Job Description
- Drive vulnerability remediation with engineering teams that support M365 cloud services such as Exchange, SharePoint, and Microsoft Teams.
- Evaluate compliance with vulnerability remediation timeframe requirements and if requirements are not being met, identify areas of improvement.
- Provide evidence of vulnerability remediation compliance and residual risk to M365 customers monthly and with regulators annually during compliance audits.
NOTE: The successful candidate must have an active U.S. Government Top Secret Clearance with access to Sensitive Compartmented Information (SCI) based on a Full Scope Polygraph.
- Work with vulnerability scanning technology such as secure baseline scanning that provides large amounts of data in hyperscale environments to manipulate, prioritize, and report on large quantities of vulnerability information.
- Reviewing and approving exceptions when the vulnerability scanner finds false positives, or when service engineers have a business need to not resolve a vulnerability if the risk is sufficiently mitigated
- Performing data analysis on large sets of data to help provide service engineers with insights needed to perform effective vulnerability remediation.
- Triaging reports of problems with the platform to identify problems and either assist in resolution or bring the issue to the attention of the development team that supports the platform.
- Create and review monthly customer reports including plans of action, mitigation milestones, risk evaluations.
- Providing an overview of the platform, and evidence from the platform to customers and auditors at least yearly. Be able to describe in detail how vulnerability management reporting complies with all FedRAMP and related controls, including but not limited to sections IA and CM.
- Identifying gaps in process or technology, developing a plan for resolution, soliciting feedback from peers and management, receiving buy-off from stakeholders, and driving the necessary improvements to completion.
Clearance Verification: This position requires successful verification of the stated security clearance to meet federal government customer requirements. You will be asked to provide clearance verification information prior to an offer of employment.
We are looking for an optimistic and positive security expert who focuses on what is possible and does not get stuck with what is wrong. We need someone who is pragmatic and who can accept (and is excited) that each day brings new challenges. Because of the scope and nature of this program, ambiguity is everywhere. You must be comfortable working with ambiguity and be comfortable making decisions without perfect information. We are at the start of long journey, so we need someone who can prioritize, focus, and get work done!
We are looking for someone with:
- 5+ years in security operations or security control design/implementation
- 5+ years' experience supporting vulnerability management scanning, reporting and remediation.
- 3+ years' experience implementing and operating vulnerability management reporting in an environment that aligns to FISMA, FedRAMP High, and NIS 800-53, among others.
- Experience with Security Technical Implementation Guide (STIG) standards, including best practices in a cleared environment.
- 5+ years working in the US Federal Government space (preferably in the Defense or Intelligence space)
- 3+ years of Program Management experience
- 3+ years of data analysis experience using query languages such as SQL/Kusto, scripting languages (Powershell, Python, etc), and tools such as Excel
- The ability to learn new tools and technologies
- Demonstrated ability to use data to influence & drive decisions
- BS/MS in computer science or equivalent experience
- Stellar cross group collaboration (soft skills)
- Ability to work independently in a dynamic mission-critical environments
- Previous experience with compliance certifications and audits would be helpful (FISMA/FedRAMP)
#M365Core #EnterpriseCloud #M365Trust
Benefits/perks listed below may vary depending on the nature of your employment with Microsoft and the country where you work.
Date Posted
11/10/2022
Views
5
Similar Jobs
Senior Technical Project Manager - Second Order Effects
Views in the last 30 days - 0
Second Order Effects SOE is a engineering consulting firm that transforms uncertainty into functional hardware and software With 50 employees in offic...
View DetailsProduct Manager - AI Based Developer Tools - NVIDIA
Views in the last 30 days - 0
NVIDIA is looking to hire a technical and creative Product Manager to pioneer the next generation of Nsight AI based Developer Tools The role involves...
View DetailsSupply Chain Planning Manager (Starlink) - SpaceX
Views in the last 30 days - 0
SpaceX is a company that aims to make life on Mars possible by developing a low latency broadband internet system using a constellation of low Earth o...
View DetailsSenior Software Engineer, Networking Software - NVIDIA
Views in the last 30 days - 0
NVIDIAs platforms have made significant impacts in AI and SoftwareDefined Networking with widespread use across leading academic institutions startups...
View DetailsSoftware Engineer II, Graphics/Vulkan - DigitalFish
Views in the last 30 days - 0
DigitalFish is seeking a Software Engineer II Graphics to join their dynamic team The ideal candidate will have experience in realtime graphics and ma...
View DetailsSr. RF Silicon Software Engineer (Starlink) - SpaceX
Views in the last 30 days - 0
SpaceX is actively developing technologies to make human life on Mars possible and deploying Starlink the worlds largest satellite constellation provi...
View Details