What are the responsibilities and job description for the Junior Vulnerability & Exposure Analyst position at Maryland Department of Information Technology?
Introduction
The Department of Information Technology (DoIT) provides support to state agencies, the Executive Office of the Governor, the Governor’s coordinating offices, and a variety of independent agencies within the Executive Branch.
Striving to provide the highest level of customer service to its internal and external customers, DoIT supports Maryland’s agencies and commissions through its leadership and strategic direction for Information Technology and Telecommunications, establishing a long-range, target technology architecture, encouraging cross-agency collaboration, and advocating best practices for operations and project management.
***This is a contractual position, with limited benefits***
***All hires need to be eligible to work in the U.S., either as a U.S. Citizen or those who have a Permanent Resident or green card, as the state of Maryland does not have the ability to sponsor employees***
***Applicants are required to submit an up-to-date and accurate resume.
Main Purpose
The Vulnerability & Exposure Analyst is a cybersecurity professional responsible for identifying, assessing, and prioritizing vulnerabilities and exposures in the organization's systems, applications, and networks. This role is crucial for proactive risk reduction and improving the organization's security posture. Vulnerability and Exposures Analysts are generally differentiated into Junior, Mid-level, and Senior levels.
A Junior Vulnerability and Exposures Analyst is an entry-level cybersecurity position. Junior analysts work under close supervision focused on operating vulnerability scanning tools, reviewing scan results, and assisting with the initial triage of findings. They focus on learning and applying the fundamentals of the vulnerability management lifecycle.
Position Duties
A Junior Vulnerability & Exposure Analyst is responsible for the following tasks:
- Operate enterprise vulnerability scanning tools to conduct regular, scheduled, and ad-hoc scans of the organization's assets.
- Review and perform initial triage of vulnerability scan results, identifying high-risk findings and potential false positives.
- Correlate vulnerability data with asset inventory information to understand the context of findings.
- Assist in the creation of vulnerability reports for system owners and technical teams.
- Track the status of remediation efforts in the vulnerability management platform or ticketing system.
- Escalate vulnerabilities and exposures for further analysis and action as necessary based on observations.
- Support Incident Response teams during incident response engagements by providing analysis and data.
- Participate in post-incident activities and contribute to lessons learned to improve security operations.
- Contribute to the development and maintenance of Standard Operating Procedures (SOPs) and response playbooks.
- Monitor various sources of open-source and proprietary vulnerability information such as vendor advisories, Common Vulnerabilities and Exposures (CVEs), Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog, and cyber threat intelligence.
- Stay informed about the latest cybersecurity threats, vulnerabilities, and attack techniques to maintain awareness of the evolving threat landscape.
Minimum Qualifications
Experience: Four years of experience in threat hunting network security analysis, network traffic analysis, information security, information systems, information assurance, trouble shooting, security operations, cryptography, and cyber threat modeling.
Notes:
1. Candidates may substitute a bachelor’s degree in computer science, cybersecurity, information technology, software engineering, information systems, computer engineering or related field for up to two years of the required experience.
2. Candidates may substitute the “Education” requirement listed above, for a High School Diploma or possession of a High School Equivalency certificate and two additional years of experience as described above.
3. Candidates may substitute the “Experience” requirement listed above for a graduate level degree in computer science, cybersecurity, information technology, software engineering, information systems, computer engineering or related field from an accredited college or university.