Find Jobs
Find Jobs Near You – Available Work in Your Location
Skip to job details
OC
OCT Consulting, LLC
IT Security Vulnerability Specialist (0036)
Career Insights for IT Specialist / Engineer
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Maryland data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
An IT Specialist or Engineer provides information technology support for a business or organization. Coordinates installation, maintenance and upgrades of computer software and hardware. Maintains computer networks, monitors network security and provides database management. Manages communication with system users and vendors.
$94,716 / year median in Maryland
+1% projected growth
Job Description
Associate / IT Security Vulnerability Specialist (0036) OCT Consulting is a management and technology consulting firm that supports Federal Government clients. We provide consulting services in the areas of Data Analytics, Change Management, Program and Project Management, Acquisition/Procurement, and Information Technology. OCT is currently looking for an Associate to join our growing Cybersecurity practice. This position will primarily support a federal client as an IT Security Vulnerability Specialist , which is a hybrid position requiring at least 3 days per week onsite in Suitland, MD. The ideal candidate will be proficient in key areas of security such as: Vulnerability Management, Intrusion Prevention and Detection, Access Control and Authorization, Policy Enforcement, Application Security, Protocol Analysis, Firewall Management, Incident Response, Data Loss Prevention (DLP), Encryption, Two-Factor Authentication, Web filtering, and Advanced Threat Protection. Responsibilities will include, but are not limited to: Lead and drive remediation efforts within government environment to increase the efficiency of vulnerability management processes. Articulate risk and impact to product, engineering and other business leaders with the ability to convey the urgency and need to remediate a vulnerability commensurate with the risk it presents to the enterprise. Conduct internal vulnerability assessments and vulnerability analysis upon external vulnerability reports, zero-day announcements, security incidents etc. Monitor and maintain vulnerability and code scanning, security configuration and other vulnerability management tools. Develop, maintain, and recommend security policies, procedures, and standards related to vulnerability management. Participate in security audits and assessments to ensure compliance with regulatory requirements and industry standards. Perform vulnerability re-production and fix validation of vulnerabilities where required. Maintain strong knowledge of ongoing security threats, remediations and operational best practices in the threat and vulnerability management. Create reports and dashboards to drive vulnerability remediation efforts and process improvements. Drive regular operational and business reviews for threat and vulnerability management activities. Support other security operation activities as needed (e.g. detection and response). Participate in the Security Incident response. Review, evaluate, refine, release and maintain Configuration Management Plans in support of program requirements. Provide recommendations and guidance for the identification of Configuration Items (CI) and Computer Software Configuration Items (CSCI). Provide guidance and expertise in the establishment, monitoring and maintenance of configuration baselines on assigned programs. Monitor effectiveness and compliance on assigned programs.