The Vulnerability Mitigation Expert reduces vulnerability risk and attack surface exposure through continuous data analysis that enables crucial infrastructure resiliency and stakeholder visibility into cyber threats. This role is focused on providing tailored mitigation strategies and improvements plans, for vulnerabilities identified through government authorities and cyber security assessment services. Candidate will need to reside in the DC Metro Area and willing to work Onsite as needed.
Things you’ll do:
- Research, analyze, and assess attack surface and vulnerability data
- Develop tailored and actionable mitigation strategies and plans to address vulnerability risk
- Work with new and emerging vulnerability data to identify potential attack paths in critical systems.
- Document and present mitigation strategies and plans to the client and stakeholders
- Analyze the root cause of vulnerabilities and support the prioritization of mitigations based on risk and return on mitigation
- Provide mitigation strategies that prioritize risk against level of effort for multiple systems or organizations
- Catalog mitigation advice, challenges, and trends and patterns
- Provide subject matter expertise on tailored mitigations to resolve and remediate vulnerabilities on targeted technologies
Required Qualifications:
- BS or BA degree
- 5-10+ years relevant experience
- experience and knowledge of tools such as Tenable Nessus, Qualys, AppDetective, and WebInspect, LookingGlass, BlackKite, Shodan
- secure architecture designs and use of detection/protection mechanisms (e.g., firewalls, IDS/IPS, full-packet capture technologies) to mitigate risk
- Experience with cybersecurity assessments and assessment data such as Security Architecture Reviews (SARs), Validated Architecture Reviews (VADRs), Risk and Vulnerability Assessments (RVAs)
- Experience reviewing assessments, assessment data, and architecture diagrams to develop mitigation strategies
- Experience designing and developing vulnerability mitigation strategies such as security controls to mitigate software vulnerabilities
- Candidate must hold an active TS/SCI.
Preferred:
- Strong analytical, organizational, and time management skills
- Ability to coordinate and be flexible with a cross-functional team
- Ability to drive action to achieve results with minimal direction
- Executive presence and comfort engaging with clients.
- Keen attention to detail, grammar, and formatting
- High drive for continuous learning and research
- Strong communication (written and verbal) and issue resolution skills
- Ability to write clearly, often about complex topics
Familiarity and working knowledge of penetration testing tools such as Kali Linux, Metasploit, Cobalt Strike)
- Experience working in a fast-paced client environment
- Experience performing security code reviews
- Ability to communicate to both technical and non-technical audiences information related to vulnerabilities
- Experience writing technical documents for both technical and non-technical audiences
Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.
From developing a stand out resume to putting your best foot forward in the interview, we want you to feel prepared and confident as you explore opportunities at Deloitte. Check out recruiting tips from Deloitte recruiters.
At Deloitte, we know that great people make a great organization. We value our people and offer employees a broad range of benefits. Learn more about what working at Deloitte can mean for you.
Our diverse, equitable, and inclusive culture empowers our people to be who they are, contribute their unique perspectives, and make a difference individually and collectively. It enables us to leverage different ideas and perspectives, and bring more creativity and innovation to help solve our client most complex challenges. This makes Deloitte one of the most rewarding places to work. Learn more about our inclusive culture.
From entry-level employees to senior leaders, we believe there’s always room to learn. We offer opportunities to build new skills, take on leadership opportunities and connect and grow through mentorship. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their career.