Senior Cybersecurity Auditor

Goldbelt
United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$100,000.0 - $170,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Artificial Intelligence Apache HTTP Server Software Applications Software System Penetration Testing VoIP Unix Cloud Computing Security Communications Protocols Cyber Security Information Systems Computer Networks
+19 more
Databases Domain Name System (DNS) Internet Information Services (IIS) Microsoft SQL Server System Center Configuration Manager Oracle (Applications) Phishing Security Content Automation Protocol Web Services Network Routers Computer Networking Systems Enterprise Software Applications IT Architecture Firewalls (Computer Science) SC Clearance Information Technology Nessus 3-tier Architectures Vulnerability Analysis

Job description

The Senior Cybersecurity Auditor provides independent security assessment and compliance oversight in support of the Defense Logistics Agency (DLA) under the J6 Enterprise Technology Services (JETS) contract. Responsibilities: Essential Job Functions:

  • Independently performs complex security analysis of classified and unclassified applications, systems, and enclaves for compliance with security requirements.
  • Performs Command Cyber Readiness Inspections and cybersecurity vulnerability evaluations.
  • Uses a variety of security techniques, technologies, and tools to evaluate security posture in highly complex computer systems and networks.
  • Performs vulnerability and risk analysis and participates in a variety of computer security penetration studies.
  • Analyzes and defines security requirements for computer and networking systems, to include mainframes, workstations, and personal computers.
  • Recommends solutions to meet security requirements.
  • Gathers and organizes technical information about an organization’s mission goals and needs and makes recommendations to improve existing security posture.
  • Provides enterprise-wide technical analysis and direction for problem definition, analysis and remediation for complex systems and enclaves.
  • Provides workable recommendations and advice to client executive management on system improvements, optimization, and maintenance in the following areas: Information Systems Architecture, Automation, Telecommunications, Networking, Communication Protocols, Application Software, Electronic Email, VOIP and VTC.
  • Competent to work at the highest level of all phases of information systems auditing.

Requirements

Do you have experience in Web services?, Do you have a Bachelor’s degree?, Necessary Skills and Knowledge:

  • Proven proficiency performing CCRI/ vulnerability assessment/ penetration testing on networks, databases, computer applications and IT frameworks.
  • Knowledge and understanding of DOD security regulations, DISA Security Technical Implementation Guides
  • Understanding of SCAP
  • Knowledge of and proficiency with:
  • VULNERATOR
  • USCYBERCOM CTO Compliance Program
  • Wireless vulnerability assessment
  • Web Services (IIS, Apache, Proxy)
  • Database (SQL Server, Oracle)
  • Email Services (Exchange)
  • Vulnerability Scans (NESSUS, SCCM)
  • Knowledge of Phishing exercises
  • Cloud Security
  • Operational Technology
  • Artificial Intelligence
  • USB Detection
  • Physical Security
  • Familiarity with AUTOCHECKLIST Tool
  • Strong analytical and problem-solving skills for resolving security issues.
  • Strong skills implementing and configuring networks and networks components., * Minimum seven (7) years of IT experience
  • Minimum five (5) years of cybersecurity experience
  • Command Cyber Readiness Inspection certification or equivalent in at least one of the following areas:
  • Nessus Scan Analysis
  • Operating Systems (Windows, Unix)
  • Boundary Defense) Network Policy, Router, Firewall)
  • Internal Defense (L2 Switch, L3 Switch)
  • DNS (Policy, BIND/Windows)
  • HBSS (remote console, AV, ABM, PA HIPS, ePO)
  • Traditional Security (Common, Basic, NCV, SCV)
  • Wireless Communications (BES, Handhelds)
  • Tenable Certified NESSUS Auditory
  • Required to possess a DOD SECRET Clearance and be eligible for an IT-II Non-Critical Sensitive security clearance or Tier 3 (T3) upon assignment.
  • Required to be a DISA Risk Management Executive, Cyber Standards Branch Certified Command
  • Cyber Readiness Inspection (CCRI) Team Lead and have a certification in penetration testing, such as:
  • Licensed Penetration Tester (LPT)
  • Certified Expert Penetration Tester (CEPT)
  • Certified Ethical Hacker (CEH)
  • Global Information Assurance Certification Penetration Tester (GPEN), * Bachelor’s degree in a related field

Benefits & conditions

3.03.0 out of 5 stars Remote $100,000 - $170,000 a year - Full-time, Pulled from the full job description

  • Health insurance
  • 401(k) matching
  • Paid time off
  • Vision insurance
  • Dental insurance, The annual salary range for this position is $100,000 - $170,000. At Goldbelt, we value and reward our team’s dedication and hard work. We provide a competitive base salary commensurate with your qualifications and experience. As an employee, you’ll enjoy a comprehensive benefits package, including medical, dental, and vision insurance, a 401(k) plan with company matching, tax-deferred savings options, supplementary benefits, paid time off, and professional development opportunities.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:26 min

Spear phishing IT administrators with malicious VoIP spoofing

Mauro Verderosa · LIVE

2:03 min

Microsoft integrating native Unix coreutils into Windows environments

Chris Heilmann +2 · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

1:30 min

Integrating automated security and vulnerability scanning

Alexandra Petri · WWC 2023

2:04 min

Defining timestamps and the international standard format

Denny Biasiolli Denny Biasiolli · Europe 2026 Virtual

1:41 min

Reverting destructive Unix commands with the Undo utility

Chris Heilmann +2 · LIVE

Videos

See all

Related articles

See all