Home › Companies › Shorepointinc › Compliance and Continuous Monitoring Engineer - Vulnerability Management (Top Secret Clearance)
Compliance and Continuous Monitoring Engineer - Vulnerability Management (Top Secret Clearance)
Shorepointinc · Washington, District of Columbia, 20535, United States · On Site · Active · BambooHR
Job facts
| Field | Value |
|---|---|
| Company | Shorepointinc |
| Title | Compliance and Continuous Monitoring Engineer - Vulnerability Management (Top Secret Clearance) |
| Normalized title | - |
| Department / team | Staff |
| Location | Washington, United States |
| Work model | On Site |
| Employment type | Full Time |
| Salary | - |
| Status | active |
| ATS provider | BambooHR |
| Posted / first seen | 2026-05-13 / 2026-05-30 |
| Changed / last seen | 2026-05-30 / 2026-06-06 |
Related slices
| Page | What it contains | Open |
|---|---|---|
| Company jobs | Active postings from Shorepointinc. | Open |
| Company breakdowns | Role, location, ATS, and work model facets for this company. | Open |
| ATS provider jobs | Active postings observed through BambooHR. | Open |
| Provider filtered search | The same provider as a filtered job collection. | Open |
| City jobs | Active postings in Washington. | Open |
| Department jobs | Active postings in Staff. | Open |
| Work model jobs | Active On Site postings. | Open |
| Lifecycle events | Open, update, close, and reopen events for this posting. | Open |
| Original posting | Canonical source or apply URL captured from the ATS. | Open |
Linked records
| Company | Shorepointinc |
| Source | 8f3b3eb9-ce20-4a59-8d89-dc4f1c2bfd80 |
| ATS provider | BambooHR |
Description
Who we are:
ShorePoint is a fast-growing, industry recognized and award-winning cybersecurity services firm with a focus on high-profile, high-threat, private and public-sector customers who demand experience and proven security models to protect their data. ShorePoint subscribes to a “work hard, play hard” mentality and celebrates individual and company successes. We are passionate about our mission and going above and beyond to deliver for our customers. We are equally passionate about an environment that supports creativity, accountability, diversity, inclusion and a focus on giving back to our community.
The Perks:
As recognized members of the Cyber Elite, we work together in partnership to defend our nation’s critical infrastructure while building meaningful and exciting career development opportunities in a culture tailored to the individuals technical and professional growth. We are committed to the belief that our team members do their best work when they are happy and well cared for. In support of this philosophy, we offer a comprehensive benefits package, including major carriers for health care providers. Highlighted benefits offered: 144 hours of PTO, 11 holidays, 85% of insurance premium covered, 401k, continued education, certifications maintenance and reimbursement and more.
Who we’re looking for:
We are seeking Compliance and Continuous Monitoring Engineer - Vulnerability Management (Top Secret Clearance) with expertise in security assessments, vulnerability management and continuous monitoring. The ideal candidate will support assessment and authorization activities, conduct technical security evaluations and ensure enterprise systems remain compliant with federal cybersecurity standards. The Compliance and Continuous Monitoring Engineer (Vulnerability Management) role will provide hands-on scanning, reporting and compliance support to strengthen the enterprise cybersecurity posture. This is a unique opportunity to shape the growth, development and culture of an exciting and fast-growing company in the cybersecurity market.
What you’ll be doing:
Work closely with organizations to ensure full comprehension of security controls; conduct site visits as required.
Assist with compliance assessments using tailored control matrices; provide expert assessment support.
Conduct annual reviews of security controls to ensure continued compliance.
Establish footholds on endpoints to provide day-to-day visibility into enterprise security posture.
Develop and maintain processes and best practices for evaluating assessment and authorization data.
Use industry-standard automation tools to review system configurations and security control compliance.
Conduct NIST control assessments in support of system authorization and continuous monitoring.
Develop and maintain Security Assessment Reports (SARs) and Risk Assessment Reports (RARs).
Employ a scan-patch-scan methodology to ensure proper remediation of vulnerabilities.
Conduct vulnerability scanning on a weekly to bi-weekly basis using industry-standard tools.
Report scan data to system administrators to support timely remediation.
Perform false positive and vulnerability analysis to validate findings and prioritize remediation.
Configure applications to ingest, process and report vulnerability data from assessments and self-assessments.
Conduct long-term trend analysis to identify changes in enterprise security posture.
Provide dashboard views and executive-level reports to communicate risk, vulnerability and compliance posture.
Configure authenticated and unauthenticated scans of web servers (e.g., Apache, IIS) to identify vulnerabilities such as outdated software, misconfigurations, exposed services and SSL/TLS weaknesses.
Assess both in-house and COTS web applications to identify OWASP Top 10 risks, including SQL injection, cross-site scripting (XSS) and insecure HTTP headers.
Lead technical troubleshooting sessions with administrators and leadership to analyze findings, validate issues and drive remediation efforts.
Maintain a general understanding of network architecture diagrams to support vulnerability analysis and remediation planning.
What you need to know:
Strong understanding of federal frameworks including NIST 800-53 and 800-53A.
Knowledge of SANS and OWASP Top 10 vulnerabilities and best practices.
Ability to synthesize and analyze large volumes of vulnerability and scan data.
Ability to clearly articulate findings in written and verbal form.
Must have’s:
Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Mathematics, Engineering or a related field or additional 10+ years of IT experience in lieu of degree.
One or more of the following certifications: (ISC)2 Certified Information Security Professional (CISSP), GIAC, GCIA or GCIH
Proven ability to analyze complex requirements and translate them into clear, actionable tasks and processes through critical thinking.
Ability to perform vulnerability and compliance assessments on all devices identified during enterprise network scans, including operating systems oracle and MySQL databases and web applications.
Proficiency with enterprise-class scanning tools such as Tenable Nessus and Tenable Security Center, database scanning tools such as AppDetective and DbProtect and web scanning tools such as Web Inspect, with strong knowledge of security best practices and common vulnerabilities for each technology, including SANS and OWASP Top 10.
Experience performing enterprise-level assessment scanning of networks, databases and web applications.
Ability to configure and perform host, port and service discoveries on large enterprise networks and identify target operating systems and applications or services from discovery results.
Proficiency in configuring, troubleshooting and administering Tenable Security Center, Tenable Nessus standalone, AppDetective and Web Inspect.
Strong understanding of security policies used by intelligence organizations, as well as NIST guidelines (e.g., 800-53 and 800-53A).
Ability to think critically and creatively and to synthesize and analyze large volumes of scan data.
Strong written and verbal communication skills with the ability to present findings clearly and comprehensively.
Applicants must possess an Top-Secret clearance with SCI eligibility and ability to pass a Counterintelligence (CI) polygraph .
Beneficial to have:
Experience with open-source and commercial testing tools, including Nessus, NMAP, AppDetective, Hailstorm, Guardium and Web Inspect.
Where it’s done:
Onsite (Washington, DC.)
Full job record
| Job ID | 9d90939bfb8bb2b46786916351fec0bcbd2fa94a |
| Org ID | ba8a0b6d-b2b7-4f57-98e0-20909e905a41 |
| Source ID | 8f3b3eb9-ce20-4a59-8d89-dc4f1c2bfd80 |
| Board ID | 8f3b3eb9-ce20-4a59-8d89-dc4f1c2bfd80 |
| Provider | bamboohr |
| Provider Job Key | 900 |
| Title | Compliance and Continuous Monitoring Engineer - Vulnerability Management (Top Secret Clearance) |
| Normalized Title | — |
| Status | active |
| Active | yes |
| Location Text | Washington, District of Columbia, 20535, United States |
| Department | Staff |
| Team | — |
| Employment Type | full_time |
| Workplace Type | on_site |
| Remote Policy | — |
| Country | United States |
| Region | — |
| City | Washington |
| Salary Raw | — |
| Salary Min | — |
| Salary Max | — |
| Salary Currency | — |
| Salary Period | — |
| Source URL | https://shorepointinc.bamboohr.com/careers/900 |
| Apply URL | https://shorepointinc.bamboohr.com/careers/900 |
| First Seen At | 2026-05-30 05:58:08Z |
| Last Seen At | 2026-06-06 09:45:56Z |
| Last Checked At | 2026-06-06 09:45:56Z |
| Last Changed At | 2026-05-30 05:58:08Z |
| Inactive At | — |
| Source Posted At | 2026-05-13 00:00:00Z |
| Source Updated At | — |
| Raw Payload Uri | s3://job-postings-prod-raw-590183727216/raw/provider=bamboohr/board=shorepointinc/date=2026-06-06/2026-06-06T09-45-55-272Z-6b2ecd4669f1a82076effded4764d1b93f1b3cd79f1ba1db0544865275727ce3.json |
Event Fields
{
"content_hash": "41c6cd773bbf999778a942d059110f30f7299f6e199ff77a12229c12a94aeb64",
"source_hash": "d1216c91843c4663fbfda9f215559d650a719b3b2513c13bc20801bb428acfeb",
"last_changed_at": "2026-05-30T05:58:08.457Z",
"active_status": "active"
}Parsed Structured
{
"language": "en",
"location": {
"raw": "Washington, District of Columbia, 20535, United States",
"city": "Washington",
"region": null,
"country": "United States",
"is_remote": false,
"confidence": 0.95
},
"salary_max": null,
"salary_min": null,
"inferred_at": "2026-06-06T09:45:56.196Z",
"launch_scope": {
"reason": "bamboohr_production_catalog",
"included": true,
"location": {
"raw": "Washington, District of Columbia, 20535, United States",
"city": "Washington",
"region": null,
"country": "United States",
"is_remote": false,
"confidence": 0.95
},
"countries": [
"United States"
]
},
"remote_policy": null,
"salary_period": null,
"workplace_type": "on_site",
"salary_currency": null
}Extensions
{}Native Structured
{
"list_job": {
"id": "900",
"isRemote": null,
"location": {
"city": "Washington",
"state": "District of Columbia"
},
"atsLocation": {
"city": null,
"state": null,
"country": null,
"province": null
},
"departmentId": "18436",
"locationType": "0",
"jobOpeningName": "Compliance and Continuous Monitoring Engineer - Vulnerability Management (Top Secret Clearance) ",
"departmentLabel": "Staff",
"employmentStatusLabel": "Full-Time"
},
"detail_errors": [],
"detail_job_opening": {
"location": {
"city": "Washington",
"state": "District of Columbia",
"postalCode": "20535",
"addressCountry": "United States"
},
"datePosted": "2026-05-13",
"atsLocation": {
"city": null,
"state": null,
"country": null,
"countryId": null
},
"description": "<p><span style=\"font-weight: bold\">Who we are:</span></p>\n<p><br></p>\n<p>ShorePoint is a fast-growing, industry recognized and award-winning cybersecurity services firm with a focus on high-profile, high-threat, private and public-sector customers who demand experience and proven security models to protect their data. ShorePoint subscribes to a “work hard, play hard” mentality and celebrates individual and company successes. We are passionate about our mission and going above and beyond to deliver for our customers. We are equally passionate about an environment that supports creativity, accountability, diversity, inclusion and a focus on giving back to our community. </p>\n<p><br></p>\n<p><span style=\"font-weight: bold\">The Perks:</span></p>\n<p><br></p>\n<p>As recognized members of the Cyber Elite, we work together in partnership to defend our nation’s critical infrastructure while building meaningful and exciting career development opportunities in a culture tailored to the individuals technical and professional growth. We are committed to the belief that our team members do their best work when they are happy and well cared for. In support of this philosophy, we offer a comprehensive benefits package, including major carriers for health care providers. Highlighted benefits offered: 144 hours of PTO, 11 holidays, 85% of insurance premium covered, 401k, continued education, certifications maintenance and reimbursement and more.</p>\n<p><br></p>\n<p><span style=\"font-weight: bold\">Who we’re looking for:</span></p>\n<p><br></p>\n<p>We are seeking <span style=\"font-weight: bold\">Compliance and Continuous Monitoring Engineer - Vulnerability Management (Top Secret Clearance) </span>with expertise in security assessments, vulnerability management and continuous monitoring. The ideal candidate will support assessment and authorization activities, conduct technical security evaluations and ensure enterprise systems remain compliant with federal cybersecurity standards. The <span style=\"font-weight: bold\">Compliance and Continuous Monitoring Engineer (Vulnerability Management) </span>role will provide hands-on scanning, reporting and compliance support to strengthen the enterprise cybersecurity posture. This is a unique opportunity to shape the growth, development and culture of an exciting and fast-growing company in the cybersecurity market.</p>\n<p><br></p>\n<p><span style=\"font-weight: bold\">What you’ll be doing:</span><br></p>\n<p><br></p>\n<ul>\n<li>Work closely with organizations to ensure full comprehension of security controls; conduct site visits as required.</li>\n<li>Assist with compliance assessments using tailored control matrices; provide expert assessment support.</li>\n<li>Conduct annual reviews of security controls to ensure continued compliance.</li>\n<li>Establish footholds on endpoints to provide day-to-day visibility into enterprise security posture.</li>\n<li>Develop and maintain processes and best practices for evaluating assessment and authorization data.</li>\n<li>Use industry-standard automation tools to review system configurations and security control compliance.</li>\n<li>Conduct NIST control assessments in support of system authorization and continuous monitoring.</li>\n<li>Develop and maintain Security Assessment Reports (SARs) and Risk Assessment Reports (RARs).</li>\n<li>Employ a scan-patch-scan methodology to ensure proper remediation of vulnerabilities.</li>\n<li>Conduct vulnerability scanning on a weekly to bi-weekly basis using industry-standard tools.</li>\n<li>Report scan data to system administrators to support timely remediation.</li>\n<li>Perform false positive and vulnerability analysis to validate findings and prioritize remediation.</li>\n<li>Configure applications to ingest, process and report vulnerability data from assessments and self-assessments.</li>\n<li>Conduct long-term trend analysis to identify changes in enterprise security posture.</li>\n<li>Provide dashboard views and executive-level reports to communicate risk, vulnerability and compliance posture.</li>\n<li>Configure authenticated and unauthenticated scans of web servers (e.g., Apache, IIS) to identify vulnerabilities such as outdated software, misconfigurations, exposed services and SSL/TLS weaknesses.</li>\n<li>Assess both in-house and COTS web applications to identify OWASP Top 10 risks, including SQL injection, cross-site scripting (XSS) and insecure HTTP headers.</li>\n<li>Lead technical troubleshooting sessions with administrators and leadership to analyze findings, validate issues and drive remediation efforts.</li>\n<li>Maintain a general understanding of network architecture diagrams to support vulnerability analysis and remediation planning.</li>\n</ul>\n<p><br></p>\n<p><span style=\"font-weight: bold\">What you need to know:</span></p>\n<p><br></p>\n<ul>\n<li>Strong understanding of federal frameworks including NIST 800-53 and 800-53A.</li>\n<li>Knowledge of SANS and OWASP Top 10 vulnerabilities and best practices.</li>\n<li>Ability to synthesize and analyze large volumes of vulnerability and scan data.</li>\n<li>Ability to clearly articulate findings in written and verbal form.</li>\n</ul>\n<p><br></p>\n<p><span style=\"font-weight: bold\">Must have’s:</span></p>\n<p><br></p>\n<ul>\n<li>Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Mathematics, Engineering or a related field or additional 10+ years of IT experience in lieu of degree.</li>\n<li>One or more of the following certifications: (ISC)2 Certified Information Security Professional (CISSP), GIAC, GCIA or GCIH</li>\n<li>Proven ability to analyze complex requirements and translate them into clear, actionable tasks and processes through critical thinking.</li>\n<li>Ability to perform vulnerability and compliance assessments on all devices identified during enterprise network scans, including operating systems oracle and MySQL databases and web applications.</li>\n<li>Proficiency with enterprise-class scanning tools such as Tenable Nessus and Tenable Security Center, database scanning tools such as AppDetective and DbProtect and web scanning tools such as Web Inspect, with strong knowledge of security best practices and common vulnerabilities for each technology, including SANS and OWASP Top 10.</li>\n<li>Experience performing enterprise-level assessment scanning of networks, databases and web applications.</li>\n<li>Ability to configure and perform host, port and service discoveries on large enterprise networks and identify target operating systems and applications or services from discovery results.</li>\n<li>Proficiency in configuring, troubleshooting and administering Tenable Security Center, Tenable Nessus standalone, AppDetective and Web Inspect.</li>\n<li>Strong understanding of security policies used by intelligence organizations, as well as NIST guidelines (e.g., 800-53 and 800-53A).</li>\n<li>Ability to think critically and creatively and to synthesize and analyze large volumes of scan data.</li>\n<li>Strong written and verbal communication skills with the ability to present findings clearly and comprehensively.</li>\n<li>Applicants must possess an Top-Secret clearance with SCI eligibility and ability to pass a Counterintelligence (CI) polygraph<em>.</em></li>\n</ul>\n<p><br></p>\n<p><span style=\"font-weight: bold\">Beneficial to have:</span></p>\n<p><br></p>\n<ul>\n<li>Experience with open-source and commercial testing tools, including Nessus, NMAP, AppDetective, Hailstorm, Guardium and Web Inspect.</li>\n</ul>\n<p><br></p>\n<p><span style=\"font-weight: bold\">Where it’s done:</span></p>\n<p><br></p>\n<ul>\n<li>Onsite (Washington, DC.)</li>\n</ul>",
"compensation": null,
"departmentId": "18436",
"locationType": "0",
"seekPromoted": false,
"jobCategoryId": "18380",
"jobOpeningName": "Compliance and Continuous Monitoring Engineer - Vulnerability Management (Top Secret Clearance) ",
"departmentLabel": "Staff",
"jobOpeningStatus": "Open",
"minimumExperience": "Experienced",
"jobOpeningShareUrl": "https://shorepointinc.bamboohr.com/careers/900",
"employmentStatusLabel": "Full-Time"
}
}Get this page with API
Rendered from the bluedoor Job Postings API. Reproduce it:
GET https://api.bluedoor.sh/job-postings/v1/jobs/9d90939bfb8bb2b46786916351fec0bcbd2fa94a?include=descriptionJSONGET https://api.bluedoor.sh/job-postings/v1/orgs/ba8a0b6d-b2b7-4f57-98e0-20909e905a41JSONGET https://api.bluedoor.sh/job-postings/v1/sources/8f3b3eb9-ce20-4a59-8d89-dc4f1c2bfd80JSONGET https://api.bluedoor.sh/job-postings/v1/jobs/9d90939bfb8bb2b46786916351fec0bcbd2fa94a/eventsJSON