- Company Name
- DigiDoc, Inc. dba Public Sector Solutions Group
- Job Title
- Security Engineer
- Job Description
-
**Job Title:** Security Engineer
**Role Summary:**
Responsible for identifying, analyzing, and remediating security vulnerabilities across enterprise server and workstation environments. Coordinates patch cycles, prioritizes risks, and develops metrics and reporting to enhance overall security posture.
**Expectations:**
- 3–7 years of experience in vulnerability or patch management, with strong skills in Windows server/desktop environments.
- Proven ability to operate scanning tools, develop remediation guides, and communicate risk to technical and business stakeholders.
**Key Responsibilities:**
- Conduct scheduled vulnerability scans and analyze results to surface actionable risks and false positives.
- Prioritize findings using CVSS, KEV, CISA, and other industry frameworks; coordinate remediation with application and server teams.
- Support monthly/quarterly patch cycles, provide work‑around guidance, and validate remediation success.
- Create and maintain dashboards (remediation progress, aging vulnerabilities, SLA/KPI compliance, platform trends).
- Operate and tune tools such as Qualys, Microsoft Defender, Intune, PatchMyPC, SCCM, Azure Update Manager; recommend automation and optimization.
- Integrate scan outputs into ticketing or workflow systems (ServiceNow, Jira).
- Ensure compliance with security policies, CIS benchmarks, NIST guidance; document SOPs, runbooks, and governance processes.
- Assist with audit and compliance reporting as needed.
**Required Skills:**
- Windows Server and desktop platform expertise.
- Patch deployment and configuration management.
- Proficiency with vulnerability scanning platforms (Qualys, Defender, Azure Update Manager, PatchMyPC, etc.).
- Ability to analyze scan output, detect false positives, and translate findings into remediation actions.
- Knowledge of CVEs, CVSS scoring, exploitability assessments, and common ransomware/vector patterns.
- Strong written and verbal communication; capability to translate technical risk into business impact.
- Independent work orientation with data‑driven decision making.
**Required Education & Certifications:**
- No specific education or certifications listed; typical requirement is a bachelor’s degree in Computer Science, Information Security, or related field.