-
Vulnerability and Compliance Analyst
- BAE Systems (Rockville, MD)
-
Job Description
BAE Systems is seeking a Vulnerability and Compliance Analystto support our work as a prime contractor on a high-profile U.S. Navy weapon system.The ideal candidate is someone who is proactive, motivated, and able to work independently in various environments, including classified and unclassified settings
This position is responsible for
+ Leading the vulnerability management process, including vulnerabilities scanning, triaging, and prioritizing remediation efforts
+ Collaborating with system owners to understand their requirements
+ Developing and implementing a vulnerability management plan, including regular meetings with system owners to discuss vulnerabilities and remediation plans
+ Identifying and mitigating false positives and unexpected anomalies in vulnerability scans
+ Maintaining a Plan of Action and Milestone (POA&M) for outstanding vulnerabilities and tracking to closure.
+ Performing configuration analysis and developing/maintaining baseline documentation
+ Performing internal assessment for DFARS/CMMC compliance
+ Developing and Reviewing Policies, Procedures and Work-Instructions required to maintain the security posture of information systems supporting the contract
+ Participating in tabletop exercises and external audits
and the U.S. Navy s Strategic Systems Programs (SSP)
Our organization has supported the U.S. Navy s Strategic Systems Programs (SSP) continually since the program s inception in the 1950s. SSP developed the first sea-based, underwater-launched Strategic Weapon System (SWS), a defense system that is truly critical to our national security. For more than six decades, SSP has maintained and upgraded this weapon system and we have been there every step of the way. The sea-based SWS is the ultimate stealthy weapon system and is the first leg of the U.S. nuclear triad. With over 70% of our nation s nuclear arsenal its importance to maintaining world peace cannot be overstated. The development of Columbia, the most advanced nuclear-powered, nuclear-armed submarine ever designed, as well the next D5LE2 weapon system is under way and will begin to be rolled out over the next decade. The Navy projects this system to be operational through 2084, meaning the program will have a total life span of more than 120 years. This is a unique program and BAE Systems employees on this program understand they are part of an important legacy.
As a decades long sole source partner on multiple contracts on behalf of our customer, our program has remarkable stability and is concurrently experiencing significant growth. Combined, these factors provide ample opportunity for professional growth and development for capable and talented individuals on our team.
BAE Systems, Inc. is the wholly owned U.S. subsidiary of BAE Systems plc.
BAE Systems plc provides some of the world's most advanced, technology-led defense, aerospace, and security solutions. As one of the top ten defense contractors, we employ a skilled workforce of around 100,000 people in more than 40 countries. We develop, engineer, manufacture, and support products and systems to protect national security and keep people safe.
Required Education, Experience, & Skills
+ Bachelor s degree in information technology, Computer Science, or a related field
+ 2 years of experience in information security, IT, or a related field
+ Strong analytical and problem-solving skills
+ Excellent communication and interpersonal skills
+ Ability to work independently and as part of a team
+ Strong understanding of vulnerability management concepts and tools
Preferred Education, Experience, & Skills
+ Experience with vulnerability scanning tools
+ Familiarity with security frameworks and standards (e.g., NIST 800-53, DISA STIGs)
+ Knowledge of scripting languages (e.g., Python, PowerShell)
+ CompTIA Security or equivalent 8570/8140 approved IAT level 2 certification
Pay Information
Full-Time Salary Range: $77809 - $132275
Please note: This range is based on our market pay structures. However, individual salaries are determined by a variety of factors including, but not limited to: business considerations, local market conditions, and internal equity, as well as candidate qualifications, such as skills, education, and experience.
Employee Benefits: At BAE Systems, we support our employees in all aspects of their life, including their health and financial well-being. Regular employees scheduled to work 20 hours per week are offered: health, dental, and vision insurance; health savings accounts; a 401(k) savings plan; disability coverage; and life and accident insurance. We also have an employee assistance program, a legal plan, and other perks including discounts on things like home, auto, and pet insurance. Our leave programs include paid time off, paid holidays, as well as other types of leave, including paid parental, military, bereavement, and any applicable federal and state sick leave. Employees may participate in the company recognition program to receive monetary or non-monetary recognition awards. Other incentives may be available based on position level and/or job specifics.
Vulnerability and Compliance Analyst
117349BR
EEO Career Site Equal Opportunity Employer. Minorities . females . veterans . individuals with disabilities . sexual orientation . gender identity . gender expression
-