Padmi

Data/Information Architect

United States · HybridPosted 4 months ago
CybersecurityUnspecified
Apply at System Soft Technologies

Opens the source posting on jobsapi.ceipal.com

Source description

About the role

View original

Data/Information Architect - Consultant (Vulnerability Management Systems Analyst - Consultant)

Interview Process: One Round of Virtual Interviews, potential for second round of in-person interviews

Duration of the Contract: 12 Months

Possibility for Extension: Yes

Work Location: Role is 100% remote

Candidate location: No SC Residency required. Open to nationwide candidates.

Additional Information: Preference will be given to candidates that are local to SC and are able to come onsite for project needs.

Scope of the project:

The position will work as a Consulting Vulnerability Management Systems Analyst within the

Division of Information Security and will assist in maturing the statewide vulnerability

management program. This role is responsible for administration of vulnerability

management platforms, agency coordination, risk documentation, and training. The

consultant will help ensure state agencies manage and reduce information security risks

through effective patching and remediation. The engagement is expected to be needed for 12

months with the possibility of extension

Daily Duties / Responsibilities:

PREFERENCE WILL BE GIVEN TO A CANDIDATE WHO CAN WORK ONSITE OVER HYBRID AND

OVER FULL-TIME REMOTE (ON-SITE AS NEEDED).

• Assist with the statewide vulnerability management program for DIS.

• Administer vulnerability management platforms, configure policies, reporting, and

services to support agencies.

• Analyze vulnerabilities, prioritize remediation, and document residual risks for agency

systems.

• Provide training and guidance to agencies on vulnerability management practices.

• Support procurement, configuration, and utilization of vulnerability management

tools.

• Develop POA&Ms with DIS staff and agencies to track remediation efforts against

SLOs.

• Perform system criticality validation reviews with agencies to align severity levels and

risk exposure.

• Provide regular reporting and communication to stakeholders regarding

vulnerabilities and risks

Required Skills (rank in order of

Importance):

• 5+ Years of Experience with

vulnerability management tools

(Qualys, Tenable, Rapid7).

• 5+ Years of Experience with

architecting, deploying, configuring,

and operating vulnerability

management platforms.

• 5+ Years of Experience with Windows

and Linux operating systems.

• 5+ Years of Experience with

interpreting and applying CVSS

ratings, POA&M tracking, and risk

mitigation strategies.

Preferred Skills (rank in order of

Importance):

• Familiarity with standards such as PCI

DSS, NIST, ITIL, CVSS, and MITRE

ATT&CK.

• Experience in application security

and automation/scripting (Python,

PowerShell, Bash).

• Prior experience leading statewide or

enterprise-wide vulnerability

programs.

• Candidate is local to Columbia, SC or

surrounding city in South Carolina

Required education/certifications:

• Bachelor's degree in information

technology or information security

related field

• Eight years of relevant work

experience may be substituted in lieu

of education OR Five years of

experience in supporting enterprise

IT environments and/or system

Deployments

Preferred Education/Certifications:

• CISSP, CISA, CISO or equivalent

advanced security certification.

• Additional relevant certifications

(e.g., CEH, OSCP, GPEN

One address, no account. We’ll tell you when matching roles go live.

More at System Soft Technologies

Related open roles

View all roles