JOBSEARCHER

Information Systems Security Engineer - Level 1

Job Description Maintain and optimize the Tenable Security Center infrastructure. Conduct regular security patching, assessments and scans on Linux Security Center servers using Tenable Nessus. Mitigate STIGS/Vulnerabilities on Tenable Linux Security Center Servers and Windows/Linux Nessus Scanning Servers. Install and update Tenable Nessus Software on Linux/Windows Scanning Servers. Install and update Tenable Security Center Software on Linux Servers. Configure and fine-tune scanning policies and asset lists to ensure thorough vulnerability coverage. Keep abreast of the latest Tenable Security Center features and updates. Perform regular vulnerability assessments of multiple device types and Operating Systems using Tenable Security Center. Utilize Nessus Scanning Tool to identify vulnerabilities across customer assets on a Continuous Monitoring basis. Review Nessus/ACAS scan results and provide direction where required. Recognizes potential, successful, and unsuccessful scan results for efficiency in reporting compromises thorough reviews and analyses of relevant event detail and summary information. Analyze scan results and generate comprehensive vulnerability reports. Monitor and track vulnerability remediation progress. Collaborate with ISS and other teams to ensure timely vulnerability remediation. Communicate effectively with stakeholders about the security posture and potential risks. Prepare and deliver clear and concise reports to management and stakeholders. Maintain accurate records of security incidents and vulnerabilities , Required Skills Familiarity with DISA STIGs, Tenable Audit files, and / or CIS Benchmarks Hands-on operational experience with enterprise vulnerability management and scanning solutions, such as Tenable Knowledge of system and application security threats and vulnerabilities Working knowledge of networking, Linux/Unix, Windows administration, patch deployment and system configuration Certs: IAT Level 2 (CEH, CompTIA Security + CE) BS and 7 years exp OR HS and 11 years of exp , Desired Skills In-depth knowledge of vulnerability assessment methodologies, tools, and best practices Self-starter, ability to work effectively both independently and as part of a team including the ability and desire to own every aspect of a task from start to finish Strong analytical and problem-solving abilities, with a keen attention to detail , About Castello Systems, Inc. At Castello Systems, we are focused on delivering solutions. One way we do this is through the integration of COTS products into our customer's enterprise. We are successful because we are experts in the tools we integrate and are experts in the intricacies of our customer’s enterprise. Many of our peers fail because they are not able to bring these two components together. When Castello Systems is brought in, our folks have access to all the resources across the company and through our partnerships with COTS vendors. When you have one of us, you have all of us. Castello Systems prefers completion based contracts. This gives us the flexibility to bring to bear the right level of expertise and when needed to deliver. Castello Systems specialize in architecting, implementing, and executing Enterprise Management through the use of industry leading technologies such as OpenText Software, Splunk, and Elastic Stack.