1

Contract Vulnerability Scanning Jobs in Virginia

... vulnerability scans utilizing DoD/DoN mandated practices and software utilities. -Conducts ... Contract to Hire position based out of Stafford, VA. Pay and Benefits The pay range for this ...

Cloud Engineer

Chantilly, VA ยท Hybrid

$120K - $160K/yr

The CMCC System Facilitator contract positions SAIC to accelerate how new capabilities are ... Awareness of security practices such as STIG hardening, vulnerability scanning, Zero Trust, or MLS ...

R&D Cybersecurity Engineer

Fort Belvoir, VA ยท On-site

$120 - $180/hr

Evaluate new vulnerability scanning and application security technologies. * Design proof-of ... on the contract. Must meet all other requirements.) * Computing Environment (CE): Microsoft ...

Systems Security Specialist

Virginia Beach, VA ยท On-site

$130K - $190K/yr

Conduct or coordinate vulnerability scanning, configuration management, and patch remediation ... This position is fully dedicated to the contract, operates independently of IT operations, and may ...

Showing results 21-40

Contract Vulnerability Scanning information

What is contract vulnerability scanning?

Contract vulnerability scanning refers to the process of hiring third-party professionals or firms to assess and identify security weaknesses in an organization's systems, networks, or applications. The scanning is typically performed on a contractual basis, often as part of compliance requirements or routine security practices. These experts use automated tools and manual techniques to detect vulnerabilities that could be exploited by attackers, providing detailed reports and recommendations for remediation. This approach allows organizations to benefit from specialized expertise without maintaining a full-time, in-house vulnerability scanning team.

What are some common challenges faced by professionals in contract vulnerability scanning roles?

Professionals in Contract Vulnerability Scanning often encounter challenges such as managing tight deadlines, adapting to varied client environments, and ensuring clear communication of technical findings to non-technical stakeholders. They must stay updated with the latest vulnerabilities and scanning tools, as threats and technologies evolve rapidly. Additionally, balancing thoroughness with efficiency is crucial, as clients expect comprehensive reports without significant delays. Collaboration with IT, security, and management teams is also key to ensure that identified vulnerabilities are properly addressed.

What is the difference between Contract Vulnerability Scanning vs Penetration Tester?

AspectContract Vulnerability ScanningPenetration Tester
Primary FocusAutomated identification of security vulnerabilities in systemsManual and automated testing to exploit vulnerabilities and assess security
Tools & TechniquesVulnerability scanners, automated toolsCustom scripts, penetration tools, manual testing
Work EnvironmentTypically performed remotely or on client sites, within security teamsOften on-site, conducting simulated attacks
CertificationsCompTIA Security+, CISSP, CEHOSCP, CEH, GPEN

Contract Vulnerability Scanning involves automated tools to identify security weaknesses, while Penetration Testers perform manual and automated testing to exploit vulnerabilities. Both roles require security certifications but differ in approach and scope, with vulnerability scanning being more automated and penetration testing more hands-on.

What are the key skills and qualifications needed to thrive as a contract vulnerability scanning specialist, and why are they important?

To thrive as a Contract Vulnerability Scanning Specialist, you need expertise in network security, vulnerability assessment methodologies, and a solid understanding of operating systems and protocols, often supported by certifications like CompTIA Security+ or CEH. Proficiency with vulnerability scanning tools such as Nessus, OpenVAS, or Qualys, and familiarity with ticketing and reporting systems are typically required. Attention to detail, analytical thinking, and clear communication are essential soft skills for identifying risks and conveying findings to non-technical stakeholders. These capabilities ensure the accurate detection of security weaknesses and effective risk mitigation for clients or organizations.
What are the most commonly searched types of Vulnerability Scanning jobs in Virginia? The most popular types of Vulnerability Scanning jobs in Virginia are:
What are popular job titles related to Contract Vulnerability Scanning jobs in Virginia? For Contract Vulnerability Scanning jobs in Virginia, the most frequently searched job titles are:
What job categories do people searching Contract Vulnerability Scanning jobs in Virginia look for? The top searched job categories for Contract Vulnerability Scanning jobs in Virginia are:
What cities in Virginia are hiring for Contract Vulnerability Scanning jobs? Cities in Virginia with the most Contract Vulnerability Scanning job openings:

Information Assurance (IA) Manager

Enhanced Veterans Solutions, Inc.

Fredericksburg, VA โ€ข On-site

$150K - $165K/yr

Full-time

Posted 4 days ago


Job description

Description:

EVS is seeking an Information Assurance Manager for an upcoming proposal effort. * The Information Assurance (IA) Manager provides Information Assurance Vulnerability Management, cybersecurity compliance, vulnerability assessment, incident-response, and Authority to Operate support for EACN from Scott Air Force Base, Illinois.


*This position is contingent upon the award of the contract. The anticipated start date and scope of work will be determined based on the outcome of the interview process and the details of the awarded contract.


  • Support the EACN Information Assurance Vulnerability Management program by providing the EACN ISSM and EACN Program Manager with technical support concerning order applicability, mitigation actions, network architecture engineering, and supporting documentation.
  • Process USCYBERCOM- and USAF-issued cyber orders in the Systems Integration Laboratory in support of the A2G2 locations at JBA, JBLM, and Scott AFB, including applicable TASKORDs, OPORDs, Cyber Tasking Orders, Time Compliance Network Orders, Maintenance Tasking Orders, Cyber NOTAMs, and Special Instructions.
  • Provide technical configuration information supporting the monitoring and updating of DISA Vendor Management System or Continuous Monitoring and Risk Scoring records and the USAF AFNETOPS Compliance Tracker.
  • Manage EACN Information Assurance Vulnerability Management responsibilities in accordance with cyber orders.
  • Provide technical support and documentation to the EACN ISSM in support of acquiring and maintaining the EACN Authority to Operate requirements.
  • Perform weekly network vulnerability scans using approved Air Force tools, such as ACAS, and provide results in the EACN Security-Compliance Report.
  • Use Government network scanning tools to provide IA findings, results, and remediation activities to the EACN ISSM and EACN Program Manager.
  • Direct implementation and track the status of patches, updates, and other actions required to maintain hardware and software compliance with cyber orders; report status through the EACN Security-Compliance Report.
  • Perform first-responder scans and other response tasks, Post-Notification Investigations, Network Defense Incident Reports, ACAS vulnerability scans, and requested VMS or CMRS configuration changes.
  • Provide backups of Intrusion Detection System Defense Center configurations and data, Syslog Server data, firewall logs, and DNS logs to the EACN ISSM.
  • Perform duties on-site at Scott AFB, Illinois.
Requirements:

ISC2 Certified Information Systems Security Professional (CISSP) certification, minimum.

SECRET security clearance at the time of contract award.

Must be able to perform duties on-site at Scott AFB, Illinois.