- Lead the agency’s vulnerability management lifecycle using Tenable.sc, Tenable.io, Nessus Manager, and Nessus scanners (on-prem and cloud).
- Analyze, prioritize, and track remediation of vulnerabilities in coordination with IT operations and system owners in a hybrid environment.
- Maintain scan schedules, asset groups, scan policies dashboards, and reports tailored to agency infrastructure and communicate risk posture and remediation progress to relevant infrastructure and application teams to remediate vulnerabilities.
- Define the scanner and security center architecture, refine data flows and synchronizations, tune scanning configurations to minimize false positives and ensure the best coverage.
- Develop and maintain documentation for system setup, operation, vulnerability management processes, exceptions, and remediation tracking.
- Support implementation of security projects that require compliance with relevant government policies or standards.
- Act as SME for vulnerability management tools and processes; updating processes and monitoring to meet organization mandates.
- Ensure systems and practices comply with FISMA and FedRAMP related Security Assessment and Authorization (SA&A) and compliance for the organization’s IT programs.
- Assist in coordination, implementation, communication, and enforcement of the organization’s IT security policies.
- Support incident response.
- Requires bachelor’s degree in computer science, cyber security, engineering, or a related technical field. Additional experience and relevant certifications may be considered in leu of a degree.
- 5-7 years of progressive and related experience in IT security with at least 3 years in vulnerability management.
- Expert knowledge of IT security vulnerabilities and risk assessments with a ability to translate complex technical risks into clear, actionable business impacts for executives and technical teams.
- Direct and manage enterprise-class Vulnerability Management (VM) platforms (e.g., Tenable/Nessus) to ensure comprehensive asset discovery, repository management accurate scanning, and robust reporting.
- Strong knowledge of vulnerability management lifecycle, patch management processes, and risk scoring (e.g., CVSS2) models.
- Familiarity with cloud platforms (AWS and GCP) and hybrid environments.
- Understanding of Windows, Linux/Unix, and network devices security hardening.
- Ability to work with program staff, executives, security application vendors and technology staff to achieve IT security goals and objectives.
- Excellent working experience in applying FISMA, and FedRAMP processes and policies, maintaining Assessment and Authorization documentation for large federal IT systems.
- Skilled at bridging gaps between program staff, executives, technology teams, and external security vendors to successfully achieve organizational security objectives with a demonstrated ability to align technical, security, and business stakeholders across the organization.
- Ability to effectively communicate orally and in writing.
- Experience supporting a nationwide mid-to large Federal agency enterprise is a plus.
- CISSP certification required (ability to obtain within 6 months of start).
- Must obtain an agency public trust suitability determination prior to start date.
Desired Qualifications:
- Experience with scripting and automation (e.g., Python, PowerShell) to automate scanning tasks, reporting, and API integrations; administration and operation of security scanning and vulnerability management platforms such as Nessus.
- Deep expertise with SIEM platforms and integration of vulnerability data into enterprise monitoring.
- Understanding of the Secure Software Development Life Cycle.
- Master’s degree or additional security or cloud certifications (e.g., CISM).
We offer Medical, Dental, Vision, Basic Life, Short-Term Disability, Accident, Term Life, Whole Life, and 401k for all W2 Consultants. A benefit overview will be provided as requested.
Skills Required
- Bachelor’s degree in computer science, cybersecurity, engineering, or a related technical field; equivalent experience or certifications may substitute.
- 5–7 years of progressive, related IT security experience, including at least 3 years in vulnerability management.
- Expert knowledge of IT security vulnerabilities and risk assessments.
- Experience translating technical risks into actionable business impacts for executives and technical teams.
- Experience managing enterprise vulnerability management platforms such as Tenable or Nessus.
- Knowledge of vulnerability management lifecycle, patch management, and CVSS2 risk scoring.
- Familiarity with AWS, GCP, and hybrid environments.
- Understanding of security hardening for Windows, Linux/Unix, and network devices.
- Experience applying FISMA and FedRAMP processes and policies.
- Experience maintaining Assessment and Authorization documentation for large federal IT systems.
- Ability to collaborate with program staff, executives, technology teams, and external security vendors.
- Strong written and verbal communication skills.
- CISSP certification, or ability to obtain it within six months of starting.
- Ability to obtain an agency Public Trust suitability determination before the start date.
- Experience supporting a nationwide mid-sized to large federal agency enterprise.
- Experience with Python or PowerShell scripting and automation for scanning, reporting, and API integrations.
- Expertise with SIEM platforms and vulnerability data integration.
- Understanding of the Secure Software Development Life Cycle.
- Master’s degree or additional security or cloud certifications such as CISM.
What We Do
Compass Pointe Consulting is a Maryland-based, women-owned small business specializing in IT and finance and accounting solutions and services. It supplies proven talent to employers across the United States through contract, contract-to-hire, permanent, and statement-of-work personnel. The company focuses on staffing and workforce solutions that help organizations fill technology and finance/accounting needs, serving clients with flexible hiring arrangements for ongoing and project-based requirements.








