Skip to Main Content

IT SYSTEMS TECHNICAL SPECIALIST **REPOST**

SR. VULNERABILITY MANAGEMENT SPECIALIST (FULL-TIME CONTRACTUAL)

Recruitment #24-004488-0019

Introduction

RECRUITMENT REPOST. PREVIOUS APPLICANTS NEED NOT REAPPLY.

GRADE

21

LOCATION OF POSITION

MDH Office of Internal Controls, Audit Compliance and Information Security (IAC/S)
201 W. Preston Street
Baltimore, MD 21201

Main Purpose of Job

The main purpose of this full-time contractual position will be to report to the Chief Information Security Officer (CISO) as part of the Information Security Division within the Office of Internal Controls, Audit Compliance and Security (IAC/S).

This position will plan, implement, maintain, and support the vulnerability management program for the Maryland Department of Health (MDH). This includes managing the policies, configuration, scheduling, and executing routine discovery, patch, and secure configurations audit scans; providing remediation/mitigation recommendations; defining, developing, and implementing vulnerability management reports, metrics, and dashboards; reviewing and resolving false positives; providing guidance on validation procedures and required artifacts; and researching and reporting on scan plugin issues.

This position will also communicate and maintain guidance on security configuration standards for Operating Systems, database systems, web servers, networking devices, and other applications, along with all MDH devices, including desktops, laptops, tablets, and other devices.

In addition, this position will maintain a knowledge base of applicable vulnerability management industry best practices and supports the training of other employees and stakeholders.

PLEASE NOTE:

Effective May 15, 2024, an employee may be required to come into the office 2 days a week. This hybrid schedule will be agreed upon between the appointing authority, supervisor and employee and can be subject to change. The employee in this position must adhere to the updated Maryland State Telework Policy effective 5/15/24 and the updated IAC/S Telework Policy effective 5/22/24.

IAC/S employees are required to disclose secondary employment: All employment (compensated and uncompensated) outside the Department. An individual may not be employed with or receive compensation outside the Department that would create a conflict of interest, an appearance of a conflict of interest, or impair the impartiality and independence of judgment of the individual. See MDH Policy 01.05.10 for additional details.

MINIMUM QUALIFICATIONS

Experience: Seven years of experience designing, developing, testing, implementing and maintaining application, communication, database or operating systems software.

Notes:

1. Candidates may substitute graduation from an accredited high school or possession of a high school equivalency certificate and thirty credit hours from an accredited college or university in Computer Science, Computer Technology, Management Information Systems or other information technology-related field to include coursework in application, communication, database or operating systems software technology for four years of the required experience. 

2. Candidates may substitute graduation from an accredited high school or possession of a high school equivalency certificate and one year of experience designing, developing, testing, implementing and maintaining application, communication, database or operating systems software for four years of the required experience.

3. Candidates may substitute experience operating computer systems; or scheduling, controlling input and output to process data on computer systems; or evaluating, implementing and maintaining computer hardware and software; or converting data from project specifications by developing program code using generally accepted computer programming languages on a year-for-year basis for a high school education.

4. Candidates may substitute the possession of a Bachelor's degree from an accredited college or university in Computer Science, Computer Information Technology, Management Information Systems or other information technology-related field to include coursework in application, communication, database or operating systems software technology and three years of experience designing, developing, testing, implementing and maintaining application, communication, database or operating systems software for the required experience.

5. Candidates may substitute U.S. Armed Forces military service experience as a commissioned officer in the Computer Systems Operations classifications or Computer Systems Operations specialty codes in the Information Technology field of work on a year-for-year basis for the required experience.

DESIRED OR PREFERRED QUALIFICATIONS

The desired candidate should possess experience designing, developing, testing, implementing and executing cybersecurity vulnerability management programs following industry standard frameworks such as NIST.

The desired candidate should possess experience with the following:
  • Information Security Governance
  • Network Security
  • Application Security 
  • Incident Response
  • Risk Management
  • Security Assessments
  • Vulnerability Management Tools
  • Cloud Security

The desired candidate should also possess job related security or industry certifications including but not limited to the following:
  • CompTIA Security+
  • CompTIA Cybersecurity Analyst (CySA+)
  • Certified Information Security Manager (CISM)
  • Certified in Risk and Information Systems Control (CRISC)
  • Certified Information Systems Auditor (CISA)
  • GIAC Security Essentials (GSEC)
  • Certified Information Security Systems Professional (CISSP)

SELECTION PROCESS

Applicants who meet the minimum (and selective) qualifications will be included in further evaluation. The evaluation may be a rating of your application based on your education, training and experience as they relate to the requirements of the position. Therefore, it is essential that you provide complete and accurate information on your application. Please report all related education, experience, dates and hours of work. Clearly indicate your college degree and major on your application, if applicable. For education obtained outside the U.S., any job offer will be contingent on the candidate providing an evaluation for equivalency by a foreign credential evaluation service prior to starting employment (and may be requested prior to interview). 

Complete applications must be submitted by the closing date. Information submitted after this date will not be added. 

Incorrect application forms will not be accepted. Resumes will not be accepted in lieu of a completed application.

Candidates may remain on the certified eligible list for a period of at least one year. The resulting certified eligible list for this recruitment may be used for similar positions in this or other State agencies.

BENEFITS

Contractual employees who work for an agency covered under the State Employee and Retiree Health and Welfare Benefits Program, have a current employment contract and work 30 or more hours a week (or on average 130 hours per month) may be eligible for subsidized health benefits coverage for themselves and their dependents. As a contractual employee, you will be responsible for paying 25% of the premiums for your medical and prescription coverage, including any eligible dependents you have enrolled. The State of Maryland will subsidize the remaining 75% of the cost for these benefits. You can also elect to enroll in dental coverage, accidental death and dismemberment insurance, and life insurance, but will be responsible to pay the full premium for these benefits.

Leave may be granted to a contractual employee who has worked 120 days in a 12 month period. This leave accrues at a rate of one hour for every 30 hours worked, not to exceed 40 hours per calendar year.

FURTHER INSTRUCTIONS

Online applications are highly recommended. However, if you are unable to apply online, the paper application (and supplemental questionnaire) may be submitted to MDH, Recruitment and Selection Division, 201 W. Preston St., Room 114-B, Baltimore, MD 21201. Paper application materials must be received by 5 pm, close of business, on the closing date for the recruitment, no postmarks will be accepted.

If additional information is required, the preferred method is to upload.  If you are unable to upload, please fax the requested information to 410-333-5689. Only additional materials that are required will be accepted for this recruitment. All additional information must be received by the closing date and time.

For questions regarding this recruitment, please contact the MDH Recruitment and Selection Division at 410-767-1251.

If you are having difficulty with your user account or have general questions about the online application system, please contact the MD Department of Budget and Management, Recruitment and Examination Division at 410-767-4850 or Application.Help@maryland.gov

Appropriate accommodations for individuals with disabilities are available upon request by calling: 410-767-1251 or MD TTY Relay Service 1-800-735-2258.

We thank our Veterans for their service to our country.

People with disabilities and bilingual candidates are encouraged to apply.

As an equal opportunity employer, Maryland is committed to recruitment, retaining and promoting employees who are reflective of the State's diversity.



Click on a link below to apply for this position:

Fill out the Supplemental Questionnaire and Application NOW using the Internet. Apply Online
View and print the Supplemental Questionnaire. This recruitment requires completion of a supplemental questionnaire. You may view and print the supplemental questionnaire here.
Apply via Paper Application. You may also download and complete the Paper Application here.

Powered by JobAps