26 vulnerability management engineer jobs at 15 companies in Easton, MD
2mo
Save
Mark Applied
Hide
2mo
Vulnerability Researcher
Annapolis Junction, Maryland, United States
OnsiteFull Time
Intelliforce: Provides engineering and technical solutions for the intelligence community.
12+ YOETop Secret clearance with polygraph required; US citizen; degree and experience as listed; vulnerability research and reverse engineering experience.
ManTech: Provides technology solutions for defense and intelligence agencies.
7+ YOECurrent active TS/SCI with poly required; 7+ years position-specific experience; experience in vulnerability research and reverse engineering (IDA Pro, Ghidra, Binary Ninja, Radare, SysInternals, GDB, WinDBG); proficiency in Python, C/C++, Assembly; CNO capability development experience.
Lead Vulnerability Researcher ($285k+/year + Sign-On Bonus)
Linthicum, Maryland, United States
$285k-$300k/yrOnsiteFull Time
Two Six Technologies: Develops cybersecurity and data systems for national security missions.
4+ YOERequires a relevant degree and 4–10 years of experience, C/C++, Python, ISA, Linux, decompilers, fuzzers, debuggers, reverse engineering, and active TS/SCI clearance with polygraph.
NetSage: Delivering specialized cyber services to the U.S. federal government.
9+ YOE6+ MgmtTS/SCI with polygraph; 9+ years relevant experience (or B.S.+11 years, M.S.+9 years, or 15 years without degree); 6+ years systems engineering leadership; vulnerability assessment and Zero Trust experience.
Markon Solutions: Provides professional program and engineering services to federal agencies.
15+ YOE6+ MgmtBachelor's degree in STEM and 15+ years of systems engineering experience, including 6+ years leading teams; TS/SCI with polygraph, Zero Trust, cybersecurity assessment, vulnerability assessment, IV&V, and secure architecture experience required.
Zero Trust, Offensive Cyber Operations (OCO), Defensive Cyber Operations (DCO), Independent Verification and Validation (IV&V), Performance Work Statements (PWS), NIST SP 800-160, INCOSE
Washington Nationals: Professional Major League Baseball team based in Washington, D.C.
5+ YOE5+ years cybersecurity/identity experience, deep expertise in identity and access management, Zero Trust, security operations, vulnerability management; U.S. work authorization and successful background check required; strong communication and documentation skills.
ASRC Federal: Provides engineering and IT services to federal government agencies.
5+ YOE5–7 years vulnerability management experience, hands-on Tenable ACAS suite experience, active Secret clearance, 8570 IAM/IAT Level I certification (or examples), and bachelor’s in cybersecurity/IS or equivalent.
Specialized Infrastructure Services - ISSO Support Systems Engineer
Laurel or Jessup
$176k-$282k/yrOnsiteFull Time
Peraton: National security and mission-critical government technology services provider.
15+ YOEProvide ISSO support for information systems: maintain ATO, manage POA&Ms, vulnerability and account management, develop SSPs, perform security assessments, use XACTA; TS/SCI with polygraph and DoD8570 IAT Level 2+ required; ~15 years systems engineering experience.
Gormat: Provides cybersecurity and systems engineering services to government defense agencies
10+ YOETS/SCI with polygraph required. Degree in system engineering or related field with 10+ years (Master's) or 12+ years (Bachelor's) experience. Experience with C/C++, Python, Assembly, reverse engineering, and vulnerability analysis.
Peraton: Provides advanced technology and mission support for government agencies.
10+ YOEU.S. citizenship and ability to obtain/maintain Public Trust; 10+ years cybersecurity experience (degree/experience tradeoffs provided); expertise in security engineering, vulnerability assessment, continuous monitoring, risk management, and compliance with NIST/RMF/FISMA.
NIST SP 800-53, FISMA, RMF, CI/CD, Zero Trust, NAS
Senior Information Systems Security Engineer (ISSE)
Annapolis Junction, Maryland, United States
$150k-$210k/yrOnsiteFull Time
Amatriot Group: Provides IT consulting and mission-critical technology support services.
Design and implement enterprise security architecture, perform security engineering across SDLC, manage vulnerability programs, support incident response, and mentor junior staff. Active TS/SCI and DoD IAT Level III required.
NIST RMF, DoD STIGs, CIS benchmarks, Tenable Nessus, ACAS, Qualys, Splunk Enterprise, PowerShell, Bash, Python, Trellix ePO On-Prem, CyberArk, VMware vSphere, GitLab, Microsoft Windows Server, Red Hat Enterprise Linux, Ubuntu Linux, Ansible, AWS, Azure, Kubernetes
Dev Technology Group: Provides information technology services to federal government agencies.
15+ YOEBachelor's in IT/CS/cybersecurity required; 15+ years IT/cybersecurity experience; CISSP and CCSP required; US citizenship required; expertise in DevSecOps, Zero Trust, ATO/FedRAMP, vulnerability assessments, and secure architecture.
CACI InternationalNYSE: CACI: Provides information technology and engineering services for government agencies.
Active TS/SCI with polygraph, strong analytics development background, proficiency in Python, experience with system authorization, RMF, and vulnerability management; multi-year technical experience as specified by education.
CACINYSE: CACI: Provides information technology and professional services to government clients.
Active TS/SCI with Polygraph; strong analytics development background; proficiency in Python; experience with RMF, system authorization, and vulnerability management (e.g., Nessus); 4+ years experience typical depending on degree.
Markon: Provides professional services and management consulting for government agencies.
15+ YOE6+ MgmtBachelor's degree in STEM and 15+ years of systems engineering experience, including 6+ years leading teams; TS/SCI with polygraph, Zero Trust, cybersecurity assessment, vulnerability assessment, IV&V, and technical leadership experience required.
NIST SP 800-160, INCOSE, Performance Work Statements (PWS), Independent Verification and Validation (IV&V)
Perdue Farms: Producer of poultry, meat, and agricultural products.
7+ YOE7+ years in information security securing AI/ML or automation platforms; experience with SOC operations, threat hunting, vulnerability and certificate/PKI management; familiarity with ICS/OT and security frameworks.
Security Information and Event Management, Security Orchestration, Automation and Response, Endpoint Detection and Response, Network Detection and Response, Public Key Infrastructure (PKI)
Momentum Engineering: Provides engineering and technical services for national security missions.
14+ YOEActive Top Secret/SCI with NSA Full Scope Polygraph, 14+ years ISSE experience (or degree + experience), CISSP and DoD 8570 IASAE Level II compliance, experience with Tenable/Nessus, RMF/NIST/CNSS, cloud and vulnerability management.
Tenable Security Center, Nessus, Splunk, Microsoft Sentinel, Risk Management Framework (RMF), NIST Special Publications, Committee on National Security Systems (CNSS)