Provide support for the Board’s vulnerability management program that includes but is not limited to the following tasks.
COMPENSATION: $50 to $60 per hour
CERTIFICATIONS: Certified Information Systems Security Professional (CISSP), GIAC Enterprise Vulnerability Assessor (GEVA) or Equivalent.
Responsibilities
- Create, configure, and execute daily and weekly credentialed and non-credentialed vulnerability scans of Board workstations, servers, and network devices.
- Evaluate the risk of all identified vulnerabilities and prepare remediation instructions for system administrators.
- Generate reports to measure the Board’s progress in meeting vulnerability remediation targets.
- Monitor the Board’s compliance with BOD 22-01 to include tracking Board vulnerabilities against CISA’s catalog of known exploited vulnerabilities.
- Manage and administer the Board’s vulnerability management systems.
- Conduct cybersecurity gap analyses to identify potential vulnerabilities in Board systems and networks.
- Collaborate with key stakeholders to assess, prioritize, and develop actionable pans to address the discovered gaps.
Qualifications
- At least five years of experience performing the functions associated with this labor category.
- Experience with security technologies, including vulnerability scanners, and SIEM solutions.
- Familiarity with relevant industry standards and regulations.
- Experience identifying and developing mitigation strategies.
- Experience analyzing data and identifying vulnerabilities.
- Experience building consensus around vulnerability management policies and procedures.
- Experience conducting security gap analyses to identify potential vulnerabilities in Board systems and networks.
- Experience collaborating with key stakeholders to assess, prioritize, and develop actionable plans to address the discovered gaps