Sr IT Security/Vulnerability Management Specialist

AAC Inc
Liberty, NC, United States
8 days ago
Apply on www.wayup.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Excel Microsoft Windows Accounting Systems Amazon Web Services Software as a Service Cloud Computing Cyber Security Information Systems Linux Monitoring of Systems Information Technology Operations Networking Hardware
+16 more
JD Edwards EnterpriseOne Python (Programming Language) Microsoft Office Oracle (Applications) Windows PowerShell SAP (Applications) Security Information and Event Management Software Engineering Data Streaming Software Vulnerability Management Information Technology Patch Management Nessus Checkmarx Api Management Vulnerability Analysis

Job description

AAC is seeking Senior Security Analyst focusing on Vulnerability Management to join our security compliance team. In this role, you will work closely with the Information Systems Security Officer (ISSO) and play a critical part in safeguarding organization’s IT infrastructure. You will be part of a broader IT program that provides end-to-end support-including help desk, systems, network, incident response and security services-ensuring the availability, integrity, and confidentiality of mission-critical systems. Responsibilities include, but are not limited to: · Lead the agency’s vulnerability management lifecycle using Tenable.sc, Tenable.io, Nessus Manager, and Nessus scanners (on-prem and cloud). · Analyze, prioritize, and track remediation of vulnerabilities in coordination with IT operations and system owners. · Maintain scan schedules, asset groups, scan policies dashboards, and reports tailored to agency infrastructure and communicate risk posture and remediation progress to relevant infrastructure, application, and cloud teams to remediate vulnerabilities. · Define the scanner and security center architecture, refine data flows and synchronizations, tune scanning configurations to minimize false positives and ensure the best coverage. · Develop and maintain documentation for system setup, operation, vulnerability management processes, exceptions, and remediation tracking. · Support implementation of security projects that require compliance with relevant government policies or standards. · Act as SME for vulnerability management tools and processes. · Ensure systems and practices comply with FISMA and FedRAMP related Security Assessment and Authorization (SA&A) and compliance for the organization’s IT programs. · Assist in coordination, implementation, communication, and enforcement of the organization’s IT security policies. · Support incident response. The position requires on-site presence 3 to 5 days per week. The on-site requirements are subject to change based on the needs and requirements of the organization., Our customer is a utility in Arizona looking to add 2,000 MW of pumped storage energy to its overall capacity to meet growing demand on its network. We are building a high-performing joint venture team to deliver this complex EPC heavy civil project and are looking for motivated, hands-on, collaborative innovators, doers, and problem solvers. The project will involve the use of a lower reservoir and the creation of an upper reservoir through the construction of new dams. The reservoirs will be connected by underground waterways tunneled into the rock, channeling water down the approximately 1,200-foot drop between the two reservoirs. The project scope includes significant access road development, construction of the upper reservoir with dams and an overflow spillway, underground tunnel waterways in challenging geological and hydrogeological conditions, upper and lower reservoir inlet/outlet structures, hydromechanical equipment, an underground powerhouse, and surface site facilities and buildings. This is your opportunity to be part of a truly historic project. The Project Billing Specialist will play a critical role in supporting project financial operations by ensuring accurate, timely, and compliant billing throughout the life of the project. This position works closely with Project Controls, Accounting, Operations, Procurement, and the client to prepare invoices, monitor contract billing requirements, reconcile project costs, and support financial reporting., + Prepare and submit client invoices in accordance with contract terms, billing schedules, and project milestones.

  • Review and validate project costs, labor, equipment, subcontractor, and material charges prior to invoicing.
  • Coordinate with Project Managers, Project Controls, and Accounting to ensure billing accuracy and completeness.
  • Track contract values, change orders, retainage, and billing status throughout the project lifecycle.
  • Monitor accounts receivable and assist with collection efforts by resolving billing questions or discrepancies.
  • Maintain detailed billing documentation to support audits and client inquiries.
  • Reconcile project costs with billing records and identify discrepancies for resolution.
  • Support monthly financial close by preparing billing reports, revenue updates, and project financial summaries.
  • Assist with forecasting project revenue and cash flow based on billing schedules.
  • Ensure compliance with company policies, contract requirements, and accounting standards.
  • Maintain organized electronic and hard-copy project billing records.
  • Participate in process improvement initiatives to enhance billing efficiency and accuracy.
  • Collaborate with cross-functional teams to ensure timely financial reporting and project success.
  • Perform other duties as assigned.

Requirements

· Requires bachelor’s degree in computer science, cyber security, engineering, or a related technical field. Additional experience and relevant certifications may be considered in leu of a degree. · 5-7 years of progressive and related experience in IT security with at least 3 years in vulnerability management. · Expert knowledge of IT security vulnerabilities and risk assessments with the ability to explain the risks associated with them to executives, program, and technology staff. · Expert knowledge of Tenable.sc (on-prem) and Tenable.io (cloud). · Strong knowledge of vulnerability management lifecycle, patch management, and risk scoring (e.g., CVSS2). · Familiarity with cloud platforms (AWS and GCP) and hybrid environments. · Understanding of Windows, Linux/Unix, and network devices security hardening. · Ability to work with program staff, executives, security application vendors and technology staff to achieve IT security goals and objectives. · Experience developing and maintaining Security Assessment and Authorization (SA&A) documentation for large IT systems for the Federal Government. · Excellent working experience in applying FISMA, and FedRAMP processes and policies to information systems. · Experience with Checkmarx and Checkmarx One (SaaS). Migration experience to Checkmarx One is desirable. · Strong communication skills (both technical and non-technical) and ability to collaborate across IT, security, and business units. · Ability to effectively communicate orally and in writing. · Experience supporting a nationwide mid-to large Federal agency enterprise is a plus. · CISSP certification required (ability to obtain within 6 months of start). · Must obtain an agency public trust suitability determination prior to start date. Desired Qualifications: · Experience with scripting and automation (e.g., Python, PowerShell) to automate scanning tasks, reporting, and API integrations; administration and operation of security scanning and vulnerability management platforms such as Nessus. · Deep expertise with SIEM platforms and integration of vulnerability data into enterprise monitoring. · Understanding of the Secure Software Development Life Cycle. · Master’s degree or additional security or cloud certifications (e.g., CISM)., + Associate’s or Bachelor’s degree in Accounting, Finance, Business Administration, Construction Management, or a related field preferred.

  • Minimum of 3 years of billing, project accounting, or construction accounting experience , preferably on large EPC, infrastructure, or heavy civil construction projects.
  • Experience with progress billing, cost-plus contracts, unit-price contracts, and change order billing is preferred.
  • Strong understanding of project accounting principles and contract billing requirements.
  • Proficiency in Microsoft Excel and Microsoft Office Suite.
  • Experience with ERP/accounting systems such as Oracle, SAP, JD Edwards, Viewpoint, CMiC, or similar systems preferred.
  • Excellent organizational skills with strong attention to detail.
  • Ability to prioritize multiple deadlines in a fast-paced project environment.
  • Strong analytical and problem-solving skills.
  • Excellent written and verbal communication skills.
  • Ability to work collaboratively with project teams, clients, and finance personnel., + Experience supporting large-scale heavy civil, tunneling, mining, hydroelectric, or infrastructure construction projects.
  • Knowledge of joint venture accounting and billing practices.
  • Experience working with owner invoicing requirements for utility or public infrastructure projects.
  • Familiarity with earned value management (EVM) and project controls concepts.

Physical Requirements

  • Ability to sit for extended periods while working on a computer.
  • Occasionally lift up to 20 pounds.
  • Ability to visit project sites as needed.
  • Ability to travel occasionally. +

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.wayup.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

3:46 min

Navigating a career in cloud transformation consulting

Piet Van Dongen · LIVE

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

8:22 min

Simulating a Linux terminal and running Spring Boot

Jakov Semenski · LIVE

Videos

See all

Related articles

See all