Overview
Join our dynamic cybersecurity team as a Cybersecurity Engineer and become a vital defender of our digital infrastructure! In this role, you will lead efforts to safeguard our IT systems, network architecture, and cloud environments by designing, implementing, and maintaining robust security measures. Your expertise will help ensure compliance with industry standards such as ISO 27001 and NIST, while proactively identifying vulnerabilities and responding to security incidents. This is an exciting opportunity for motivated professionals eager to make a tangible impact in the realm of information security and cyber defense.
Duties
Vulnerability Scanning & Assessment
- Conduct regular vulnerability scans across servers, workstations, network devices, and cloud infrastructure using tools such as Tenable/Nessus, Qualys, or Rapid7 InsightVM.
- Validate and triage scan results to eliminate false positives and confirm exploitability.
- Perform ad hoc scans in response to newly disclosed CVEs, zero-days, or emerging threats.
Risk Prioritization & Reporting
- Score and prioritize vulnerabilities using CVSS, exploitability data, and asset criticality/business context.
- Maintain vulnerability management dashboards and metrics (mean time to remediate, aging vulnerabilities, coverage gaps) for leadership and audit purposes.
- Prepare executive-level summaries highlighting risk trends and remediation progress.
Remediation Coordination
- Partner with system owners, IT operations, and application teams to track remediation timelines and validate patch/fix implementation.
- Escalate overdue or high-risk vulnerabilities through governance and risk channels.
- Support exception/risk acceptance processes when remediation isn't immediately feasible, documenting compensating controls.
Process & Tooling
- Maintain and tune vulnerability scanning tool configurations, scan schedules, and asset inventories.
- Integrate vulnerability data with SIEM, CMDB, or ticketing systems (ServiceNow, Jira, Remedy) for streamlined tracking.
- Support patch management cadence alignment with vulnerability remediation SLAs.
Compliance & Standards
- Ensure vulnerability management practices align with frameworks such as NIST 800-40, CIS Benchmarks, PCI-DSS, or internal policy requirements.
- Support audit and compliance requests related to vulnerability and patch management evidence.
Required Skills/Tools
- Nessus/Tenable.io, Qualys, or Rapid7 InsightVM
- CVSS scoring methodology
- Basic scripting (Python/PowerShell) for report automation
- Ticketing/CMDB tools (ServiceNow, Jira)
- Understanding of network and OS-level vulnerabilities (Windows, Linux)
Qualifications
- Proven experience in cybersecurity engineering or related roles with a strong understanding of computer networking concepts including routing protocols (EIGRP, OSPF), TCP/IP stack, DNS, DHCP, VPNs, load balancing, and network support.
- Hands-on knowledge of cybersecurity frameworks such as ISO 27000 series standards (ISO 27001), NIST standards (RMF), COBIT, DIACAP; familiarity with FIPS compliance is a plus.
- Expertise in deploying and managing cybersecurity tools such as SIEM solutions (Splunk or SolarWinds), Endpoint Detection and Response (EDR) systems like Fiddler or PowerShell scripting for incident management automation.
- Strong background in system administration across multiple operating systems including Windows Server environments, Linux distributions (Ubuntu, Debian), Solaris or BSD variants; experience with virtualization platforms like VMware vSphere or Citrix is advantageous.
- Knowledge of cloud security engineering principles for PaaS/IaaS environments including AWS CloudFormation templates or Google Cloud Platform architecture design.
- Ability to perform vulnerability research & assessment using attack frameworks; conduct threat detection & response investigations; execute system hardening techniques; and support disaster recovery planning.
- Excellent problem-solving skills combined with the ability to communicate complex technical concepts clearly; relevant certifications such as CISSP, CISA or GIAC are preferred.
Join us in protecting critical digital assets through innovative cybersecurity strategies! We are committed to fostering an inclusive environment where talented professionals thrive while making a meaningful difference in the world of information security.
Pay: $55.00 - $65.00 per hour
Work Location: Hybrid remote in Brooklyn, NY 11202