Sobre esta vaga de Security Engineer - Vulnerability Management na Accenture Federal Services
The work
As a Security Engineer – Vulnerability Management Specialist, you will be responsible for managing and enhancing the organization’s vulnerability management program and supporting IT systems in achieving compliance necessary to pass formal Controls Assessments. You will identify, assess, prioritize, and mitigate security vulnerabilities across systems, networks, cloud platforms, and applications.
This role requires close collaboration with IT, ISSOs, Controls Assessors, development teams, and security stakeholders to strengthen the organization’s security posture and ensure alignment with federal and industry standards.
You will support the collection and validation of RMF artifacts, review and refine Control Statements for accuracy, ensure systems are properly hardened, and verify that assessor documentation reflects the true vulnerability state of evaluated systems. Additionally, you will enable continuous improvement by establishing repeatable processes that help new systems achieve Authority to Operate (ATO) readiness.
Key responsibilities:
- Manage and mature the organization’s vulnerability management program
- Identify, assess, and prioritize vulnerabilities across applications, networks, endpoints, cloud environments, and enterprise systems
- Collaborate with ISSOs and Controls Assessors to capture RMF artifacts and validate security control effectiveness
- Review, advise, and refine security Control Statements to ensure systems are hardened and accurately represented in assessment documentation
- Support compliance with federal frameworks including NIST 800‑53, FISMA, and SOX
- Implement best practices for vulnerability management, patching, configuration hardening, and risk reduction
- Assist in incident response activities involving exploited vulnerabilities, providing risk assessment and remediation guidance
- Establish repeatable vulnerability workflows and processes to support ATO readiness for new systems
- Communicate risk clearly to stakeholders and recommend effective mitigation strategies
- Contribute to the continuous improvement of security processes and controls
Here’s what you need:
- 4–6 years of experience in vulnerability management or a related information security role
- Advanced knowledge of vulnerability management tools such as Tenable Nessus, Qualys, Rapid7, or OpenVAS
- Strong understanding of vulnerability scanning, assessment, and risk prioritization
- Familiarity with CVSS, NIST 800‑53, and OWASP Top 10
- Understanding of OS‑level vulnerabilities (Windows, Linux, macOS)
- Knowledge of core network protocols and components (TCP/IP, DNS, firewalls, routers, switches)
- Experience with Cloud Service Providers (AWS, Azure, GCP) and cloud‑native policies
- Experience configuring and working with Identity Providers (IdP)
- Experience with patch management tools and processes
- Basic understanding of compliance requirements such as FISMA and SOX
- Familiarity with NIST CSF, ISO 27001, CIS Controls
- Ability to assess vulnerabilities, identify risks, and support incident response
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field (or equivalent experience)
Preferred qualifications:
- Advanced skills in vulnerability exploitation and proof‑of‑concept (PoC) development
- Familiarity with exploit frameworks such as Metasploit
- Experience working with cloud security tools (AWS Inspector, Azure Security Center, GCP Security Command Center)
- Experience identifying and mitigating high‑impact vulnerabilities in complex environments
- Experience with configuration assessment tools such as SCAP or CIS‑CAT
- Knowledge of threat intelligence processes and correlating vulnerabilities with real‑world threats
- Understanding of threat modeling and attack surface analysis
- Experience with SIEM tools (Splunk, QRadar) and integrating them with vulnerability processes
- Ability to analyze logs, alerts, and correlation events
Bonus Points:
– GIAC Certified Vulnerability Analyst (GCVA)
– Offensive Security Certified Professional (OSCP)
– CISSP
– CISM
Eligibility requirements:
- U.S. Citizenship required
- Eligible to obtain a Public Trust security clearance
As required by local law, Accenture Federal Services provides reasonable ranges of compensation for hired roles based on labor costs in the states of California, Colorado, Hawaii, Illinois, Maine, Maryland, Massachusetts, Minnesota, New Jersey, New York, Vermont, Virginia, Washington, and the District of Columbia, and the city of Cleveland. The base pay range for this position in these locations is shown below. Compensation for roles at Accenture Federal Services varies depending on a wide array of factors, including but not limited to office location, role, skill set, and level of experience. Accenture Federal Services offers a wide variety of benefits. You can find more information on benefits here. We accept applications on an on-going basis and there is no fixed deadline to apply.