Information Systems Security Engineer - Level 1
Job Description
Maintain and optimize the Tenable Security Center infrastructure.
Conduct regular security patching, assessments and scans on Linux Security Center servers using
Tenable Nessus.
Mitigate STIGS/Vulnerabilities on Tenable Linux Security Center Servers and Windows/Linux
Nessus Scanning Servers.
Install and update Tenable Nessus Software on Linux/Windows Scanning Servers.
Install and update Tenable Security Center Software on Linux Servers.
Configure and fine-tune scanning policies and asset lists to ensure thorough vulnerability
coverage.
Keep abreast of the latest Tenable Security Center features and updates.
Perform regular vulnerability assessments of multiple device types and Operating Systems using
Tenable Security Center.
Utilize Nessus Scanning Tool to identify vulnerabilities across customer assets on a Continuous
Monitoring basis.
Review Nessus/ACAS scan results and provide direction where required.
Recognizes potential, successful, and unsuccessful scan results for efficiency in reporting
compromises thorough reviews and analyses of relevant event detail and summary information.
Analyze scan results and generate comprehensive vulnerability reports.
Monitor and track vulnerability remediation progress.
Collaborate with ISS and other teams to ensure timely vulnerability remediation.
Communicate effectively with stakeholders about the security posture and potential risks.
Prepare and deliver clear and concise reports to management and stakeholders.
Maintain accurate records of security incidents and vulnerabilities
,
Required Skills
Familiarity with DISA STIGs, Tenable Audit files, and / or CIS Benchmarks
Hands-on operational experience with enterprise vulnerability management and scanning solutions,
such as Tenable
Knowledge of system and application security threats and vulnerabilities
Working knowledge of networking, Linux/Unix, Windows administration, patch deployment and
system configuration
Certs: IAT Level 2 (CEH, CompTIA Security + CE)
BS and 7 years exp OR HS and 11 years of exp
,
Desired Skills
In-depth knowledge of vulnerability assessment methodologies, tools, and best practices
Self-starter, ability to work effectively both independently and as part of a team including the ability
and desire to own every aspect of a task from start to finish
Strong analytical and problem-solving abilities, with a keen attention to detail
,
About Castello Systems, Inc.
At Castello Systems, we are focused on delivering solutions. One way we do this is through the integration of COTS products into our customer's enterprise. We are successful because we are experts in the tools we integrate and are experts in the intricacies of our customer’s enterprise. Many of our peers fail because they are not able to bring these two components together. When Castello Systems is brought in, our folks have access to all the resources across the company and through our partnerships with COTS vendors. When you have one of us, you have all of us. Castello Systems prefers completion based contracts. This gives us the flexibility to bring to bear the right level of expertise and when needed to deliver. Castello Systems specialize in architecting, implementing, and executing Enterprise Management through the use of industry leading technologies such as OpenText Software, Splunk, and Elastic Stack.