Job Title: Cyber Command Vulnerability Management Specialist
Location: Brooklyn, NY 11201 (Hybrid)
Duration: 24 Months
Job Description:
We are seeking an experienced and highly skilled Vulnerability Management Specialist to join a cybersecurity team for a long-term engagement. The ideal candidate will bring deep technical expertise in vulnerability assessments, scripting, and security analysis. This role will support the design, implementation, and enhancement of a vulnerability management program, with a focus on infrastructure scanning and risk analysis using Rapid7.
Research, analyze, and provide briefings on vulnerabilities (CVEs, CVSS, vector strings, etc.), threat intelligence, and mitigation strategies.
Design, build, and maintain Rapid7 vulnerability scanning infrastructure.
Manage and conduct vulnerability scans across networks using Rapid7.
Perform deep-dive analysis and generate reports/dashboards to assess and prioritize risks.
Develop and implement risk mitigation strategies and remediation plans.
Create automation scripts using Python, PowerShell, etc., to streamline vulnerability management.
Prepare and deliver technical briefings and reports to internal teams and stakeholders.
Travel within NYC as needed for project requirements.
Minimum 8 years of experience in cybersecurity, with strong expertise in:
Vulnerability management tools and assessments
Attack surface management
Security risk analysis
In-depth knowledge of CVE, CVSS, NVD, MITRE ATT&CK, and threat vectors.
Hands-on experience with Rapid7 (infrastructure design, scanning, dashboards, analysis).
Strong scripting experience with Python, PowerShell, or similar for automation.
Proficient in Excel for data analysis (VLOOKUP, Pivot Tables, etc.).
Proven ability to evaluate vulnerabilities, assess impact, and execute remediation plans.
Strong communication skills for presenting findings and recommendations.
Experience communicating technical information to diverse stakeholders.
Familiarity with the threat landscape, TTPs, and Cyber Command initiatives.
Knowledge of security best practices (NIST, CIS, etc.).
Experience with Tableau for visual reporting.
Background in firewall technologies, IDS/IPS, VPNs, proxies, and secure network design.
Familiarity with multi-platform environments: Windows, Linux, VMware, Cisco, Mobile OS.
Understanding of cryptography, encryption, encoding, and hashing.
Ability to interpret cybersecurity documentation and technical procedures.
Relevant certifications such as CISSP, GSEC, GCIA, GCIH, CEH, CWAPT are highly preferred.