Cybersecurity SME KEVBOD Analysis Pen-Test Governance
Haymarket, VA - USA
Job Summary
About QBE LLC
QBE LLC is a small business dedicated to delivering innovative technology cybersecurity and mission-support solutions to federal government customers. Our experienced professionals work closely with our customers to solve complex challenges protect critical information and support essential government missions.
At QBE we turn the possible into the proven.
Overview
QBE LLC is seeking a Cybersecurity SME - KEV/BOD Analysis; Pen-Test Governance to provide expert vulnerability risk analysis federal directive support and penetration-testing governance for NIH/OD-OIT.
This position is primarily remote but will require some TDY.
Responsibilities
Analyze Known Exploited Vulnerabilities and applicable federal cybersecurity directives.
Determine organizational impact and support prioritization of required remediation activities.
Track compliance with vulnerability-related directives and remediation deadlines.
Provide expert risk analysis for critical and actively exploited vulnerabilities.
Develop reports dashboards and executive briefings on KEV and directive compliance.
Establish governance processes for penetration testing activities.
Review penetration-test scope rules of engagement methods and deliverables.
Track penetration-test findings through remediation and closure.
Evaluate risk exceptions and compensating controls.
Advise leadership on vulnerability risk and remediation priorities.
#qf
#qg
Minimum Qualifications
Associate degree in cybersecurity information technology computer science information systems business communications or a related field or an additional two or more years of relevant experience in place of the degree requirement.
At least 10 years of relevant experience aligned to the responsibilities of this position.
Expert knowledge of vulnerability risk management and remediation processes.
Experience analyzing high-impact vulnerabilities and federal cybersecurity directives.
Experience overseeing or governing penetration-testing activities.
Strong risk-analysis and executive communication skills.
CompTIA Security certification.
Certified in Risk and Information Systems Control (CRISC) certification.
Ability to obtain and maintain the required federal background investigation Public Trust determination or security clearance associated with the position.
Preferred Qualifications
Federal vulnerability management experience.
Familiarity with CISA Known Exploited Vulnerabilities and Binding Operational Directives.
Experience coordinating enterprise penetration testing.
Physical Requirements
Ability to remain in a stationary position for extended periods while working at a computer.
Ability to communicate effectively through virtual and in-person meetings.
Ability to perform duties in an office remote or hybrid environment based on program requirements.
Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of the position.
Equal Opportunity Employer
QBE LLC is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to any characteristic protected by applicable federal state or local law.
The projected compensation range for this position is $115000.00 - $130000.00. There are differentiating factors that can impact a final salary/hourly rate including but not limited to Contract Wage Determination relevant work experience skills and competencies that align to the specified role geographic location (for remote opportunities) education and certifications as well as Federal Government Contract Labor addition QBE invests in its employees beyond just compensation. QBEs benefits offerings include dependent upon position Health Insurance Life Insurance Paid Time Off Holiday Pay short-term and long-term Disability Retirement and Savings Learning and Development opportunities wellness programs as well as other optional benefit elections.
About Company
POSSIBLE TO PROVEN Where some see problems, we see possibilities. QBE's unparalleled experience, in-depth insights and sought-after technical expertise allow us to mitigate mission-critical challenges into transformative solutions. Find Out More What We Do Cybersecurity Cyber risks ar ... View more