graphic including the slogan "together we can make an impact."
STR Logo

STR

Information Systems Security Engineer (ISSE) - Vulnerability Analyst

Posted 2 Hours Ago
Be an Early Applicant
Easy Apply
In-Office
Woburn, MA
105K-145K Annually
Junior
Easy Apply
In-Office
Woburn, MA
105K-145K Annually
Junior
Manage vulnerability lifecycle for classified networks: track IAVA advisories, perform scanning and patch testing, produce impact assessments and metrics, support RMF continuous monitoring, and assist in POA&M remediation and security inspections.
The summary above was generated by AI

About the Team:

The Classified Cyber Security team at STR is comprised of highly skilled professionals who are responsible for maintaining compliance IAW with Government protocol and directives. 

The Classified Cybersecurity (CCS) team consists of a collaborative group of ISSM’s, ISSO’s, and ISSE’s who are passionate about national security that take great pride in maintaining confidentiality, integrity, and availability of our Information Systems and enable execution of STRs portfolio of programs across a vast customer base. 

The Role:

STR has an exciting opportunity for a cybersecurity professional to join our established Cybersecurity/Risk Management Framework (RMF) program as a key contributor for classified programs.

In this dynamic position, you will interface and collaborate with other Cybersecurity professionals (ISSMs, ISSOs, ISSEs), Security professionals (CPSOs, FSOs), and System Administrators from our Classified Information Technology (CIT) organization.  The role will focus on Vulnerability Management across STR’s classified computer networks. This includes managing configuration changes to STR's baseline software and hardware, supporting security architecture improvements, and patch process for current and future technologies.  The ideal candidate is expected to bring strong technical skills to enhance STR Vulnerability Management processes, along with a demonstrated eagerness to learn and develop within the classified lab ISSE function.

 Please note: This is an onsite role and does not offer remote or hybrid work options.

Responsibilities:

  • Review, track, and manage IA Vulnerability (IAVA) announcements (e.g., US-CERT, CISA, vendor alerts, etc.) applicable to STR’s classified networks, ensuring they are communicated to stakeholders and tracked to closure.
  • Perform vulnerability/compliance scanning and remediation tracking.
  • Perform monthly patch testing for all classified network supported operating systems, applications, and hardware (i.e. firmware, BIOS, appliances – switch, firewall, etc.).
  • Prepare System Impact Assessments from the monthly patch testing for communication to the Classified Network Enterprise Configuration Control Board.
  • Prepare and provide metrics on vulnerability status, patch compliance, and the overall risk posture of the various classified networks.
  • Proactively identify potential improvements to the patching processes primarily for 3rd party vendors and firmware updates.
  • Assist ISSMs, ISSOs, ISSEs in monitoring and resolving Plan of Action and Milestones (POA&M) to mitigate system vulnerabilities.
  • Conduct reviews and technical inspections to identify and mitigate potential security weaknesses, ensuring all security features are implemented and functional.
  • Support the completion of Continuous Monitoring requirements in accordance with RMF and NIST SP800-53 standards.
  • Perform other tasks as assigned by the manager.

Who You Are:

  • Security Clearance: Active Secret security clearance with the ability and willingness to obtain Top Secret, SCI, and/or SAP access (U.S. citizenship required).
  • Experience:
    • 2-3 years of hands-on technical experience in Information Assurance/Cyber Engineering or System Administration in the Defense Industrial Base (DIB)
    • Experience with Windows Server Update Services (WSUS) and Linux patching
  • Certification: Minimum of a DoD 8140/8570 IAT Level II certification (Security+) with the willingness and ability to obtain Level III (CISSP, CISM).
  • Knowledge: Knowledge of NIST SP800-53 control implementation and assessment, looking to learn and advance in Cybersecurity field.
  • Familiarity: Knowledge of the DCSA Authorization and Assessment Process Manual/Guide (DAAPM/DAAG) and the Joint Special Access Implementation Guide (JSIG).
  • Technical Skills:
    • Configuration, certification, and auditing/analysis of Windows/Linux operating systems and system virtualization in peer-to-peer, LAN & WAN networks.
    • Using IA vulnerability/compliance scanning tools (e.g. NMap, ACAS, Nessus, Security Content Automation Protocol (SCAP)).
    • Familiarity with scripting in Windows (PowerShell) and Linux (Bash, Ansible) to enhance deployment of patches to systems.
  • Attributes: Excellent communication skills, detail-oriented, self-starter with a focus on understanding STR CCS and CIT processes and procedures. A desire for continuous improvement while working in a team environment and the ability to handle multiple fast-changing priorities/projects effectively. Well-organized, with the ability to track multiple issues and establish processes to assist the team in tracking items to closure.

Pay Information
Full-Time Salary Range: $105,000-$145,000

The salary range listed is based on external market data. Offers are based on factors, such as but not limited to, the candidate’s experience, education, training, key skills/critical skills, security clearances, and prevailing market and business conditions.


STR is a growing technology company with locations near Boston, MA, Arlington, VA, near Dayton, OH, Melbourne, FL, and Carlsbad, CA. We specialize in advanced research and development for defense, intelligence, and national security in: cyber; next generation sensors, radar, sonar, communications, and electronic warfare; and artificial intelligence algorithms and analytics to make sense of the complexity that is exploding around us.

STR is committed to creating a collaborative learning environment that supports deep technical understanding and recognizes the contributions and achievements of all team members. Our work is challenging, and we go home at night knowing that we pushed the envelope of technology and made the world safer.

STR is not just any company. Our people, culture, and attitude along with their unique set of skills, experiences, and perspectives put us on a trajectory to change the world. We can't do it alone, though - we need fellow trailblazers. If you are one, join our team and help to keep our society safe! Visit us at www.str.us for more info.


STR is an equal opportunity employer. We are fully dedicated to hiring the most qualified candidate regardless of race, color, religion, sex (including gender identity, sexual orientation and pregnancy), marital status, national origin, age, veteran status, disability, genetic information or any other characteristic protected by federal, state or local laws.

If you need a reasonable accommodation for any portion of the employment process, email us at [email protected] and provide your contact info.

Pursuant to applicable federal law and regulations, positions at STR require employees to obtain national security clearances and satisfy the requirements for compliance with export control and other applicable laws.

Top Skills

Windows Server,Linux,Windows Server Update Services (Wsus),Nmap,Acas,Nessus,Scap,Powershell,Bash,Ansible,System Virtualization,Rmf,Nist Sp800-53,Daapm/Daag,Jsig
HQ

STR Woburn, Massachusetts, USA Office

600 W Cummings Park, Woburn, MA, United States, 01801

Similar Jobs at STR

Yesterday
Easy Apply
In-Office
Woburn, MA, USA
Easy Apply
158K-218K Annually
Junior
158K-218K Annually
Junior
Machine Learning • Security • Software • Analytics • Defense
Develop and implement target tracking and prediction algorithms (e.g., MHT) in C++; design and run simulations and Monte Carlo experiments; perform performance analysis and verification; collaborate with multidisciplinary teams and customers; support system simulation and data analysis; obtain and maintain required security clearance.
Top Skills: C++,Python,Matlab,Git,Linux,Anaconda,Docker,Numpy,Scipy,Pandas,Matplotlib,Multiple Hypothesis Tracking (Mht),Monte Carlo Methods,Data Structures
Yesterday
Easy Apply
In-Office
Woburn, MA, USA
Easy Apply
134K-184K Annually
Senior level
134K-184K Annually
Senior level
Machine Learning • Security • Software • Analytics • Defense
Develop and implement target-tracking and prediction algorithms (e.g., MHT), design and run experiments and simulations, analyze performance, collaborate with multidisciplinary teams, and support customer interactions onsite in Woburn, MA.
Top Skills: C++,Python,Matlab,Git,Linux,Anaconda,Docker,Numpy,Scipy,Pandas,Matplotlib,Multiple Hypothesis Tracking,Monte Carlo Methods,Data Structures,Systems Simulation
Yesterday
Easy Apply
In-Office
Woburn, MA, USA
Easy Apply
120K-165K Annually
Expert/Leader
120K-165K Annually
Expert/Leader
Machine Learning • Security • Software • Analytics • Defense
Lead development and maintenance of technical documentation for defense R&D programs. Write and edit reports, test plans, specifications, proposals, and SOWs; ensure compliance with DoD standards; manage version control and document configuration; support design and test reviews; collaborate with engineers and program managers to ensure accuracy and clarity.
Top Skills: Adaptive Signal ProcessingAi/MlConfiguration ManagementDidsDod StandardsExcelMicrosoft PowerpointMicrosoft WordMil-StdsOpen ArchitectureSignal ProcessingVersion Control

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account