Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Compliance and Continuous Monitoring Engineer - Vulnerability Management (Top Secret Clearance)

ShorePoint Inc

Who we are:

ShorePoint is a fast-growing, industry recognized and award-winning cybersecurity services firm with a focus on high-profile, high-threat, private and public-sector customers who demand experience and proven security models to protect their data. ShorePoint subscribes to a "work hard, play hard" mentality and celebrates individual and company successes. We are passionate about our mission and going above and beyond to deliver for our customers. We are equally passionate about an environment that supports creativity, accountability, diversity, inclusion and a focus on giving back to our community.


The Perks:

As recognized members of the Cyber Elite, we work together in partnership to defend our nation's critical infrastructure while building meaningful and exciting career development opportunities in a culture tailored to the individuals technical and professional growth. We are committed to the belief that our team members do their best work when they are happy and well cared for. In support of this philosophy, we offer a comprehensive benefits package, including major carriers for health care providers. Highlighted benefits offered: 144 hours of PTO, 11 holidays, 85% of insurance premium covered, 401k, continued education, certifications maintenance and reimbursement and more.

Who we're looking for:

We are seeking Compliance and Continuous Monitoring Engineer - Vulnerability Management (Top Secret Clearance) with expertise in security assessments, vulnerability management and continuous monitoring. The ideal candidate will support assessment and authorization activities, conduct technical security evaluations and ensure enterprise systems remain compliant with federal cybersecurity standards. The Compliance and Continuous Monitoring Engineer (Vulnerability Management) role will provide hands-on scanning, reporting and compliance support to strengthen the enterprise cybersecurity posture. This is a unique opportunity to shape the growth, development and culture of an exciting and fast-growing company in the cybersecurity market.

What you'll be doing:

  • Work closely with organizations to ensure full comprehension of security controls; conduct site visits as required.
  • Assist with compliance assessments using tailored control matrices; provide expert assessment support.
  • Conduct annual reviews of security controls to ensure continued compliance.
  • Establish footholds on endpoints to provide day-to-day visibility into enterprise security posture.
  • Develop and maintain processes and best practices for evaluating assessment and authorization data.
  • Use industry-standard automation tools to review system configurations and security control compliance.
  • Conduct NIST control assessments in support of system authorization and continuous monitoring.
  • Develop and maintain Security Assessment Reports (SARs) and Risk Assessment Reports (RARs).
  • Employ a scan-patch-scan methodology to ensure proper remediation of vulnerabilities.
  • Conduct vulnerability scanning on a weekly to bi-weekly basis using industry-standard tools.
  • Report scan data to system administrators to support timely remediation.
  • Perform false positive and vulnerability analysis to validate findings and prioritize remediation.
  • Configure applications to ingest, process and report vulnerability data from assessments and self-assessments.
  • Conduct long-term trend analysis to identify changes in enterprise security posture.
  • Provide dashboard views and executive-level reports to communicate risk, vulnerability and compliance posture.
  • Configure authenticated and unauthenticated scans of web servers (e.g., Apache, IIS) to identify vulnerabilities such as outdated software, misconfigurations, exposed services and SSL/TLS weaknesses.
  • Assess both in-house and COTS web applications to identify OWASP Top 10 risks, including SQL injection, cross-site scripting (XSS) and insecure headers.
  • Lead technical troubleshooting sessions with administrators and leadership to analyze findings, validate issues and drive remediation efforts.
  • Maintain a general understanding of network architecture diagrams to support vulnerability analysis and remediation planning.
What you need to know:
  • Strong understanding of federal frameworks including NIST 800-53 and 800-53A.
  • Knowledge of SANS and OWASP Top 10 vulnerabilities and best practices.
  • Ability to synthesize and analyze large volumes of vulnerability and scan data.
  • Ability to clearly articulate findings in written and verbal form.
Must have's:
  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Mathematics, Engineering or a related field or additional 10+ years of IT experience in lieu of degree.
  • One or more of the following certifications: (ISC)2 Certified Information Security Professional (CISSP), GIAC, GCIA or GCIH
  • Proven ability to analyze complex requirements and translate them into clear, actionable tasks and processes through critical thinking.
  • Ability to perform vulnerability and compliance assessments on all devices identified during enterprise network scans, including operating systems oracle and MySQL databases and web applications.
  • Proficiency with enterprise-class scanning tools such as Tenable Nessus and Tenable Security Center, database scanning tools such as AppDetective and DbProtect and web scanning tools such as Web Inspect, with strong knowledge of security best practices and common vulnerabilities for each technology, including SANS and OWASP Top 10.
  • Experience performing enterprise-level assessment scanning of networks, databases and web applications.
  • Ability to configure and perform host, port and service discoveries on large enterprise networks and identify target operating systems and applications or services from discovery results.
  • Proficiency in configuring, troubleshooting and administering Tenable Security Center, Tenable Nessus standalone, AppDetective and Web Inspect.
  • Strong understanding of security policies used by intelligence organizations, as well as NIST guidelines (e.g., 800-53 and 800-53A).
  • Ability to think critically and creatively and to synthesize and analyze large volumes of scan data.
  • Strong written and verbal communication skills with the ability to present findings clearly and comprehensively.
  • Applicants must possess an Top-Secret clearance with SCI eligibility and ability to pass a Counterintelligence (CI) polygraph.
Beneficial to have:
  • Experience with open-source and commercial testing tools, including Nessus, NMAP, AppDetective, Hailstorm, Guardium and Web Inspect.
Where it's done:
  • Onsite (Washington, DC.)
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Compliance and Continuous Monitoring Engineer - Vulnerability Management (Top Secret Clearance) in Washington DC vacancy
  •  ...appliances employed to maintain compliance with all regulatory...  ...limited to extensive engineering of Windows and Linux operating...  ..., IT infrastructure management, resource monitoring, and alerting....  ...CISM, CISSP. ctive Top-Secret clearance. Someone with 5-7 years... 
    Secret clearance
    Relocation package

    Macpower Digital Assets Edge

    Washington DC
    4 days ago
  •  ...Senior Level Vulnerability Patch Management Engineer The Alaka`ina Foundation...  ...to maintain compliance with all regulatory...  ...management, resource monitoring and alerting....  ...Required Citizenship and Clearance: U.S....  ...Must have an active Top Secret-SCI clearance.... 
    Secret clearance
    Full time

    Alakaina Family of Companies

    Arlington, VA
    1 day ago
  •  ...a Product Manager SME to work...  ...Unclassified, Secret, and Top Secret...  ...enterprise vulnerability assessment operations...  ...the Assured Compliance Assessment...  ...to deliver continuous monitoring aligned with...  ...administrators, network engineers, and...  ...security clearance with the... 
    Secret clearance
    Contract work

    ECS Limited

    Falls Church, VA
    4 days ago
  • $135k - $216k

     ...Systems Security Engineer Peraton is seeking...  ..., and risk management strategies are clearly...  ...risk appetite, and compliance requirements. Oversee...  ...Direct ongoing monitoring and continuous assessment...  ...required. ~ Active Top Secret security clearance required. ~ The... 
    Secret clearance
    Contract work
    For contractors
    Work at office
    Shift work

    Peraton

    Washington DC
    3 days ago
  • $107.9k - $195.05k

     ...experienced Senior Continuous Monitoring Analyst to...  ...partners, engineers, and other industry...  ...posture, and compliance with RMF...  ...systems. Analyze vulnerability and security...  ...~ Active Top Secret (TS) clearance with SCI eligibility...  ...vulnerability management activities.... 
    Secret clearance
    Local area
    Immediate start

    Leidos

    Alexandria, VA
    1 day ago
  •  ...development for cloud systems and ensuring compliance with NIST 800-53 across AWS and...  ...experience, along with an active Top Secret clearance. Responsibilities include documentation maintenance, vulnerability tracking, and continuous monitoring support. #J-18808-Ljbffr CGI... 
    Secret clearance

    CGI Njoyn

    Washington DC
    3 days ago
  •  ...III to support cybersecurity engineering and compliance in a NAVSEA Program Office....  ...involves implementing controls, monitoring security posture, and fixing vulnerabilities across systems. Candidates...  ...degree, and an active DoD Secret clearance or the ability to obtain one... 
    Secret clearance
    Work at office

    Elevate Ventures

    Washington DC
    4 days ago
  • $120k

     ...requires an active Top Secret/SCI clearance with ability to obtain...  ...the security and compliance of our client's...  ...departments to implement and manage security protocols,...  ...assess potential vulnerabilities in the company's...  ...mitigate risks. Continuously monitor updates to NISPOM,... 
    Secret clearance
    Contract work
    For contractors
    Local area
    Flexible hours

    Koniag Government Services

    Washington DC
    1 day ago
  •  ...threats and vulnerabilities in this digital...  ...leaders, engineers, and assessors...  ...looking for a top-tier security...  ...measurable, continuously verifiable security...  ...continuous monitoring, with a focus...  ..., and report compliance and risk...  ...an active DoD Secret clearance; Top Secret preferred... 
    Secret clearance
    Permanent employment
    Remote work

    Tetrad Digital Integrity

    Washington DC
    1 day ago
  •  ...Akima Data Management (ADM) is seeking...  ...Governance, Risk, and Compliance (GRC)...  ...assessments, vulnerability analyses, and...  ...administrators, engineers, and development...  ...practices. Support continuous monitoring activities,...  ...Active TOP SECRET with SCI clearance (required).... 
    Secret clearance
    Full time
    Part time
    For contractors
    Work at office
    Remote work

    Akima

    Alexandria, VA
    16 hours ago
  • $185k - $200k

     ...DevOps Engineer Purpose and...  ...searching for a Top-Secret cleared...  ...facilitate task management, cross-...  ...-source monitoring tools....  ...scanning, and compliance checks throughout...  ..., and vulnerability assessment...  ...mechanisms for continuous monitoring...  ...environment Clearance Required:... 
    Secret clearance
    Monday to Friday

    Navstar

    Washington DC
    1 day ago
  •  ...Services company, is seeking a Monitoring Engineer with a Top Secret security clearance to support EHS and our government...  ...to optimize and improve management of vSphere Infrastructure. Plans...  ...ensure long‑term success with a continuous improvement approach while balancing... 
    Secret clearance
    Work experience placement
    Local area
    Flexible hours

    Koniag Government Services, LLC

    Washington DC
    4 days ago
  • $150k - $165k

     ...System Security Engineer (ISSE) Team Lead...  ...Mandatory Requirements: Top Secret Clearance with SCI...  ...cybersecurity and Risk Management Framework (RMF)...  ...) efforts, and continuous monitoring in compliance with DoD and Department...  ...POA&M tracking, vulnerability remediation, and... 
    Secret clearance
    Full time
    Temporary work
    Immediate start
    Remote work
    Flexible hours

    JFL Consulting

    Washington DC
    16 hours ago
  • $135.2k - $278.5k

     ...a Glassdoor Top 100 Best Place...  ...Lead Senior Manager will design, engineer, and...  ...implement cloud monitoring and logging...  ...and business continuity solutions for...  ...hold an active Secret clearance Bonus...  ...management, vulnerability remediation, and compliance reporting.... 
    Secret clearance
    Live in
    Work at office
    Local area

    Accenture

    Arlington, VA
    4 days ago
  •  ...Cybersecurity and Management to improve a federal...  ...) application, IA compliance measurements and...  ...Authorization (A&A), Vulnerability Management, and...  ...Government (DoD-Issued) Top Secret Security Clearance with SCI and a CI-...  ..., oversight, continuous monitoring, and maintenance... 
    Secret clearance
    Contract work

    Macpower Digital Assets Edge

    Washington DC
    16 hours ago
  • $165k - $214k

     ...Virginia Secret Hybrid...  ...Engineer to support...  ...cybersecurity, compliance, and risk management activities...  ...standards, manage vulnerabilities, and...  ...actively monitor Plan of Action...  .... Clearance Level: Must...  ...two of the top reasons our...  ...prioritizes continuous... 
    Secret clearance
    Full time
    Currently hiring
    Flexible hours

    GovCIO

    Alexandria, VA
    16 hours ago
  •  ...Customer Support Engineer (CSE), you...  ...& Management task area....  ...delivery, compliance, and customer...  ...monitoring and data integrity...  .... Conduct vulnerability analysis and...  .... Support continuous...  ...anActive Secret security clearance. Provide customer...  ...Technology TOP 50 (ranking... 
    Secret clearance
    Temporary work
    For contractors
    For subcontractor
    Work at office
    Remote work

    Agil3 Technology Solutions, LLC

    Arlington, VA
    4 days ago
  •  ...provider in Arlington, VA, is seeking a Senior Level Vulnerability Patch Management Engineer to ensure compliance with regulatory requirements. You will be...  ...requires U.S. citizenship and an active Top Secret-SCI clearance. Competitive salaries and full-time employee benefits... 
    Secret clearance
    Full time

    International Executive Service Corps

    Arlington, VA
    16 hours ago
  • $90k - $150k

     ...discretion of the government. Clearance Needed: Active Top Secret clearance (with...  ...transfer, cybersecurity vulnerabilities, supply chain exposure,...  ...development, negotiation, and monitoring of national security...  ...including those for Data Management, Cloud/Infrastructure, Software... 
    Secret clearance
    Work experience placement
    Remote work

    Blu Omega

    Arlington, VA
    11 days ago
  • $90.3k - $189.6k

     ...System Security Manager (ISSM) The...  ...posture in compliance with FISMA,...  ...implementation and continuous monitoring of security...  ...800-53). Clearance Required: Active Top Secret with SCI...  ...staff of 10 engineers including timecard...  ...security vulnerabilities are tracked and... 
    Secret clearance
    Contract work
    Work experience placement
    Flexible hours

    CACI International

    Washington DC
    1 day ago
  • Program Manager - Job Description...  ...operations and compliance activities...  ...incident response, vulnerability management,...  ...activities. Monitor contract...  ...requirements to support continuous program...  ...Science, Engineering, Business Administration...  ...eligible for Top Secret clearance if required... 
    Secret clearance
    Contract work
    For contractors
    For subcontractor

    cFocus Software Incorporated

    Washington DC
    4 days ago
  •  ...governance, incident management, deployment,...  ...operations, compliance adherence,...  ...driving continuous operational...  .... Monitor production systems...  ...Support vulnerability remediation...  ...certificate renewals, secret management,...  ...security clearance with the...  ...to obtain TOP SECRET security... 
    Secret clearance
    Permanent employment
    Work at office
    Remote work
    Monday to Friday
    Flexible hours
    Night shift
    1 day per week

    Peraton

    Washington DC
    1 day ago
  •  ...description: TLinked LLC is seeking a Monitoring Engineer to join our team of qualified...  ...delivery. Prioritize and manage work using agile methodology...  ...US Citizenship and an active SECRET Government Security Clearance with the ability to obtain TOP SECRET if needed. Bachelor’s... 
    Secret clearance
    For contractors
    Work at office
    Remote work
    Shift work
    Day shift

    Tlinked Llc

    Washington DC
    4 days ago
  •  ...seeking a Product Manager SME to work in...  ...to Unclassified, Secret, and Top Secret environments...  ...responsible for directing continuous monitoring, threat detection,...  ...encompasses RMF compliance, vulnerability management, SOC...  ...Secret security clearance with the ability to... 
    Secret clearance
    Contract work
    Shift work

    ECS Limited

    Falls Church, VA
    4 days ago
  •  ...Principal Network Systems Engineer) Saliense is a growing Management and Technology...  ...possess an active Secret clearance to be considered...  ...to obtain a Top Secret clearance....  ...workstation and server vulnerability remediation and patch...  ...Systems. Monitors, performance tunes... 
    Secret clearance
    Work at office
    Local area
    Immediate start
    3 days per week

    Saliense Consulting LLC

    Arlington, VA
    16 hours ago
  •  ...Unclassified, Secret, and Top Secret...  ...infrastructure management across AWS GovCloud...  ...Lead unifies engineering execution,...  ...compliant, and continuously aligned to...  ...maintain full compliance with program...  ...• Oversees monitoring strategies using...  ...Secret security clearance with the... 
    Secret clearance
    Contract work

    ECS Limited

    Arlington, VA
    3 days ago
  • $112.8k - $257k

     ...Cybersecurity and RMF Engineer, Lead The...  ...tools needed to assess vulnerabilities and recommend the best...  ...tools. You'll manage the research of technology...  ...packages, POA&Ms, continuous monitoring, or secure cloud...  ...suitable controls ~ Secret clearance ~ HS diploma or... 
    Secret clearance
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Arlington, VA
    3 days ago
  • A prominent engineering and services firm is seeking an IT Strategy...  ...on strategic planning and continuous process improvement. The ideal candidate needs a Top Secret security clearance and at least five years of...  ..., performance monitoring, and aligning strategic objectives... 
    Secret clearance

    EmergencyMD

    Washington DC
    16 hours ago
  • $150k - $170k

     ...- Identity & Access Management Engineer - Onsite - Active Secret Required Title 1802 -...  ...Arlington, VA Security Clearance Requirement Top Secret About Us...  ...expertise supervising, monitoring, and troubleshooting...  ...implementation gaps, vulnerabilities, and risks, developing... 
    Secret clearance
    Temporary work
    Local area

    Rollout Systems, LLC

    Arlington, VA
    2 days ago
  •  ...Senior Continuity Professional Seeking a Senior Continuity professional...  ...COOP plans, ensuring compliance with federal continuity...  ...in continuity and emergency management working groups Deploy to...  ...multiple priorities ~ Active Top-Secret clearance (SCI eligible with recent... 
    Secret clearance
    Work at office

    Omniscius

    Washington DC
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Compliance and Continuous Monitoring Engineer - Vulnerability Management (Top Secret Clearance). Be the first to apply!