Vulnerability Management/Cloud Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+26 more
Job description
As an Associate Systems Engineer Information Assurance team, specializing in vulnerability management and cloud security, your role involves a comprehensive understanding of vulnerability management program development, cloud security tooling, and best practices. You will have the ability to dive deep into any technical challenges or concerns, making informed decisions to safeguard system uptime and minimize disruptive outage events. You will collaborate with cross-functional teams to define architectural decisions and platform integrations for new and existing initiatives, aligning them with best practices around vulnerability management and cloud security. This role will focus on managing the backend infrastructure of the vulnerability management program and helping develop the maturity of the overall program. There will be a preference for the candidate to have software development experience. Interested in protecting CISA’s critical transportation sector? Bring your cyber defense skills and join the shield!
Administer and support Windows, Linux, network, or vulnerability management-based security toolsets and processes such as hardened configurations, cloud security, and privilege management Identify, assess and prioritize remediation activities for security vulnerabilities Create and implement cloud security best practices Product administration and support for vulnerability management scanning and orchestration tooling Discover, investigate and remediate security anomalies in the environment Correlate and analyze large amounts of data from multiple systems to identify user behavior patterns Member of Incident Response Support Team Identify and evaluate: 1) business and technology risks, 2) internal controls which mitigate risks, and 3) methods and technologies to improve the internal control environment Provide guidance and support for emerging security initiatives Consult with other business and Tech teams on Cyber Security best practices and secure system implementations
Requirements
The final salary or hourly wage, as applicable, paid to each candidate/applicant for this position is ultimately dependent on a variety of factors, including, but not limited to, the candidate’s/applicant’s qualifications, skills, and level of experience as well as the geographical location of the position.
Applicants must be legally authorized to work in the United States. Visa sponsorship not available., A Bachelor or Master’s Degree in Cyber Security, Computer Science, Computer Engineering, or related field. A minimum of 7 years recent Information Assurance experience may be taken into account in lieu of a degree. 5+ years recent experience in administering or securing Windows, Linux, Network or Cloud based systems 5+ years recent experience administering/supporting Cyber Security tools or controls in a complex enterprise environment 2+ years recent experience with scripting (e.g. python, PowerShell, bash, perl, regular expressions) Understanding of vulnerability management tooling and/or processes Excellent written and dynamic verbal communication skills Demonstrated understanding of control objectives, cyber threats and vulnerabilities Must be flexible and able to handle stressful situations in a professional manner Demonstrated ability to work under minimal supervision High degree of self-motivation, commitment and integrity Ability to work well with others and as a member of a team 6 year(s) experience in Cybersecurity or a Bachelor/Master’s Degree with an emphasis in Cybersecurity Recent experience implementing and administering security technologies for a large enterprise Experience reviewing raw log files, data correlation, and analysis (i.e. firewalls, network flow, IDS, system logs, SIEM) Working knowledge of configuration management, TCP/IP, simple DNS, SSH, exploits and malware Proficiency with software engineering best practices such as version control, automated testing, code review, and continuous delivery Understanding of CVSS v3.x, EPSS, KEV, CWE, CPE/CVE, NVD flows and common deduping pitfalls Experience building risk-based prioritization models that combine severity + exploitability + asset criticality + exposure Proficiency with relational databases Ability to design vulnerability management orchestration that creates tickets, routes to owners, bundles duplicates, escalates breaches, pauses on maintenance windows, and posts to chat channels Experience identifying vulnerabilities or areas of weakness which pose a threat and developing security controls to detect or prevent exploitation Demonstrated understanding of Tech Policy and Compliance frameworks Deep knowledge of at least one major cloud platform (AWS, Azure, or Google Cloud Platform)
About the company
This position is a contract/temporary role where Hays offers you the opportunity to enroll in full medical benefits, dental benefits, vision benefits, 401K and Life Insurance ($20,000 benefit).
Why Hays?
You will be working with a professional recruiter who has intimate knowledge of the industry and market trends. Your Hays recruiter will lead you through a thorough screening process in order to understand your skills, experience, needs, and drivers. You will also get support on resume writing, interview tips, and career planning, so when there’s a position you really want, you’re fully prepared to get it.
Nervous about an upcoming interview? Unsure how to write a new resume?
Visit the Hays Career Advice section to learn top tips to help you stand out from the crowd when job hunting.
Hays is committed to building a thriving culture of diversity that embraces people with different backgrounds, perspectives, and experiences. We believe that the more inclusive we are, the better we serve our candidates, clients, and employees. We are an equal employment opportunity employer, and we comply with all applicable laws prohibiting discrimination based on race, color, creed, sex (including pregnancy, sexual orientation, or gender identity), age, national origin or ancestry, physical or mental disability, veteran status, marital status, genetic information, HIV-positive status, as well as any other characteristic protected by federal, state, or local law. One of Hays’ guiding principles is ‘do the right thing’. We also believe that actions speak louder than words. In that regard, we train our staff on ensuring inclusivity throughout the entire recruitment process and counsel our clients on these principles. If you have any questions about Hays or any of our processes, please contact us.
In accordance with applicable federal, state, and local law protecting qualified individuals with known disabilities, Hays will attempt to reasonably accommodate those individuals unless doing so would create an undue hardship on the company. Any qualified applicant or consultant with a disability who requires an accommodation in order to perform the essential functions of the job should call or text .
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
What Are The Top Skills Required For Azure Developers?
Walking Into The Era of Supply Chain Risks
Best Paying Jobs in Technology