TDI (Tetrad Digital Integrity)

Vulnerability Analyst

TDI (Tetrad Digital Integrity)  •  $110k - $120k/yr  •  Arlington, VA (Onsite)  •  4 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Tetrad Digital Integrity (TDI) is a leading-edge cybersecurity firm with a mission to safeguard and protect our customers from increasing threats and vulnerabilities in this digital age.

TDI is seeking a Vulnerability Analyst to join the Compartmented Enterprise Services Office (CESO) effort. This program is establishing a modern secure web service (SWS) operation as part of a state-of-the-art, highly automated platform capable of supporting a rapidly expanding customer population. Apply today to become part of the Leidos team assisting CESO as it migrates to a high security cloud environment, providing vulnerability management, risk assessment, and compliance services that protect the integrity of the platform throughout its lifecycle.

Multiple positions are available, including day-shift opportunities in Arlington, VA, and night-shift opportunities in San Antonio, TX. All positions are fully onsite and require an active TS/SCI clearance.

RESPONSIBILITIES:

  • Responsible for meeting both regulatory (Legal and Mandated Requirements) and non-regulatory (Real-World Threat Reduction) compliance demands across the CESO environment.
  • Assist in the management and maintenance of the IAVA (Information Assurance Vulnerability Alerts) program for CESO systems.
  • Manage and enforce information security policies, and train and educate end-users on proper security practices.
  • Conduct security and risk assessments using established frameworks (e.g., NIST, RMF, Common Criteria), mitigating risk via security controls and testing and evaluation to certify and accredit commercial security products used within the CESO platform.
  • Develop, update, organize, maintain, and track RMF documentation using information obtained from the customer.
  • Ensure privacy of data throughout its lifecycle; perform vulnerability management (scanning, assessment, reporting, and mitigation verification), business continuity, and disaster recovery activities.
  • Coordinate with infrastructure, storage, database, and application teams to align vulnerability management activities with CESO's operational and compliance requirements.
  • Maintain documentation, operational procedures, and compliance reports supporting CESO's secure cloud migration.
  • Responsible for a combination of duties to protect information and maintain security controls across the CESO system, site, or program in order to reduce risk.

QUALIFICATIONS:

  • Candidate must currently have a TS/SCI with the ability to obtain and maintain a CI Poly.
  • DoDD 8140 compliant certification, at minimum IAT Level II (e.g., Security+ CE), at start.
  • Bachelor's degree and 2+ years of related IT security experience; additional experience, education, or training may be considered in lieu of degree.
  • Experience with the Defense Information Systems Agency (DISA) security model, controls, and authorization processes for standard computing systems and cloud computing environments across the Department of Defense.
  • Experience conducting activities associated with Information Assurance Vulnerability Alerts (IAVAs), including those issued by the Cybersecurity and Infrastructure Security Agency (CISA).
  • Experience creating and maintaining Information Assurance documentation, including Security Control Traceability Matrices (SCTMs), Risk Assessment Reports (RARs), Security Assessment Reports (SARs), and Plans of Action and Milestones (POA&Ms).
  • Experience with ACAS and SIEM tools.
  • Experience implementing application and hardware security settings in accordance with vendor and/or DISA best business practices.

PAY RANGE:

The anticipated salary range for this position is $110,000 - $120,000. This range is a good-faith estimate and not a guarantee of compensation. Final compensation will be based on factors including experience, education, skills, geographic location, internal equity, market data and applicable contract requirements, and may fall outside the posted range.

TDI does business with the federal government, which restricts employment to individuals who are either US citizens or lawful permanent residents of the United States.

“TDI is an Equal Opportunity Employer. Employment decisions are made based on individual qualifications, merit, and business needs. We do not discriminate in employment opportunities or practices based on race, color, religion, sex, or national origin, in accordance with applicable federal laws.”

TDI (Tetrad Digital Integrity)

About TDI (Tetrad Digital Integrity)

For over 20 years, TDI’s one and only passion has been delivering cybersecurity solutions to effectively manage the business of cyber. At the global vanguard of innovation, we created Cybersecurity Performance Management (CPM) and the industry-leading CPM platform, CnSight®. Combining CnSight® with our remarkable historical experience and our exceptional capabilities of cyber operations and compliance, we offer Managed Cybersecurity Performance, a first of its kind managed CPM offering. TDI’s CPM solutions mitigate risk, reduce ransomware, provide continuous compliance, improve cyber-ROI, and provide comprehensive instantaneous visibility into how an organization is performing against its cyber strategy, particularly for Boards of Directors.

CnSight® is the industry-leading Cybersecurity Performance Management (CPM) platform which mitigates risk, reduces ransomware, provides continuous compliance, improves cyber-ROI, and provides comprehensive instantaneous visibility into how an organization is performing against its cyber strategy, so executives and Boards may effectively manage the business of cybersecurity– the result: reduced stress, better performance, less cost, and a true understanding of cyber investment.

With CnSight® at its core, TDI’s Managed Cybersecurity Performance offering ensures strategic cyber goals are met to protect an organization’s investments, assets and reputation by reducing the risk of ransomware, lowering cyber insurance premiums, improving ROI, reducing legal and fiduciary liability, delivering actionable reporting to the Board and C-Suite, providing on-call advice, ensuring continuous compliance and providing subject matter expertise on the organization’s behalf in meeting with the C-Suite and the Board, dealing with auditors, and supporting budget decisions – the result: reduced stress, better performance, less cost, and a true understanding of cyber investment.

Industry
IT & Software
Company Size
51-200 employees
Headquarters
Washington, DC
Year Founded
2001
Social Media