- Location
- Oklahoma City, OK, US
- Type
- Full-time
- Department
- Security
- Experience
- 3+ years
- Education
- Bachelor
- Closing date
- Today
- Source
- iCIMS
Description
Overview
Position Summary
The Vulnerability Management Technician (T3) is responsible for working all aspects of the team's Internal Vulnerability Assessment (IVA) and External Vulnerability Assessment (EVA) service, and for beginning direct involvement in 3rd-party assessment engagements, including penetration tests. T3 technicians perform vulnerability scanning, triage, remediation tracking, and reporting under the direction of the Vulnerability Management Team Supervisor.
Responsibilities
Essential Duties and Responsibilities
Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Internal and External Vulnerability Assessment (IVA/EVA):
- Perform internal and external vulnerability scans across applicable systems, networks, and applications.
- Analyze scan results to identify, validate, and prioritize vulnerabilities based on severity and business impact.
- Perform technical and nontechnical risk and vulnerability assessments of relevant technology focus areas (e.g., local computing environment, network and infrastructure, enclave boundary, applications).
- Track remediation status of identified findings through resolution, escalating overdue or high-severity items to the Vulnerability Management Team Supervisor.
- Prepare clear, accurate reports summarizing findings, technical detail, and recommended remediation steps.
- Measure the effectiveness of defense-in-depth architecture against known vulnerabilities.
3rd-Party Assessment Support:
- Support the intake, scoping, and coordination of 3rd-party IVA, EVA, and penetration test engagements.
- Assist in preparing environments and documentation for 3rd-party assessors and coordinate access as needed.
- Review 3rd-party assessment findings, validate results, and support remediation planning and tracking alongside internally identified findings.
- Maintain current knowledge of applicable cyber defense policies, regulations, and compliance documents relevant to vulnerability and assessment work.
- Other duties as assigned.
Required Knowledge, Skills, and Abilities
- Knowledge of computer networking concepts and protocols, and network security methodologies.
- Knowledge of cybersecurity and privacy principles, and of cyber threats and vulnerabilities.
- Knowledge of application vulnerabilities and Application Security Risks (e.g., OWASP Top 10).
- Knowledge of network security architecture concepts, including topology, protocols, components, and defense-in-depth principles.
- Knowledge of network protocols such as TCP/IP, DHCP, DNS, and directory services.
- Knowledge of system administration concepts across common operating systems (e.g., Unix/Linux, Windows).
- Knowledge of penetration testing principles, tools, and techniques.
- Skill in conducting vulnerability scans and recognizing vulnerabilities in security systems.
- Skill in using network analysis tools to identify vulnerabilities (e.g., fuzzing, Nmap).
- Skill in conducting application vulnerability assessments.
- Ability to work independently within established procedures and escalate appropriately.
- Ability to communicate technical findings clearly in written reports and to team leadership.
Work Environment
This job operates in a professional office or security operations environment. This role routinely uses standard office and security equipment such as computers, phones, and vulnerability scanning and monitoring tools.
Physical Demands
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job.
While performing the duties of this job, the employee is regularly required to talk or hear. The employee is frequently required to sit for long periods of time; stand; walk; use hands to type, handle or feel; and reach with hands and arms. The employee is occasionally required to stoop, kneel, crouch, or crawl. The employee must occasionally lift and move up to 25 pounds. Specific vision abilities required by this job include close vision, distance vision, color vision, peripheral vision, depth perception, and ability to adjust focus.
Position Type and Expected Hours of Work
This is a full-time position. Due to the nature of cybersecurity, hours of work are variable and may occasionally include overnight hours and/or weekends to support assessment windows or urgent findings.
Travel
No travel is expected for this position.
Qualifications
Minimum Qualifications
- 3+ years of experience in vulnerability assessment, IT security, or a related technical role.
- Demonstrated experience with vulnerability scanning tools and vulnerability management platforms.
- Working knowledge of internal and external vulnerability assessment processes.
- Bachelor's degree in Computer Science, Information Security, or a related field preferred, or equivalent professional experience.
Preferred Qualifications
- Industry certification such as CompTIA Security+, CySA+, or PenTest+.
- Prior exposure to 3rd-party penetration testing or assessment engagements.
- Familiarity with COTS platform patching processes and how vulnerability findings map to patch remediation workflows.
Other Duties
Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties, or responsibilities that are required of the employee for this job. Duties, responsibilities, and activities may change at any time with or without notice.