Infrastructure Scanning Analyst

cFocus Software Incorporated
United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Cyber Security Databases Software Vulnerability Management Information Technology Vulnerability Analysis

Job description

cFocus Software seeks a Infrastructure Scanning Analyst to join our program supporting the National Institutes of Health (NIH). This position is fully remote. This position requires a Public Trust or the ability to obtain a public trust clearance., * Perform credentialed host, network, application, and database vulnerability scans across NIH/OD-managed systems.

  • Schedule and execute recurring vulnerability assessments in accordance with Government-defined scanning frequencies.
  • Perform specialized vulnerability assessments for High Value Assets (HVAs) and other designated systems.
  • Validate scan coverage to ensure all approved assets are included within the enterprise vulnerability management program.
  • Maintain scan schedules while minimizing operational impact.
  • Operate, administer, and maintain the NIH/OD vulnerability scanning infrastructure.
  • Configure, optimize, and maintain enterprise vulnerability scanning tools and supporting services.
  • Ensure scanning infrastructure provides comprehensive enterprise visibility and situational awareness.
  • Support integration between NIH/OD vulnerability management tools and existing enterprise vulnerability management capabilities.
  • Maintain operational readiness of vulnerability scanning platforms.

Requirements

  • Public Trust Clearance
  • B.S. Computer Science, Information Technology, or a related field
  • 5+ years of experience performing enterprise vulnerability assessments.
  • Experience operating enterprise vulnerability scanning platforms.
  • Experience performing credentialed host and network vulnerability assessments.
  • Experience supporting Federal cybersecurity programs or large enterprise environments.
  • Experience interpreting vulnerability data and developing remediation guidance.

Benefits & conditions

Invitation for Job Applicants to Self-Identify as a U.S. Veteran

  • A ā€œdisabled veteranā€ is one of the following:
  • a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or
  • a person who was discharged or released from active duty because of a service-connected disability.
  • A ā€œrecently separated veteranā€ means any veteran during the three-year period beginning on the date of such veteran’s discharge or release from active duty in the U.S. military, ground, naval, or air service.
  • An ā€œactive duty wartime or campaign badge veteranā€ means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.
  • An ā€œArmed forces service medal veteranā€ means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on cfocussoftware.applytojob.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg Ā· LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman Ā· WWC 2022

42 sec

Energy forecasts and resource demands of information technology

Marjolein Pordon Ā· LIVE

1:30 min

Integrating automated security and vulnerability scanning

Alexandra Petri Ā· WWC 2023

2:46 min

Missing equipment retrieval processes for departing employees

Jasmin Azemović Jasmin Azemović Ā· WWC Europe 2026

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger Ā· LIVE

Videos

See all

Related articles

See all