What are the responsibilities and job description for the Principal Consultant - Lead Vulnerability Management Engineer position at NYSTEC?
NYSTEC is a nonprofit technology consulting company, advising agencies, organizations, institutions, and businesses since 1996. We're independent and vendor-neutral, so we have our clients' best interests at heart. At NYSTEC, we know that we succeed when individuals and teams flourish personally and professionally, so our benefits and perks support that mindset.
About the Role:As a lead vulnerability management engineer in NYSTEC's Cybersecurity and Data Privacy Practice, you will collaborate with team members to conceptualize, deliver, and support our clients through today's ever-changing cybersecurity landscape. NYSTEC is considered a trusted advisor, partner of choice, and employer of choice. We believe that every interaction is an opportunity to deliver exceptional service that empowers client success.
Serving as a lead vulnerability management engineer, your day-to-day role as a NYSTEC consultant will include understanding the technical details of vulnerabilities, explaining details to both technical and non-technical stakeholders, assessing impacts and providing remediation support.
NYSTEC is looking for a dedicated and qualified technical resource to assist a New York City (NYC) organization with day-to-day vulnerability management activities.
This role will be performed onsite in NYC.
Key Responsibilities- Analyzing identified vulnerabilities (including zero-day vulnerabilities).
- Identifying systems impacted, determining organizational impact, recommending compensating and mitigating controls, and prioritizing remediation efforts.
- Supporting organizational staff with remediation efforts, tracking, and interacting with internal and external stakeholders.
- Using tools such as Armis, Splunk, Secureworks, Tenable, and Rapid 7 to discover vulnerabilities (including scans, setup alerts, etc.).
- Tracking and validating the remediation of patches to systems and applications (security regression testing).
- Assisting with reviewing and interpreting the results of regular internal and external vulnerability scans.
- Performing correlation searches in Splunk.
- Assisting with monitoring and analyzing data from security systems (such as intrusion detection/prevention [IDS/IPS] logs) to determine any patterns indicating a compromised system(s).
- Experience with tools including, but not limited to Armis, Splunk, Secureworks, Tenable, and Rapid 7.
- Ability to understand the technical details of vulnerabilities, to explain the details to a technical and nontechnical audience, and to describe how they impact the organization.
- Exceptional technical understanding of vulnerabilities and attacker tools and methods.
- Experience with vulnerability discovery techniques and tools.
- Experience with web application testing and tools.
- Experience with IDS/IPS systems and logs.
- Experience with Splunk.
- Experience with hands-on testing to confirm vulnerabilities and their remediation.
- Ability to work in a team setting.
- Proficient technical, communication, and writing skills.
Preferred/Desired Qualifications
- Certified information systems security professional (CISSP) or other skill-specific certifications (e.g., certified ethical hacker [CEH], offensive security certified professional [OSCP], Global Information Assurance Certification penetration tester [GPEN], Global Information Assurance Certification exploit researcher and advanced penetration tester [GXPN], Computing Technology Industry Association penetration testing [CompTIA PenTest ]).
Education and Experience
- A bachelor's degree in cybersecurity or a related field of study and eight or more years of experience with five years of experience with vulnerability assessments and management, penetration testing, security assessments and monitoring solutions.
- An equivalent combination of advanced education, training, and experience will be considered.
The pay range for this position is $121,355 to $166,863.
It is NYSTEC's policy to provide equal employment opportunity (EEO) to all individuals, regardless of actual or perceived race, color, creed, religion, sex, or gender (including pregnancy, childbirth, and related medical conditions), gender identity or gender expression (including transgender status), age, national origin, ancestry, citizenship status, physical or mental disability, protected medical condition as defined by applicable state or local law, genetic information, military service and veteran status, sexual orientation, marital status, or any other characteristic protected by local, state, or federal laws and ordinances. NYSTEC is strongly committed to this policy and believes in the concept and spirit of the law.
Federal law requires employers to provide reasonable accommodation to qualified individuals with disabilities. Please contact recruitment@nystec.com if you require a reasonable accommodation to apply for or to perform this job. Examples of reasonable accommodation include making a change to the application process or work procedures, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment.
Applicants must be authorized to work in the United States without the need for visa sponsorship now or in the future.
Learn more about NYSTEC by visiting www.nystec.com.
Salary : $121,355 - $166,863