Security Engineer - Vulnerability Management
accenturefederalservices
Job at a glance
At Accenture Federal Services, nothing matters more than helping the US federal government make the nation stronger and safer and life better for people. Our 13,000+ people are united in a shared purpose to pursue the limitless potential of technology and ingenuity for clients across defense, national security, public safety, civilian, and military health organizations. Join Accenture Federal Services, a technology company within global Accenture.
Recognized as a Glassdoor Top 100 Best Place to Work, we offer a collaborative and caring community where you feel like you belong and are empowered to grow, learn and thrive through hands-on experience, certifications, industry training and more. Join us to drive positive, lasting change that moves missions and the government forward! The work As a Security Engineer – Vulnerability Management Specialist, you will be responsible for managing and enhancing the organization’s vulnerability management program and supporting IT systems in achieving compliance necessary to pass formal Controls Assessments.
You will identify, assess, prioritize, and mitigate security vulnerabilities across systems, networks, cloud platforms, and applications. This role requires close collaboration with IT, ISSOs, Controls Assessors, development teams, and security stakeholders to strengthen the organization’s security posture and ensure alignment with federal and industry standards. You will support the collection and validation of RMF artifacts, review and refine Control Statements for accuracy, ensure systems are properly hardened, and verify that assessor documentation reflects the true vulnerability state of evaluated systems.
Additionally, you will enable continuous improvement by establishing repeatable processes that help new systems achieve Authority to Operate (ATO) readiness. Key responsibilities: Manage and mature the organization’s vulnerability management program Identify, assess, and prioritize vulnerabilities across applications, networks, endpoints, cloud environments, and enterprise systems Collaborate with ISSOs and Controls Assessors to capture RMF artifacts and validate security control effectiveness Review, advise, and refine security Control Statements to ensure systems are hardened and accurately represented in assessment documentation Support compliance with federal frameworks including NIST 800‑53, FISMA, and SOX Implement best practices for vulnerability management, patching, configuration hardening, and risk reduction Assist in incident response activities involving exploited vulnerabilities, providing risk assessment and remediation guidance Establish repeatable vulnerability workflows and processes to support ATO readiness for new systems Communicate risk clearly to stakeholders and recommend effective mitigation strategies Contribute to the continuous improvement of security processes and controls Here’s what you need : 4–6 years of experience in vulnerability management or a related information security role Advanced knowledge of vulnerability management tools such as Tenable Nessus, Qualys, Rapid7, or OpenVAS Strong understanding of vulnerability scanning, assessment, and risk prioritization Familiarity with CVSS, NIST 800‑53, and OWASP Top 10 Understanding of OS‑level vulnerabilities (Windows, Linux, macOS) Knowledge of core network protocols and components (TCP/IP, DNS, firewalls, routers, switches) Experience with Cloud Service Providers (AWS, Azure, GCP) and cloud‑native policies Experience configuring and working with Identity Providers (IdP) Experience with patch management tools and processes Basic understanding of compliance requirements such as FISMA and SOX Familiarity with NIST CSF, ISO 27001, CIS Controls Ability to assess vulnerabilities, identify risks, and support incident response Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field (or equivalent experience) Preferred qualific