with vendor provided fixes and contact the appropriate vendor for a defined and attainable solution.
  • Conduct coordination with DISA/FSO, DoD Combatant Commands, Services, Agencies, Field Activities, Intelligence Agencies, LE, US Government organizations.
  • Provide notification of potential threats by tracking vulnerabilities and exploits, propagation of worms and viruses as they migrate throughout DoD and globally Develop, staff, and release analysis findings in technical analysis reports to DoD Community
Qualifications:
  • Active DoD TS/SCI clearance
  • Proficient in developing briefing materials, administrative, and logistics support
  • Have a working understanding of the Risk Management Framework (RMF)
  • Have specialized knowledge in computer network theory and understand IT standards, including the OSI model, and the methods of exploiting those standards
  • Must have advanced communication and presentation skills (verbal and written) enabling precise conveyance of information across all CC/S/A/FA with command and proper enunciation of the English language
  • The candidate must have strong interpersonal, organizational and critical thinking/problem solving skills
  • Must be flexible, dependable and be able to multi-task with priorities
  • Proficiency in use of Microsoft Office Suite
  • 3+ years experience with IA Experience with and/or a working knowledge of the following:
    • DoD Vuleravilitaman
    • Networking infrastructure: routers, switches, and web security gateway
    • TCP/IP Protocols and Services
    • Identification and Access Management
    • SIEM Reports
  • Host Base Security Systems (HBSS)
  • Knowledge of Tanium
  • Enterprise Mission Assurance Support Service (eMASS)
  • Experience at USCYBERCOM or Cyber Service Centers or equivalent.
  • Demonstrated understanding of cyber advanced persistent threats, actors, infrastructure, and TTP's.
  • Demonstrate understanding of defensive cyber operations to include cyber incident response, and Intrusion Detection Systems (IDS).
  • Experience with network analysis and coursework preferred.
  • MA or MS degree preferred.
  • DoD 8570 IAT Level II
  • Certification in any of the following areas: A+, Network+, Security+, CISSP

An Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities


SRG Government Services (SRG) is a leading provider of information technology, training, engineering, accounting and intelligence analytical services for agencies in the intelligence, defense, homeland security, cyber security, and federal civilian markets. SRG utilizes an innovative approach to identify and qualify talent that is unique to the federal contracting industry, featuring a cutting-edge platform that allows us to rapidly and precisely match professionals to client requirements. We have a proprietary database of over one million candidates and maintain continuous contact with our qualified talent.


EOE/ADA
#clearance
Apply Online

Send an email reminder to:

Share This Job:

Related Jobs:

Login to save this search and get notified of similar positions.