Cybersecurity SME - KEV/BOD Analysis; Pen-Test Governance
Hybrid Remote Remote with TDY, VA
Job Type
Full-time
Description

About QBE, LLC

QBE, LLC is a small business dedicated to delivering innovative technology, cybersecurity, and mission-support solutions to federal government customers. Our experienced professionals work closely with our customers to solve complex challenges, protect critical information, and support essential government missions.

At QBE, we turn the possible into the proven.


Overview

QBE, LLC is seeking a Cybersecurity SME - KEV/BOD Analysis; Pen-Test Governance to provide expert vulnerability risk analysis, federal directive support, and penetration-testing governance for NIH/OD-OIT.


This position is primarily remote but will require some TDY.


Responsibilities

• Analyze Known Exploited Vulnerabilities and applicable federal cybersecurity directives.

• Determine organizational impact and support prioritization of required remediation activities.

• Track compliance with vulnerability-related directives and remediation deadlines.

• Provide expert risk analysis for critical and actively exploited vulnerabilities.

• Develop reports, dashboards, and executive briefings on KEV and directive compliance.

• Establish governance processes for penetration testing activities.

• Review penetration-test scope, rules of engagement, methods, and deliverables.

• Track penetration-test findings through remediation and closure.

• Evaluate risk exceptions and compensating controls.

• Advise leadership on vulnerability risk and remediation priorities.

#qf

#qg


Requirements

Minimum Qualifications

• Associate degree in cybersecurity, information technology, computer science, information systems, business, communications, or a related field, or an additional two or more years of relevant experience in place of the degree requirement.

• At least 10 years of relevant experience aligned to the responsibilities of this position.

• Expert knowledge of vulnerability risk management and remediation processes.

• Experience analyzing high-impact vulnerabilities and federal cybersecurity directives.

• Experience overseeing or governing penetration-testing activities.

• Strong risk-analysis and executive communication skills.

• CompTIA Security+ certification.

• Certified in Risk and Information Systems Control (CRISC) certification.

• Ability to obtain and maintain the required federal background investigation, Public Trust determination, or security clearance associated with the position.


Preferred Qualifications

• Federal vulnerability management experience.

• Familiarity with CISA Known Exploited Vulnerabilities and Binding Operational Directives.

• Experience coordinating enterprise penetration testing.


Physical Requirements

• Ability to remain in a stationary position for extended periods while working at a computer.

• Ability to communicate effectively through virtual and in-person meetings.

• Ability to perform duties in an office, remote, or hybrid environment based on program requirements.

• Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of the position.


Equal Opportunity Employer

QBE, LLC is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to any characteristic protected by applicable federal, state, or local law.


The projected compensation range for this position is $115,000.00 - $130,000.00.  There are differentiating factors that can impact a final salary/hourly rate, including, but not limited to, Contract Wage Determination, relevant work experience, skills and competencies that align to the specified role, geographic location (for remote opportunities), education and certifications as well as Federal Government Contract Labor categories. In addition, QBE invests in its employees beyond just compensation. QBE's benefits offerings include, dependent upon position, Health Insurance, Life Insurance, Paid Time Off, Holiday Pay, short-term and long-term Disability, Retirement and Savings, Learning and Development opportunities, wellness programs as well as other optional benefit elections.