Junior Vulnerability Assessment Analysts
Alexandria, VA
Applications have closed
XOR Security
Job Description:
XOR Security is currently seeking several Junior Vulnerability Assessment Analysts to support an Agency-level SOC program. The position will lead the analysts that will conduct enterprise-level security assessments and penetration testing. To support this vital mission, XOR staff are on the forefront of providing Advanced CND Operations, and Systems Engineering support to include the development of advanced analytics and countermeasures to protect critical assets from hostile adversaries. To ensure the integrity, security, and resiliency of critical operations, we are seeking candidates with diverse backgrounds in cyber security systems operations, threat analysis, continuous monitoring, vulnerability assessment, and penetration testing. Candidates must have leadership experience, strong written and verbal communications skills, researching and analysis skills, and attention to detail. The ideal candidate will have a solid understanding of operating system and application vulnerabilities, with hands-on experience conducting enterprise-level vulnerability scans and network penetration testing.
Corporate duties such as solution/proposal development, corporate culture development, mentoring employees, supporting recruiting efforts, will also be required. The program is currently operating remotely but will be performed onsite in Alexandria, VA when directed to do so by the customer.
Position is contingent on successfully completing a program-based background investigation.
Job Duties:
- Schedule and conduct web application, database, operating system, and wireless vulnerability assessments and support penetration testing efforts.
- Develop and review analysis reports resulting from vulnerability assessments and penetration testing.
- Develop follow-up action plans to resolve reportable issues and communicate with the other technologists to address security threats and vulnerabilities.
- Identify security gaps, evaluate and implement enhancements.
- Stay up to date with current vulnerabilities, attacks, and countermeasures and provide a detailed analysis of enterprise risks, compensating controls, and risk mitigation plans.
- Collaborate on problem management and root cause analysis discussions with fellow network engineers, security engineers, and analysts.
- Identification and implementation of counter-measures or mitigating controls for deployment and implementation in the enterprise network environment.
Required Qualifications:
- Mid-level analysts: 3 years of demonstrated experience in vulnerability assessments for an enterprise network, analyzing vulnerabilities, providing assessments and remediation instructions, and applying Information Systems Security principles and methods.
- Junior analysts: 1 year of demonstrated experience in vulnerability assessments for an enterprise network, analyzing vulnerabilities, providing assessments and remediation instructions, and applying Information Systems Security principles and methods.
- Bachelor’s Degree in Information Technology, Cyber Security, Computer Science, Computer Engineering, or Electrical Engineering.
- Experience with Application Security implementation, understanding of Firewall Management and Advanced Threat Protection, familiarity with Access Control, Authorization, Intrusion Prevention and Intrusion Detection, familiar with Protocol Analysis and requirements when handling sensitive and classified Information, familiar with FISMA compliance and Risk Management Framework.
- Strong analytical and technical skills in conducting vulnerability assessments, conduct troubleshooting of failed scans, as well as abilities and prior experience with analyzing vulnerability reports from enterprise assessment tools.
- Ability to assess large-scale reporting, analyze trends, and provide contextual reporting to senior management and system owners.
- Excellent organizational and attention to detail in tracking and reporting compliance activity and trend analysis of enterprise vulnerabilities.
- A working knowledge of the various operating systems (e.g. Windows, OS X, Linux, etc.) commonly deployed in enterprise networks, a conceptual understanding of Windows Active Directory is also required, and a working knowledge of network communications and routing protocols (e.g. TCP, UDP, ICMP, BGP, MPLS, etc.) and common internet applications and standards (e.g. SMTP, DNS, DHCP, SQL, HTTP, HTTPS, etc.).
Desired Qualifications:
- One or more certifications for VAT Analysts: GPEN, GWAPT, GSNA, GMON, GISF, GAWN, GWEB, GXPN, CEH, GNFA, OSCP, OSEE, OSCE, OSWP, CISSP
Closing Statement:
XOR Security offers a very competitive benefits package including paid health insurance coverage from first day of employment, 401k with a vested company match, vacation and supplemental insurance benefits.
XOR Security is an Equal Opportunity Employer (EOE). M/F/D/V.
Citizenship Clearance Requirement
Applicants selected may be subject to a government security investigation - Applicants must meet eligibility requirements – US CITIZENSHIP REQUIRED.
Tags: Active Directory Analytics Application security CEH CISSP Clearance Compliance Computer Science DNS Firewalls FISMA GNFA GPEN GWAPT GXPN Intrusion detection Intrusion prevention Linux Monitoring OSCE OSCP OSEE OSWP Pentesting Risk management Security assessment SMTP SQL Vulnerabilities Vulnerability scans Windows
Perks/benefits: 401(k) matching Health care
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Ethical hacker / Pentester H/F jobs
- Open Information Security Specialist jobs
- Open Cyber Security Architect jobs
- Open Staff Security Engineer jobs
- Open Manager Pentest H/F jobs
- Open Senior Information Security Analyst jobs
- Open Senior Cyber Security Engineer jobs
- Open Cyber Security Specialist jobs
- Open Product Security Engineer jobs
- Open Principal Security Engineer jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open IT Security Analyst jobs
- Open Cybersecurity Analyst jobs
- Open Chief Information Security Officer jobs
- Open Cybersecurity Consultant jobs
- Open Senior Information Security Engineer jobs
- Open Consultant SOC / CERT H/F jobs
- Open Security Specialist jobs
- Open Cybersecurity Specialist jobs
- Open Senior Penetration Tester jobs
- Open Sr. Security Engineer jobs
- Open Security Researcher jobs
- Open Senior Security Architect jobs
- Open IT Security Engineer jobs
- Open Clearance-related jobs
- Open ISO 27001-related jobs
- Open Network security-related jobs
- Open Application security-related jobs
- Open Windows-related jobs
- Open Agile-related jobs
- Open Pentesting-related jobs
- Open Vulnerability management-related jobs
- Open GCP-related jobs
- Open Analytics-related jobs
- Open SaaS-related jobs
- Open CISA-related jobs
- Open IAM-related jobs
- Open Threat intelligence-related jobs
- Open APIs-related jobs
- Open Java-related jobs
- Open Security assessment-related jobs
- Open DevOps-related jobs
- Open Malware-related jobs
- Open Kubernetes-related jobs
- Open Security Clearance-related jobs
- Open CI/CD-related jobs
- Open IDS-related jobs
- Open CEH-related jobs
- Open EDR-related jobs