View all jobs
We have the following opportunities available:
Vulnerability Assessment Analyst
We are seeking a Vulnerability Assessment Analyst for an opportunity in Washington, DC. All applicants must have an active Public Trust.
We have the following opportunities available:
- Vulnerability Assessment Analyst Mid | 5+ years | CBP BI - High Trust
- Vulnerability Assessment Analyst Junior | 3+ years - Position 1; 5+ years - Position 2 | CBP BI - High Trust
Job Description
The Contractor shall provide Vulnerability Assessment (VA) support to CBP information systems, including but not limited to the following:- Assist the Government in managing CBP Enterprise Information System Vulnerability Management (ISVM) compliance validation.
- Assist the Government in briefing leadership on current and future vulnerabilities, security policies and industry standards.
- Assist the Government in briefing leadership on most impactful vulnerabilities, configurations, and penetration testing efforts.
- Assist the Government in creating and managing all scans in accordance with the CBP VAT scan standardization documentation.
- Assist the Government in performing regularly scheduled vulnerability assessments using a master schedule as directed.
- Assist the Government in managing, customizing, and maintaining scan policies, zones, and repositories as they relate to the CBP network.
- Assist the Government in performing scan functions and review scan results to ensure accurate findings.
- Assist the Government in creating and customizing scan reports and data feeds to be imported / integrated into third party assessment tools.
- Support the coordination of the VA scanning and testing in advance with the system ISSO and the Government Task Monitor (TM) to assure coordination with network maintenance, availability, and operations.
- Coordinate with system owner / ISSM/ ISSO to make any necessary changes to the schedule.
- Use test procedures approved by the Government VAT Team Lead, including scripts to collect information and VA tools that are Security Content Automation Protocol (SCAP) compatible; the latest versions of tools with up-to-date lists of vulnerability checks in accordance with CBP's policies, needs, and technologies.
- Assist the Government in conducting specialized VA testing to include Database and Web application assessments, penetration testing, mobile application assessments, 802.11 wireless assessments, and radio frequency testing and analysis of frequencies in common usage by IOT devices (approximately 300MHz to 6GHz).
- Assist the Government in employing ad hoc or emergency VA scanning to support targeted incident investigation, escalation, and emergency response to security events in accordance with documented procedures.
- Support internal and external audits, including but not limited to OIG, NCATS, CSP, KPMG, etc.
- Provide support to facilitate Bug Bounty assessments performed by contracted vendors on CBP Information Systems.
- Assist the Government in managing / maintaining asset inventory for each FISMA system, database, and web application Uniform Resource Identifiers (URLs) as provided by each system ISSO.
- Assist the Government in providing support to ISSO / ISSM interpreting scan results and recommend remediation plans.
- Assist the Government in performing enumeration for data calls, including but not limited to CISA Binding Operational Directives (BOD) and Emergency Directives (ED).
- Travel to be physically on location to perform onsite security assessments of CBP facilities, systems, and applications as requested.