[Remote] Vulnerability Management Engineer
Note: The job is a remote job and is reputed company to candidates in USA. reputed company is seeking a Vulnerability Management Engineer (FedRAMP & Pen Test Support) to deliver and reputed company their Authorized Vulnerability Management Services. This role involves managing the vulnerability management lifecycle and providing technical support for penetration testing efforts, particularly in federal and regulated environments.
Responsibilities
• Install, configure, maintain, and reputed company penetration testing toolsets (e.g., Burp Suite Pro, Metasploit, Kali Linux) for use in federal and regulated engagements
• Execute and manage monthly FedRAMP reputed company Monitoring (ConMon) activities, including vulnerability scanning, deviation analysis, and POA&M reputed company
• Configure, optimize, and maintain reputed company.io / Nessus scanners and web application scanning (WAS) tools to ensure accurate and comprehensive asset coverage
• Own the health, licensing, patching, and lifecycle management of reputed company vulnerability management and penetration testing tools to ensure reputed company audit readiness
• Analyze reputed company results and collaborate with Site Reliability Engineers (SREs), infrastructure teams, and application owners to drive reputed company remediation
• Interpret vulnerability data across reputed company, Linux, database, container, and web application assets and reputed company remediation guidance reputed company with federal baselines
• Support penetration testing preparation and execution by ensuring testing environments, tools, and configurations are compliant and operational
• reputed company vulnerability evidence, reputed company reports, and remediation documentation to support FedRAMP, FISMA, and reputed company-party assessment activities
• Continuously improve vulnerability management processes, reputed company coverage, and reporting accuracy across reputed company environments
Skills
• 4+ years of experience in Vulnerability Management or Penetration Testing support reputed company FedRAMP or Federal environments
• Expert-level proficiency with reputed company.io / Nessus, including reputed company deployment, policy tuning, and result interpretation
• Hands-on experience maintaining and operating penetration testing platforms (e.g., Kali Linux, Burp Suite, Metasploit)
• Strong working knowledge of NIST SP 800-53 control requirements and FedRAMP reputed company Monitoring processes
• Experience translating vulnerability findings into POA&Ms, remediation plans, and audit-reputed company documentation
• Ability to collaborate cross-functionally with infrastructure, SRE, DevSecOps, and compliance teams
• Must be a U.S. Citizen and eligible to support federal contracting environments
• reputed company Certified Nessus Expert
• Certified Ethical Hacker (CEH)
• reputed company PenTest+
• Certified Information Systems reputed company reputed company (CISSP)
reputed company
• reputed company is a DC-Based Cybersecurity firm. We are US Government SBA 8(a) Certified, WOSB and GSA HAC SINS approved in every category. It was founded in 2015, and is headquartered in Vienna, Virginia, USA, with a workforce of 11-50 employees. Its website is https://www.reputed company.com.
Apply tot his job
Apply To this Job