Location: Remote (Columbia, South Carolina)/(preference for candidates available for on-site support)
Duration: 12 Months (Possible Extension)
The Consultant will serve as a Vulnerability Management Systems Analyst within an enterprise Information Security team. This role focuses on enhancing and supporting a large-scale vulnerability management program by administering tools, coordinating with stakeholders, and driving risk reduction efforts through effective remediation strategies.
- Support and enhance an enterprise-wide vulnerability management program
- Administer vulnerability management platforms, including configuration, policy setup, and reporting
- Analyze vulnerabilities, prioritize remediation efforts, and document residual risks
- Provide training and guidance on vulnerability management best practices
- Assist in the procurement, implementation, and optimization of security tools
- Develop and track Plans of Action & Milestones (POA&Ms) to ensure timely remediation
- Conduct system criticality and risk validation assessments
- Deliver regular reports and updates to stakeholders on vulnerabilities and risk posture
- 5+ years of experience with vulnerability management tools (e.g., Qualys, Tenable, Rapid7)
- 5+ years of experience in designing, deploying, and managing vulnerability management platforms
- 5+ years of experience with Windows and Linux operating systems
- Strong experience with CVSS scoring, POA&M tracking, and risk mitigation strategies
- Familiarity with security frameworks (e.g., PCI DSS, NIST, ITIL, CVSS, MITRE ATT&CK)
- Experience with application security and scripting (Python, PowerShell, Bash)
- Experience leading enterprise or large-scale vulnerability management programs
- Local to or near Columbia, South Carolina (preferred)
Required:
- Bachelor’s degree in Information Technology, Cybersecurity, or related field
- OR equivalent combination of education and relevant experience
Preferred:
- Advanced security certifications (e.g., CISSP, CISA, CISM or equivalent)
- Additional certifications such as CEH, OSCP, or GPEN
Remote role with occasional on-site presence as needed (preference for candidates available for on-site support)
For more details reach at resumes@navitassols.com.