Remote – United States
I. DESCRIPTION OF SERVICES
Vulnerability Inventory and Baseline Establishment
1. Review the Agency’s existing vulnerability data, including vulnerabilities identified through scanning, assessments, or other security tools.
2. Establish and maintain a consolidated vulnerability baseline.
3. Develop and document a remediation timeline for all identified vulnerabilities, reflecting current risk posture and aging.
Risk Classification and Prioritization
1. Ensure that vulnerabilities are categorized and prioritized based on risk, severity, exploitability, and potential impact to Agency operations.
2. Align vulnerability classification and prioritization to applicable NIST guidance.
3. Validate that remediation timeframes align with Agency established expectations for different vulnerability risk levels.
Remediation Coordination and Communication
1. Coordinate remediation activities with system, server, and application owners.
2. Communicate clear remediation expectations, risk context, and required timelines to responsible parties.
3. Track remediation progress and identify blockers, dependencies, or delays impacting closure.
4. Escalate overdue, high risk, or critical vulnerabilities to appropriate Agency governance or oversight bodies, in accordance with Agency processes.
Tracking, Metrics, and Reporting
1. Maintain ongoing tracking of vulnerability remediation status.
2. Produce periodic status reports summarizing.
Validation and Closure
1. Validate remediation actions through available evidence, including vulnerability scan results or other supporting artifacts.
2. Confirm closure of vulnerabilities in tracking systems once remediation is completed and validated.
3. Ensure vulnerabilities that cannot be remediated within required timeframes are formally documented and supported by approved risk acceptance or exception documentation, in accordance with Agency policy.
Program Improvement Support
1. Identify process gaps, systemic issues, or control weaknesses affecting vulnerability remediation effectiveness.
2. Provide recommendations for improving vulnerability remediation processes and accountability, aligned with NIST standards and Agency governance requirements.
II. CANDIDATE SKILLS AND QUALIFICATIONS
| Minimum Requirements: Candidates that do not meet or exceed the minimum stated requirements (skills/experience) will be displayed to customers but may not be chosen for this opportunity. | ||
| Years | Required/Preferred | Experience |
| 8 | Required | Experience in Vulnerability Inventory and Baseline Establishment |
| 8 | Required | Experience in Risk Classification and Prioritization |
| 8 | Required | Experience in tracking vulnerability remediation |
| 8 | Required | Experience in producing status reports |
| 8 | Required | Experience in validating remediation actions through available evidence, including vulnerability scan results |
Note : Expected Start Date 05/26/2026 and Expected End Date 08/31/2026 . May be renewed up to 3 years.
Normal business hours are Monday through Friday from 8:00 AM to 5:00 PM , excluding State holidays when the agency is closed. The worker may be required to work outside the normal business hours on weekends, evenings and holidays, as requested.
...integrity guide everything we do, and our focus on community impact keeps us grounded in purpose-driven innovation. Overview: Appliance Install Driver Monday - Friday As a CSC Appliance Install Driver your days will be active, delivering and installing laundry...
We have an immediate need for a VDC Engineer for our New York City Office in lower Manhattan. LiRo-Hill Virtual Design & Construction Operations (VDCO) is a multidisciplinary practice seamlessly integrating technology and innovation for the built environment...
...Consultative Sales Polaris Estate Planning & Elder Law Creve Coeur / St. Charles, Missouri Full-Time | In-Office | Base $50,000 | Total Comp $100,000$150,000+ Do you know how to lead a consultation, build trust quickly, and confidently ask for the business...
...practice that values precision, professionalism, and initiative. ROLE DESCRIPTION We are seeking an experienced, certified paralegal to join our team on a part-time, remote basis. This is an excellent opportunity for a seasoned litigation paralegal who thrives in...
...Description: Airport Maintenance, Full-Time, Evening Shift Starting Pay Rate: The pay rate for this position is $28.32 per hour Schedule: Monday-Friday, 3:30 P.M. - Midnight The Lincoln Airport Authority offers a very comprehensive benefits package. ~ Health...