Full-Time

IT Security Vulnerability Specialist

Updated on 9/4/2026

OCT Consulting

OCT Consulting

Compensation Overview

$110k - $130k/yr

No H1B Sponsorship

Suitland-Silver Hill, MD, USA

Hybrid

At least three days per week on-site in Suitland, Maryland.

US Citizenship, US Top Secret Clearance Required

Bachelor's

Category
Cybersecurity (1)
Required Skills
Incident Response
Vulnerability Analysis
Cryptography
Excel/Numbers/Sheets
Requirements
  • At least 7 years of experience supporting Authorization and Accreditation.
  • Proficiency in all steps of the National Institute of Standards and Technology Risk Management Framework.
  • Knowledge of National Institute of Standards and Technology Special Publications 800-53 and 800-53A.
  • A bachelor's degree or equivalent experience.
  • In-depth understanding and hands-on experience with multiple vulnerability scanning platforms, including scanning with Security Technical Implementation Guides and Center for Internet Security benchmarks.
  • Proficiency with Microsoft Excel.
  • A related industry certification such as GIAC GEVA, CASP, CAP, CISSP, CISM, GSEC, GMON, or Security+.
  • U.S. citizenship.
  • A Secret security clearance.
Responsibilities
  • Lead and drive remediation efforts within a government environment to improve the efficiency of vulnerability management processes.
  • Articulate risk and impact to product, engineering, and business leaders, conveying the urgency and need to remediate vulnerabilities commensurate with enterprise risk.
  • Conduct internal vulnerability assessments and vulnerability analysis of external vulnerability reports, zero-day announcements, and security incidents.
  • Monitor and maintain vulnerability and code-scanning, security-configuration, and other vulnerability-management tools.
  • Develop, maintain, and recommend security policies, procedures, and standards related to vulnerability management.
  • Participate in security audits and assessments to ensure compliance with regulatory requirements and industry standards.
  • Perform vulnerability reproduction and fix validation when required.
  • Maintain knowledge of ongoing security threats, remediations, and operational best practices in threat and vulnerability management.
  • Create reports and dashboards to drive vulnerability remediation efforts and process improvements.
  • Drive regular operational and business reviews for threat and vulnerability management activities.
  • Support other security operations activities as needed, including detection and response.
  • Participate in security incident response.
  • Review, evaluate, refine, release, and maintain Configuration Management Plans in support of program requirements.
  • Provide recommendations and guidance for identifying Configuration Items and Computer Software Configuration Items.
  • Provide guidance and expertise in establishing, monitoring, and maintaining configuration baselines on assigned programs.
  • Monitor effectiveness and compliance on assigned programs.

Company Size

N/A

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A