Summary
Accenture Federal Services helps the U.S. federal government strengthen national security, public safety, civilian, defense, and military health missions through technology and ingenuity. The Security Engineer – Vulnerability Management Specialist will manage and enhance the vulnerability management program, assess and mitigate vulnerabilities across enterprise environments, and support compliance and Authority to Operate readiness. The role collaborates with IT, ISSOs, Controls Assessors, development teams, and security stakeholders to improve security processes and controls.
Responsibilities
- Manage and mature the organization’s vulnerability management program
- Identify, assess, and prioritize vulnerabilities across applications, networks, endpoints, cloud environments, and enterprise systems
- Collaborate with ISSOs and Controls Assessors to capture RMF artifacts and validate security control effectiveness
- Review, advise, and refine security Control Statements to ensure systems are hardened and accurately represented in assessment documentation
- Support compliance with federal frameworks including NIST 800‑53, FISMA, and SOX
- Implement best practices for vulnerability management, patching, configuration hardening, and risk reduction
- Assist in incident response activities involving exploited vulnerabilities, providing risk assessment and remediation guidance
- Establish repeatable vulnerability workflows and processes to support ATO readiness for new systems
- Communicate risk clearly to stakeholders and recommend effective mitigation strategies
- Contribute to the continuous improvement of security processes and controls
Skills
- 4–6 years of experience in vulnerability management or a related information security role
- Advanced knowledge of vulnerability management tools such as Tenable Nessus, Qualys, Rapid7, or OpenVAS
- Strong understanding of vulnerability scanning, assessment, and risk prioritization
- Familiarity with CVSS, NIST 800‑53, and OWASP Top 10
- Understanding of OS‑level vulnerabilities (Windows, Linux, macOS)
- Knowledge of core network protocols and components (TCP/IP, DNS, firewalls, routers, switches)
- Experience with Cloud Service Providers (AWS, Azure, GCP) and cloud‑native policies
- Experience configuring and working with Identity Providers (IdP)
- Experience with patch management tools and processes
- Basic understanding of compliance requirements such as FISMA and SOX
- Familiarity with NIST CSF, ISO 27001, CIS Controls
- Ability to assess vulnerabilities, identify risks, and support incident response
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field (or equivalent experience)
- U.S. Citizenship required
- Eligible to obtain a Public Trust security clearance
- Advanced skills in vulnerability exploitation and proof‑of‑concept (PoC) development
- Familiarity with exploit frameworks such as Metasploit
- Experience working with cloud security tools (AWS Inspector, Azure Security Center, GCP Security Command Center)
- Experience identifying and mitigating high‑impact vulnerabilities in complex environments
- Experience with configuration assessment tools such as SCAP or CIS‑CAT
- Knowledge of threat intelligence processes and correlating vulnerabilities with real‑world threats
- Understanding of threat modeling and attack surface analysis
- Experience with SIEM tools (Splunk, QRadar) and integrating them with vulnerability processes
- Ability to analyze logs, alerts, and correlation events
- GIAC Certified Vulnerability Analyst (GCVA)
- Offensive Security Certified Professional (OSCP)
- CISSP
- CISM
Qualifications
Must Haves
- 4–6 years of experience in vulnerability management or a related information security role
- Advanced knowledge of vulnerability management tools such as Tenable Nessus, Qualys, Rapid7, or OpenVAS
- Strong understanding of vulnerability scanning, assessment, and risk prioritization
- Familiarity with CVSS, NIST 800‑53, and OWASP Top 10
- Understanding of OS‑level vulnerabilities (Windows, Linux, macOS)
- Knowledge of core network protocols and components (TCP/IP, DNS, firewalls, routers, switches)
- Experience with Cloud Service Providers (AWS, Azure, GCP) and cloud‑native policies
- Experience configuring and working with Identity Providers (IdP)
- Experience with patch management tools and processes
- Basic understanding of compliance requirements such as FISMA and SOX
- Familiarity with NIST CSF, ISO 27001, CIS Controls
- Ability to assess vulnerabilities, identify risks, and support incident response
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field (or equivalent experience)
- U.S. Citizenship required
- Eligible to obtain a Public Trust security clearance
Nice to Haves
- Advanced skills in vulnerability exploitation and proof‑of‑concept (PoC) development
- Familiarity with exploit frameworks such as Metasploit
- Experience working with cloud security tools (AWS Inspector, Azure Security Center, GCP Security Command Center)
- Experience identifying and mitigating high‑impact vulnerabilities in complex environments
- Experience with configuration assessment tools such as SCAP or CIS‑CAT
- Knowledge of threat intelligence processes and correlating vulnerabilities with real‑world threats
- Understanding of threat modeling and attack surface analysis
- Experience with SIEM tools (Splunk, QRadar) and integrating them with vulnerability processes
- Ability to analyze logs, alerts, and correlation events
- GIAC Certified Vulnerability Analyst (GCVA)
- Offensive Security Certified Professional (OSCP)
- CISSP
- CISM
Benefits
- Hands-on experience
- Certifications
- Industry training