Cyber Systems Engineer IV – Vulnerability Management
Listed on 2026-10-08
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Systems Engineer
Program Description
The program provides Systems Engineering and Technical Assistance (SETA) support in the areas of Cyber Security and Management to improve the Information Assurance (IA) posture of a National customer. The contracts support functions are: IA Management, Federal Information Security Management Act (FISMA) coordination and reporting, Risk Management Framework (RMF) application, IA compliance measurements and metrics, Assessment and Authorization (A&A), Vulnerability Management, and Cyber Defense support.
ResponsibilitiesProgram Description
The program provides Systems Engineering and Technical Assistance (SETA) support in the areas of Cyber Security and Management to improve the Information Assurance (IA) posture of a National customer. The contracts support functions are: IA Management, Federal Information Security Management Act (FISMA) coordination and reporting, Risk Management Framework (RMF) application, IA compliance measurements and metrics, Assessment and Authorization (A&A), Vulnerability Management, and Cyber Defense support.
PositionDescription
The Vulnerability Management Cyber SE provides support to the customer in the area of Cyber Security. Daily tasks include, but are not limited to:
- Support the IT vulnerability management lifecycle.
- Support government activities and reporting to appropriate IC and DoD authorities (i.e., USCYBERCOM, IC-SCC)
- Assess and manage the implementation of identified corrections associated with high visibility technical vulnerabilities
- Using several database sources, collect the necessary metrics to develop and deliver a periodic Cyber Vulnerabilities Metrics Report
- Develop and deliver asset vulnerability views for categories such as mission, cross domain, and location, as required by the customer
- Develop cyber vulnerability analysis for known vulnerabilities, as well as cyber-related metrics and reporting deliverables
- Document and deliver awareness notices related to cyber vulnerabilities
- Document and deliver Government activities and reporting related to tasking and directions received from external stakeholders (i.e., USCYBERCOM, IC-SCC).
- Coordinate and prepare Inspector General (IG) FISMA closure requests from field reps and program Information System Security Engineers (ISSEs)
- Coordinate with RMF stakeholders on closure Body of Evidence (BoE) for Enterprise Vulnerability and Remediation (EVAR) tracked findings
- Prepare and update slides for weekly and monthly meetings
- Research trending vulnerabilities being reported through enterprise security tools
- Support the automation of current activities with system engineers and software developers from other groups and offices
- Ensure divisional processes are accurately documented and kept up to date
- Maintain representation of divisional activities and metrics via Confluence on a weekly basis
- Integrate analysis with intelligence and cyber operations functions
- Assist with the development of new processes and deliverables to support enterprise vulnerability analysis designed to inform the enterprise of existing vulnerabilities and help prioritize remediation efforts
- BS with 8-10 years of experience, MS with 6-8 years of experience, Ph.D. with 3-5 years of experience
- Must possess and be able to maintain a TS/SCI with Poly
- Able to support customer’s core hours ; Mon – Fri)
- A Cyber Certification (DoD 8570/8140)
- Familiarity with the IT vulnerability management lifecycle.
- Excellent communications skills – Verbal and Non-Verbal
- Strong analytic and risk management skills
- Strong attention to detail and organizational skills
- Excellent communications skills
- Self-starter requiring limited direction and supervision
- Experience implementing RMF Process and NIST 800-53 technical controls, as well as…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).