Compliance and Continuous Monitoring Engineer - Vulnerability Management (Top Secret Clearance)
ShorePoint Inc
Who we are:
ShorePoint is a fast-growing, industry recognized and award-winning cybersecurity services firm with a focus on high-profile, high-threat, private and public-sector customers who demand experience and proven security models to protect their data. ShorePoint subscribes to a "work hard, play hard" mentality and celebrates individual and company successes. We are passionate about our mission and going above and beyond to deliver for our customers. We are equally passionate about an environment that supports creativity, accountability, diversity, inclusion and a focus on giving back to our community.The Perks: As recognized members of the Cyber Elite, we work together in partnership to defend our nation's critical infrastructure while building meaningful and exciting career development opportunities in a culture tailored to the individuals technical and professional growth. We are committed to the belief that our team members do their best work when they are happy and well cared for. In support of this philosophy, we offer a comprehensive benefits package, including major carriers for health care providers. Highlighted benefits offered: 144 hours of PTO, 11 holidays, 85% of insurance premium covered, 401k, continued education, certifications maintenance and reimbursement and more. Who we're looking for: We are seeking Compliance and Continuous Monitoring Engineer - Vulnerability Management (Top Secret Clearance) with expertise in security assessments, vulnerability management and continuous monitoring. The ideal candidate will support assessment and authorization activities, conduct technical security evaluations and ensure enterprise systems remain compliant with federal cybersecurity standards. The Compliance and Continuous Monitoring Engineer (Vulnerability Management) role will provide hands-on scanning, reporting and compliance support to strengthen the enterprise cybersecurity posture. This is a unique opportunity to shape the growth, development and culture of an exciting and fast-growing company in the cybersecurity market. What you'll be doing:
- Work closely with organizations to ensure full comprehension of security controls; conduct site visits as required.
- Assist with compliance assessments using tailored control matrices; provide expert assessment support.
- Conduct annual reviews of security controls to ensure continued compliance.
- Establish footholds on endpoints to provide day-to-day visibility into enterprise security posture.
- Develop and maintain processes and best practices for evaluating assessment and authorization data.
- Use industry-standard automation tools to review system configurations and security control compliance.
- Conduct NIST control assessments in support of system authorization and continuous monitoring.
- Develop and maintain Security Assessment Reports (SARs) and Risk Assessment Reports (RARs).
- Employ a scan-patch-scan methodology to ensure proper remediation of vulnerabilities.
- Conduct vulnerability scanning on a weekly to bi-weekly basis using industry-standard tools.
- Report scan data to system administrators to support timely remediation.
- Perform false positive and vulnerability analysis to validate findings and prioritize remediation.
- Configure applications to ingest, process and report vulnerability data from assessments and self-assessments.
- Conduct long-term trend analysis to identify changes in enterprise security posture.
- Provide dashboard views and executive-level reports to communicate risk, vulnerability and compliance posture.
- Configure authenticated and unauthenticated scans of web servers (e.g., Apache, IIS) to identify vulnerabilities such as outdated software, misconfigurations, exposed services and SSL/TLS weaknesses.
- Assess both in-house and COTS web applications to identify OWASP Top 10 risks, including SQL injection, cross-site scripting (XSS) and insecure headers.
- Lead technical troubleshooting sessions with administrators and leadership to analyze findings, validate issues and drive remediation efforts.
- Maintain a general understanding of network architecture diagrams to support vulnerability analysis and remediation planning.
- Strong understanding of federal frameworks including NIST 800-53 and 800-53A.
- Knowledge of SANS and OWASP Top 10 vulnerabilities and best practices.
- Ability to synthesize and analyze large volumes of vulnerability and scan data.
- Ability to clearly articulate findings in written and verbal form.
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Mathematics, Engineering or a related field or additional 10+ years of IT experience in lieu of degree.
- One or more of the following certifications: (ISC)2 Certified Information Security Professional (CISSP), GIAC, GCIA or GCIH
- Proven ability to analyze complex requirements and translate them into clear, actionable tasks and processes through critical thinking.
- Ability to perform vulnerability and compliance assessments on all devices identified during enterprise network scans, including operating systems oracle and MySQL databases and web applications.
- Proficiency with enterprise-class scanning tools such as Tenable Nessus and Tenable Security Center, database scanning tools such as AppDetective and DbProtect and web scanning tools such as Web Inspect, with strong knowledge of security best practices and common vulnerabilities for each technology, including SANS and OWASP Top 10.
- Experience performing enterprise-level assessment scanning of networks, databases and web applications.
- Ability to configure and perform host, port and service discoveries on large enterprise networks and identify target operating systems and applications or services from discovery results.
- Proficiency in configuring, troubleshooting and administering Tenable Security Center, Tenable Nessus standalone, AppDetective and Web Inspect.
- Strong understanding of security policies used by intelligence organizations, as well as NIST guidelines (e.g., 800-53 and 800-53A).
- Ability to think critically and creatively and to synthesize and analyze large volumes of scan data.
- Strong written and verbal communication skills with the ability to present findings clearly and comprehensively.
- Applicants must possess an Top-Secret clearance with SCI eligibility and ability to pass a Counterintelligence (CI) polygraph.
- Experience with open-source and commercial testing tools, including Nessus, NMAP, AppDetective, Hailstorm, Guardium and Web Inspect.
- Onsite (Washington, DC.)
Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the Compliance and Continuous Monitoring Engineer - Vulnerability Management (Top Secret Clearance) in Washington DC vacancy
- ...Cybersecurity Engineer... ...Unclassified, Secret, and Top Secret environments... ..., monitoring capabilities, and compliance posture that... ...and access management to cross-domain... ...services, continuous monitoring... ...recurring vulnerability assessments... ...Secret security clearance with the ability...Secret clearanceContract work
$140k - $180k
...Cybersecurity Engineer to... ...cybersecurity, compliance, and risk management activities supporting... ..., manage vulnerabilities, and ensure... .... Ensure continuous endpoint compliance and monitor security... ...management. Clearance Level: Must... ...an active Secret clearance...Secret clearanceCurrently hiring$135k - $165k
...Systems Security Engineer to support... ..., compliance, and risk management activities supporting... ..., manage vulnerabilities, and ensure... ...Performs continuous scanning, patching... ...continuous monitoring of security... ...strategies. Clearance Level: Must... ...an active Secret clearance...Secret clearanceCurrently hiring- ...a Product Manager SME to work... ...Unclassified, Secret, and Top Secret... ...enterprise vulnerability assessment operations... ...the Assured Compliance Assessment... ...to deliver continuous monitoring aligned with... ...administrators, network engineers, and... ...security clearance with the...Secret clearanceContract work
- ...III to support cybersecurity engineering and compliance in a NAVSEA Program Office.... ...involves implementing controls, monitoring security posture, and fixing vulnerabilities across systems. Candidates... ...degree, and an active DoD Secret clearance or the ability to obtain one...Secret clearanceWork at office
$130k - $135k
...PKI/Encryption Engineer to support IT across... ...systems. Manage the full... ...operations, and ensure compliance with federal... ...in audits, vulnerability assessments, and... ...documentation, SOPs, and continuous improvement of... ...Active Top Secret security clearance with SCI eligibility...Secret clearanceFull timePart timeFor contractorsRemote work- ...requires an active Top Secret/SCI clearance with ability to obtain... ...the security and compliance of our client's... ...departments to implement and manage security protocols,... ...assess potential vulnerabilities in the company's... ...risks. * Continuously monitor updates to NISPOM,...Secret clearanceContract workFor contractorsLocal areaFlexible hours
$150k - $165k
...System Security Engineer (ISSE) Team Lead... ...Mandatory Requirements: Top Secret Clearance with SCI... ...cybersecurity and Risk Management Framework (RMF)... ...) efforts, and continuous monitoring in compliance with DoD and Department... ...POA&M tracking, vulnerability remediation, and...Secret clearanceFull timeTemporary workImmediate startRemote workFlexible hours- ...Akima Data Management (ADM) is seeking... ...Governance, Risk, and Compliance (GRC)... ...assessments, vulnerability analyses, and... ...administrators, engineers, and development... ...practices. Support continuous monitoring activities,... ...Active TOP SECRET with SCI clearance (required)....Secret clearanceFull timePart timeFor contractorsWork at officeLocal areaRemote work
- ...Security Monitor 2 page is loaded##... ...:*** Continuously monitor to detect... ...credentials, and clearances for military... ...Identify and report vulnerabilities in physical... ....* Enforce compliance with site... ...CLEARANCE:** Top Secret SCI CI Polygraph... ..., facilities management, and advanced...For contractorsShift work
- ...is hiring a Construction Security Monitor in Arlington, VA. This role... ...controlling site access, and ensuring compliance with security procedures. Candidates must possess an active Top Secret/Sensitive Compartmented Information clearance with a Counterintelligence Polygraph...Secret clearance
$90k - $150k
...discretion of the government. Clearance Needed: Active Top Secret clearance (with... ...transfer, cybersecurity vulnerabilities, supply chain exposure,... ...development, negotiation, and monitoring of national security... ...including those for Data Management, Cloud/Infrastructure, Software...Secret clearanceWork experience placementRemote work- ...Supply Chain Risk Management Tool... ...Unclassified, Secret, and Top Secret environments... ...and continuously improving the... ...Analysis platforms, vulnerability intelligence... ...chain posture by monitoring alerting... ...cybersecurity engineers to validate findings... ...security clearance with the...Secret clearanceContract work
$150k - $170k
...- Identity & Access Management Engineer - Onsite - Active Secret Required Title 1802 -... ...Arlington, VA Security Clearance Requirement Top Secret About Us... ...expertise supervising, monitoring, and troubleshooting... ...implementation gaps, vulnerabilities, and risks, developing...Secret clearanceTemporary workLocal area$68k - $122k
...overseeing and monitoring authorized IT systems... ...and program management. Maximum... .... Conduct continuous assessments of... ...assessments are in compliance with industry auditor... ...security, vulnerabilities, and threats.... ...Active DoD Top Secret clearance with SCI eligibility...Secret clearanceRemote work$62k - $124k
...Washington, DC is seeking a Security Management Lead (SML) – Senior to oversee security program activities and drive compliance across mission-critical operations. The... ...relevant experience and an active DoD Top Secret/SCI clearance. This role offers a salary range of $6...Secret clearanceFor contractors- ...description: TLinked LLC is seeking a Monitoring Engineer to join our team of qualified... ...delivery. Prioritize and manage work using agile methodology... ...US Citizenship and an active SECRET Government Security Clearance with the ability to obtain TOP SECRET if needed. Bachelor’s...Secret clearanceFor contractorsWork at officeRemote workShift workDay shift
- ...seeking a Product Manager SME to work in... ...to Unclassified, Secret, and Top Secret environments... ...responsible for directing continuous monitoring, threat detection,... ...encompasses RMF compliance, vulnerability management, SOC... ...Secret security clearance with the ability to...Secret clearanceContract workShift work
$112.8k - $257k
...Cybersecurity and RMF Engineer, Lead The... ...tools needed to assess vulnerabilities and recommend the best... ...identifying tools. You’ll manage the research of... ...packages, POA&Ms, continuous monitoring, or secure cloud 5+... ...suitable controls Secret clearance HS diploma or GED...Secret clearanceFull timePart timeLocal area- ...) SECURITY & COMPLIANCE ENGINEERING (SCE) POSITION... ...requires continuous evaluation of... ...: Continuous monitoring of system compliance... ...Experience: Vulnerability scanning... ...Information Security Manager (CISM)... ...certifications Clearance Level Minimum of active Secret Clearance and...Secret clearanceRemote work
- ...Principal Network Systems Engineer) Saliense is a growing Management and Technology... ...possess an active Secret clearance to be considered... ...to obtain a Top Secret clearance.... ...workstation and server vulnerability remediation and patch... ...Systems. Monitors, performance tunes...Secret clearanceWork at officeLocal areaImmediate start3 days per week
- A prominent engineering and services firm is seeking an IT Strategy... ...on strategic planning and continuous process improvement. The ideal candidate needs a Top Secret security clearance and at least five years of... ..., performance monitoring, and aligning strategic objectives...Secret clearance
- ...Cloud Security Engineer to work in... ...Unclassified, Secret, and Top Secret environments... ...on patch management, continuous monitoring, and incident... ...authorization compliance, and operational... ...by operating vulnerability scanning workflows... ...security clearance with the ability...Secret clearanceContract work
- ...networking performance and compliance and protect... ...Security Project Engineering and Knowledge Management. Key... ...identify and exploit vulnerabilities in systems and applications... ...confirmed. Security Clearance The successful... ...active U.S. Government Top Secret Security Clearance...Secret clearanceFor contractorsLocal area
- ...Seeking a Senior Continuity professional to support and modernize... ...enhancing COOP plans, ensuring compliance with federal continuity... ...in continuity and emergency management working groups Deploy to... ...multiple priorities Active Top-Secret clearance (SCI eligible with recent read...Secret clearanceWork at office
$80k - $128k
...Threat Analysis Clearance: Secret Peraton is... ...seeking a Risk and Vulnerability Analyst.... ...role ensures continuous visibility, compliance, and timely remediation... ...vulnerability monitoring and risk... ...SOC, IR, and engineering teams. Ensure... ...vulnerability management, or risk analysis...Secret clearanceContract workShift work- ...skilled Cybersecurity Compliance Lead to support our... ...compliance, risk management frameworks, and Department... ...governance and continuous auditing. Key Responsibilities... ...: Active Top Secret clearance and U.S. citizenship... ...assessments, and compliance monitoring. Ability to...Secret clearanceLocal area
$82k - $138k
...Link is quality and compliance-focused, under our guiding... ...is seeking a Vulnerability Remediation and Patching... ...have an active DoD Top Secret Clearance Non-remote (... ...for overseeing the management of patch deployment... ...response times. Monitor patch release cycles...Secret clearanceHourly payContract workTemporary workWork experience placementRemote workRelocation package- ...contractor specializing in Management Consulting, Information... ...confidence that we are continually measuring and improving... ...satisfaction. Policy and Compliance Analyst DISA Active Secret Clearance Required. Job Type:... ...must possess an active Top Secret security clearance...Secret clearanceFull timeContract workTemporary workFor contractors
- ...cybersecurity firm is seeking a Public Key Infrastructure Engineer to enhance identity management and secure clients’ data. The role involves... ...cybersecurity experience, particularly in PKI, and must hold a Top Secret clearance. Support for obtaining Security+ certification is...Secret clearance
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Compliance and Continuous Monitoring Engineer - Vulnerability Management (Top Secret Clearance). Be the first to apply!
Related searches
- computer lab monitor Washington DC
- program monitor Washington DC
- community monitor Washington DC
- clinical research monitor Washington DC
- security monitor Washington DC
- monitor tech Washington DC
- patient monitor Washington DC
- pool monitor Washington DC
- cardiac monitor tech Washington DC
- quality assurance monitor Washington DC

