Associate Security Consultant - Vulnerability Management

Auto Import

<h1><b>About Us</b></h1><p></p><p><b>Since 1989, SHI International Corp. has helped organizations change the world through technology. We’ve grown every year since, and today we’re proud to be a $16 billion global provider of IT solutions and services.</b></p><p><b> </b></p><p><b>Over 17,000 organizations worldwide rely on SHI’s concierge approach to help them solve what’s next. But the heartbeat of SHI is our employees – all 7,000 of them. If you join our team, you’ll enjoy:</b></p><ul><li style="text-align:left"><p><b>Our commitment to diversity, as the largest minority- and woman-owned enterprise in the U.S.</b></p></li><li style="text-align:left"><p><b>Continuous professional growth and leadership opportunities.</b></p></li><li style="text-align:left"><p><b>Health, wellness, and financial benefits to offer peace of mind to you and your family.</b></p></li><li style="text-align:left"><p><b>World-class facilities and the technology you need to thrive – in our offices or yours. </b></p></li></ul><p style="text-align:inherit"></p><p style="text-align:inherit"></p><h1><b>Job Summary</b></h1><p style="text-align:inherit"></p>The Associate Security Consultant - Vulnerability Management is a critical role within Stratascale’s Adversarial Operations Group, assigned to the Vulnerability Management team. This individual will assist in leading and supporting the development and delivery of a diverse range of exposure management consulting, Vulnerability Management as a Service (VMaaS), and operational service programs to a portfolio of our clients.<p style="text-align:inherit"></p><p style="text-align:inherit"></p><p><b>Role Description</b>​​</p><ul><li><p><span>Conduct day-to-day VMaaS activities, including vulnerability scanning, asset discovery, scan policy configuration, and reporting.</span></p></li><li><p><span>Independently conduct Attack Surface Control (ASC) engagements for a variety of clients, including the use of automated tools and manual micro-penetration testing.</span></p></li><li><p><span>With guidance from more senior consultants, monitor automated penetration testing tooling to identify and validate security weaknesses.</span></p></li><li><p><span>Perform validation of vulnerability findings to eliminate false positives and determine actual risk.</span></p></li><li><p><span>Collaborate with the penetration testing team to conduct further deep-dive testing as needed based on vulnerability discoveries.</span></p></li><li><p><span>Consult and document attack surface, threats, and vulnerability improvements based on the team’s overall assessment of the client’s environment.</span></p></li><li><p><span>Perform assessment and threat modeling against industry best practices to identify control weaknesses and assess the effectiveness of existing controls.</span></p></li><li><p><span>Perform root cause analysis on identified vulnerabilities and attack surface weaknesses to determine technical solutions to be presented to client along with recommendations for remediations.</span></p></li><li><p><span>With guidance from more senior security consultants, collaborate with the client’s security teams to understand mitigation or resolutions for findings discovered by analysts.</span></p></li><li><p><span>Review Stratascale Cyber Threat Intelligence (CTI)-provided threat intelligence for specific threat vectors that align with the client's industry or potentially impact the client by using attack path modeling.</span></p></li><li><p><span>Assist in defining, measuring, and quantifying business risk and vulnerability impacts to clients and their stakeholders.</span></p></li><li><p><span>With guidance from more senior security consultants, provide technical support on remediation, cloud security, governance, compliance, and core infrastructure systems.</span></p></li><li><p><span>With guidance from more senior security consultants, assist customers with strategies, use of platforms, technical and compliance analysis, and implementing automation.</span></p></li><li><p><span>Execute consulting projects by creating and completing deliverables, ensuring client needs and practice obligations are met.</span></p></li><li><p><span>Participate in customer and internal meetings as required, providing technical guidance and facilitating discussions.</span></p></li><li><p><span>Stay educated on new product technologies, industry trends, and emerging capabilities within the practice.</span></p></li></ul><p><br><br><b>Behaviors and Competencies</b></p><ul><li><p><b><span>Communication:</span></b><span> Can effectively communicate technical ideas and information to diverse audiences and collaborate with team members in client communications.</span></p></li><li><p><b><span>Relationship Building:</span></b><span> Can contribute to team initiatives, collaborate with diverse groups, and support effective relationship management.</span></p></li><li><p><b><span>Self-Motivation:</span></b><span> Can take ownership of personal and professional initiatives, collaborate with others when necessary, and drive results through self-motivation.</span></p></li><li><p><b><span>Negotiation:</span></b><span> Can participate in negotiations and work collaboratively with others to drive consensus.</span></p></li><li><p><b><span>Impact and Influence:</span></b><span> Can contribute positively to team goals and support a collaborative, results-driven environment.</span></p></li><li><p><b><span>Business Development:</span></b><span> Can support business development initiatives and collaborate with various stakeholders to contribute to business results.</span></p></li><li><p><b><span>Emotional Intelligence:</span></b><span> Can use emotional information to guide thinking and behavior, manage, and/or adjust emotions to adapt to environments or achieve one's goal(s).</span></p></li><li><p><b><span>Detail-Oriented:</span></b><span> Can manage multiple tasks, maintain a high level of detail orientation, identify errors or inconsistencies at work, and ensure accuracy across all assignments.</span></p></li><li><p><b><span>Follow-Up:</span></b><span> Can take ownership of assigned tasks, collaborate with others in managing follow-ups, and drive results through effective task completion.</span></p></li><li><p><b><span>Presenting:</span></b><span> Can effectively use visual aids and clear communication techniques to present findings and engage both technical and non-technical audiences.</span></p></li><li><p><b><span>Time Management:</span></b><span> Can manage assigned responsibilities effectively, balance competing priorities, and seek guidance when needed.</span></p></li><li><p><b><span>Analytical Thinking:</span></b><span> Can apply analytical techniques to solve problems, draw insights, and clearly communicate findings.</span></p></li><li><p><b><span>Critical Thinking:</span></b><span> Can gather and synthesize information from various sources to support informed problem-solving and decision-making.</span></p></li><li><p><b><span>Technical Troubleshooting:</span></b><span> Can troubleshoot technical problems, collaborate with others to develop solutions, and drive results in problem resolution.</span></p></li></ul><p><br><br><b>Skill Level Requirements</b></p><ul><li><p>Experience with Vulnerability Management tools such as Tenable, Rapid7, Qualys, and Tanium to support day-to-day VMaaS delivery activities including scanning, asset management, and reporting. - <b>Foundational to Intermediate</b></p></li><li><p>Familiarity with offensive security methodologies and frameworks such as PTES, OWASP (WSTG/MASVS/ASVS), MITRE ATT&CK, and threat modeling to support risk-based testing. - <b>Foundational to Intermediate</b></p></li><li><p>Ability to develop exploit proofs-of-concept, reproduce vulnerabilities reliably, and support fix validation; familiarity with exploit development fundamentals is a plus. — <i>Foundational</i></p></li><li><p>Reporting and communication skills, including writing technical reports with reproducible steps, risk ratings, and actionable remediation, and contributing to executive summaries with guidance; able to present findings to both technical and non-technical stakeholders. - <b>Intermediate</b></p></li><li><p>Familiarity with vulnerability management workflows, responsible disclosure practices, and integration of pen test results into remediation programs and retesting cycles. - <b>Foundational to Intermediate</b></p></li><li><p>Proficiency with productivity and documentation tools such as Word, Excel, PowerPoint, and Outlook to produce test plans, findings reports, and final deliverables. - <b>Intermediate</b></p></li></ul><p></p><p><b>The following skills are preferred, but not required:</b></p><ul><li><p>Experience supporting penetration tests across networks, web and mobile applications, APIs, wireless, and cloud environments, including participation in scoping, rules of engagement, and debriefs. - <b>Foundational to Intermediate</b></p></li><li><p>Familiarity with assessing cloud services (AWS, Azure, GCP) including IAM misconfigurations, storage, serverless, <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">container/orchestration,</span> and cloud networking, with an ability to communicate cloud-specific remediation guidance. - <b>Foundational</b></p></li><li><p>Web application testing skills including auth flows, access control, injection, deserialization, SSRF, XXE, business logic abuse, and modern app architectures (SPAs, microservices, GraphQL, WebSockets). - <b>Foundational to Intermediate</b></p></li><li><p>Familiarity with social engineering and phishing engagements, including payload development, infrastructure setup, pretexting, and measurement aligned to customer policies and legal constraints. - <b>Foundational</b></p></li><li><p>Foundational scripting and automation skills to support testing and proof-of-concept development using Python, PowerShell, Bash, and basic Go or JavaScript as needed. - <b>Foundational to Intermediate</b></p></li><li><p>Working knowledge of Active Directory and Azure AD attack paths (Kerberoasting, <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">constrained/unconstrained</span> delegation, ACL abuses, LAPS/MAPS, certificate services) and exposure to simulating enterprise attack chains. - <b>Foundational</b></p></li><li><p>Hands-on experience with common offensive tooling and techniques, including reconnaissance, enumeration, exploitation, post-exploitation, lateral movement, and data exfiltration, along with foundational operational security practices. - <b>Foundational to Intermediate</b></p></li><li><p>Familiarity with red/purple team exercises and working alongside blue teams to translate findings into detection and hardening recommendations (e.g., SIEM detections, EDR tuning, hardening baselines). - <b>Foundational</b></p></li></ul><p><br><br><b>Other Requirements</b></p><ul><li><p><span>Completed Bachelor’s Degree in a related field or relevant work experience required.</span></p></li><li><p><span>1–3 years of hands-on penetration testing or vulnerability management experience, including exposure to engagements supporting mid-to-large enterprise environments.</span></p></li><li><p><span>Ability to travel to SHI, Partner, and client events, and on-site testing engagements as needed.</span></p></li><li><p><b><span>Industry certifications preferred (e.g., CPTS, OSCP, PNPT, Security+, CySA+, or vendor-specific VM certifications.)</span></b></p></li><li><p><span>Demonstrated understanding of legal/ethical considerations, testing authorization, and safe handling of client data.</span></p></li></ul><p style="text-align:inherit"></p><p style="text-align:inherit"></p><p>The estimated annual pay range for this position is $80,000 - $110,000 which includes a base salary and bonus. The compensation for this position is dependent on job-related knowledge, skills, experience, and market location and, therefore, will vary from individual to individual. Benefits may include, but are not limited to, medical, vision, dental, 401K, and flexible spending.</p><p></p><p></p><p style="text-align:left"><span><span><span>Equal Employment Opportunity – <span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span class="WHR0"><span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">M/F/Disability/Protected</span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span> Veteran Status</span></span><span> </span></span></p>

Back to blog