Information Security Engineer – Threat and Vulnerability Management
Job in
Washington, District of Columbia, 20022, USA
Listed on 2026-09-15
Listing for:
Jobtailor
Full Time
position Listed on 2026-09-15
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
- Conduct ongoing vulnerability assessments across servers, workstations, network devices, cloud infrastructure, Microsoft Azure, and Microsoft 365 environments
- Use the firm’s vulnerability scanning platform to identify security weaknesses
- Prioritize findings using exploitability, threat intelligence, asset criticality, and exposure
- Present remediation recommendations to system owners and the Director
- Maintain the firm’s threat profile, tracking threat actors, campaigns, and tactics targeting law firms, professional services, clients, and relevant industries
- Monitor threat intelligence feeds, information-sharing communities, and dark web sources for indicators of compromise, credential exposure, and mentions of the firm, its people, or clients
- Translate threat intelligence into action by prioritizing actively exploited vulnerabilities and recommending new detections
- Brief the Director and peers on emerging threats
- Execute prompt injection and cross-client data isolation test cases as directed
- Bring emerging AI attack techniques into the testing program
- Complete special projects and other assigned duties
- Bachelor’s degree in cybersecurity, information systems, or a related field, or equivalent years of experience
- Four years or more of relevant information security experience
- A Master’s degree in cybersecurity or a related field may be considered in lieu of one year of experience
- Hands-on experience with vulnerability management or threat and vulnerability assessment, including scanning, analysis, and risk-based prioritization of findings
- Experience with vulnerability scanning platforms such as Tenable, Rapid7, Qualys, or equivalent
- Working knowledge of application, operating system, and network security fundamentals, including common monitoring tools
- Experience with incident response, digital forensics, and cyber threat intelligence in an operational environment, including analysis of threat actor tactics and indicators of compromise
- Thorough understanding of current security principles, techniques, and protocols
- Ability to effectively communicate information security issues, risks, and recommendations to both technical and non-technical peers and management, including through well-written reports
- Ability to problem-solve
- Excellent interpersonal, verbal and written communication skills, including the ability to communicate effectively in a virtual environment
- Ability to work calmly and effectively in a high-pressure, deadline-oriented environment
- Ability to use good judgment, take initiative, and consult others as appropriate
- Willingness to be flexible with time and adjust to a changing work environment
- Ability to build and maintain positive relationships while maintaining a client service orientation
- Ability to use sound judgment and discretion with highly confidential information
- Ability to take direction and accept supervision
- Ability to work independently, organize and prioritize work accurately, be detail-oriented, and recognize urgency
- Ability to work effectively in a team-oriented collaborative environment
Demonstrates expertise in vulnerability management, threat assessment, and incident response, with a strong ability to communicate security issues and recommendations effectively. Proficient in utilizing vulnerability scanning platforms and analyzing threat intelligence to enhance organizational security posture.
Highest-signal resume keywords- Vulnerability Management
- Threat Assessment
- Incident Response
- Vulnerability Scanning Platforms
- Cyber Threat Intelligence
- Vulnerability Assessment
- Threat Intelligence Analysis
- Risk-Based Prioritization
- Incident Response
- Digital Forensics
- Security Principles
- Application Security
- Network Security
- Operating System Security
- Threat Actor Tactics
- Effective Communication
- Problem-Solving
- Interpersonal Skills
- Team Collaboration
- Client Service Orientation
- Bachelor’s Degree in Cybersecurity
- Master’s Degree in Cybersecurity
- Vulnerability Scanning
- Threat Profile
- Indicators of Compromise
- High-Pressure Environment
- Confidential Information
- Microsoft Azure
- Microsoft 365
- Tenable
- Rapid7
- Qualys
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×