vTech solution Inc · Virginia, United States

Work with us

4 open positions

Facebook

Open positions

IT Security Audit Manager / Lead Auditor

Job Summary:

Seeking an IT Security Audit Manager / Lead Auditor to lead and manage SEC530 security audits for Fairfax Quick Modules, PrintSafe, and Prisma Print. This role serves as the primary client contact and holds full accountability for audit planning, delivery, findings, reports, work papers, and overall quality.

Key Responsibilities:

  • Develop the project plan, audit schedule, and SEC530 audit programs
  • Manage entrance conferences, evidence requests, interviews, weekly reporting, findings reviews, and exit conferences
  • Determine control applicability and approve sampling/testing procedures
  • Review audit evidence and work papers for completeness and sufficiency
  • Ensure inquiry is not the primary evidence source; validate timeliness of access termination testing
  • Develop findings covering condition, criteria, cause, effect, and recommendation
  • Prepare and finalize separate audit reports for each system
  • Coordinate management corrective action plans and final deliverable acceptance
  • Ensure compliance with GAGAS or IIA Global Internal Audit Standards

Required Skills & Certifications:

  • 10+ years of IT audit, cybersecurity assurance, technology risk, or compliance experience
  • 5+ years leading IT security or system compliance audits
  • Experience with one or more Commonwealth of Virginia standards: SEC530 (Information Security), SEC502 (IT Security Audit), SEC520 (IT Risk Management)
  • Experience auditing financial, tax, payment-processing, or revenue systems handling sensitive financial data
  • Experience with NIST SP 800-53 control assessments
  • Experience preparing audit programs, work papers, findings, corrective action plans, and final reports
  • Government or regulated-industry audit experience
  • Strong skills in evidence sufficiency, work-paper review, findings/report development, and third-party/SaaS risk assessment
  • Project, schedule, risk, and stakeholder management skills
  • CISA certification required or strongly preferred

Preferred Skills & Certifications:

  • Commonwealth of Virginia IT audit experience
  • PMP strongly preferred
  • CIA, CISSP, or CRISC desirable

Scheduling:

  • Duration: 3 Months
  • Working: 40 hrs/week
📍 Washington D.C., United States💼 Hybrid⏰ Full Time
Apply
OT Security Specialist

Job Title: OT Security Specialist

Duration: 3 Months

Location: Richmond, VA 23219

Work Module: Hybrid

Position Summary

The OT Security Specialist will provide industrial control system and operational technology expertise throughout the assessment. This role will guide safe testing of the selected TOC, field cabinet, field-connected assets, communications paths, and any approved controlled device scenario.

The specialist will determine whether proposed testing techniques are suitable for the operational environment and will help protect system availability, traffic operations, and public safety.

Key Responsibilities

  • Review the architecture of the OT environment, including the Central Office, selected TOC, field network, Azure DMZ, LTE connectivity, and field cabinet.
  • Interpret the OT environment using the Purdue Model and identify relevant security zones and conduits.
  • Review approved OT network diagrams, device configurations, field connectivity, industrial protocols, and operational dependencies.
  • Identify testing methods that are safe for the selected operational systems and connected field devices.
  • Establish asset-specific safety constraints, stop conditions, emergency procedures, and prohibited actions for inclusion in the ROE.
  • Support testing of the selected TOC and approved field-connected assets.
  • Evaluate the security of field communications paths and field-adjacent access opportunities.
  • Support approved physical access and controlled device scenarios.
  • Evaluate whether field access could provide unauthorized connectivity to internal OT resources.
  • Assess OT host hardening, default services, management interfaces, insecure protocols, trust relationships, and segmentation controls.
  • Advise the testing team when active validation could affect operational availability or device stability.
  • Prevent unauthorized PLC logic changes, firmware updates, configuration changes, persistence, denial-of-service activity, or other unsafe actions.
  • Coordinate testing with OIS, TOC personnel, field operations staff, and escorts.
  • Evaluate technical findings in the context of operational impact, public safety, recoverability, and compensating controls.
  • Map applicable findings to MITRE ATT&CK for ICS and NIST SP 800-82.
  • Develop practical remediation recommendations that account for OT availability, maintenance windows, equipment lifecycle, and operational constraints.
  • Prepare technical content for the field, physical, controlled device, TOC, and consolidated assessment reports.
  • Support final debriefing and retesting of remediated OT findings.

Required Skills

  • OT and ICS cybersecurity
  • SCADA environments and industrial architecture
  • Purdue Model segmentation
  • Industrial network protocols
  • Field device and cabinet security
  • OT network discovery and asset identification
  • Safe assessment of operational systems
  • OT vulnerability analysis
  • Field communications and remote-access security
  • OT logging, monitoring, and detection
  • Physical and field-access risk analysis
  • Operational safety and availability protection
  • MITRE ATT&CK for ICS
  • NIST SP 800-82
  • Technical report writing and risk communication

Required Experience

  • Minimum five years of OT, ICS, SCADA, or industrial cybersecurity experience
  • Experience assessing operational networks and field-connected devices
  • Experience conducting or supporting penetration testing in operationally sensitive environments
  • Experience applying safety restrictions and stop-work procedures during technical testing
  • Experience evaluating OT segmentation, remote access, and field connectivity
  • Experience documenting technical findings in terms of both cybersecurity risk and operational impact
  • Experience working with network engineers, penetration testers, SOC teams, and operations personnel

Desired Experience

  • Experience with transportation systems, traffic operations centers, roadside technology, cameras, dynamic message signs, sensors, or similar field devices
  • Experience with LTE-connected industrial or field networks
  • Experience assessing cloud-connected OT boundary environments
  • Experience supporting public-sector or critical infrastructure organizations
  • Familiarity with NIST SP 800-53, CIS Controls, SEC530, SEC520, and SEC502
  • Desired Certifications
  • Global Industrial Cyber Security Professional, GICSP
  • GIAC Response and Industrial Defense, GRID
  • Certified Information Systems Security Professional, CISSP
📍 Virginia, United States💼 Hybrid⏰ Full Time
Apply
Network Security Engineer

Job Title: Network Security Engineer

Duration: 3 Month

Location: Hybrid | Richmond, VA, (2 Days Remote + 3 Days Onsite as Required)

Position Summary

The Network Security Engineer will assess the network security controls supporting the OT environment. Primary areas include firewall and ACL configuration, network segmentation, VPN and remote access, Azure-hosted DMZ components, wireless security, boundary protections, and connectivity between external, DMZ, TOC, field, and internal OT zones.

The engineer will coordinate with the Lead Penetration Tester to validate whether configured network controls prevent or detect unauthorized movement across security boundaries.

Key Responsibilities

  • Review approved network diagrams, segmentation models, device configurations, firewall rules, ACLs, and remote-access architecture.
  • Confirm the placement of in-scope assets within the Purdue-style segmentation model.
  • Evaluate external network protections associated with approved OT-facing public IP addresses.
  • Assess Azure-hosted DMZ components, public-facing gateways, security groups, network controls, and connectivity into the OT environment.
  • Test segmentation boundaries between externally reachable assets, the DMZ, TOC resources, field-connected systems, and internal OT resources.
  • Evaluate firewall rules and ACLs for unnecessary access, overly broad permissions, insecure protocols, or unintended trust paths.
  • Assess VPN controls, remote-access boundaries, authentication paths, geolocation controls, and access integrity.
  • Validate network reachability from approved internal starting points.
  • Review network trust relationships and identify paths that could support unauthorized lateral movement.
  • Assess wireless access points and controllers when included in the approved scope.
  • Support external discovery, service enumeration, packet analysis, and network-path validation.
  • Coordinate all active tests with the OT Security Specialist to prevent operational disruption.
  • Verify whether network and remote-access activity is visible to logging and monitoring systems.
  • Document segmentation gaps, firewall or ACL weaknesses, remote-access risks, and compensating controls.
  • Develop network-specific remediation recommendations, including rule changes, segmentation improvements, monitoring enhancements, and access-control restrictions.
  • Provide evidence and technical content for the DMZ, segmentation, and remote-access assessment report.
  • Support retesting of remediated Critical and High network findings.

Required Skills

  • Enterprise network security
  • Firewall and ACL assessment
  • Network segmentation testing
  • VPN and remote-access security
  • Azure networking and boundary security
  • TCP/IP, routing, switching, and network protocols
  • Network discovery and service enumeration
  • Packet analysis and traffic inspection
  • Wireless network security
  • Trust-path and lateral-movement analysis
  • Network security architecture
  • Secure remote administration
  • Network logging and monitoring
  • Technical evidence collection and report writing

Required Experience

  • Minimum five years of network security engineering or network security assessment experience
  • Experience evaluating enterprise firewalls, ACLs, VPNs, and segmented networks
  • Experience validating network controls through configuration review and technical testing
  • Experience assessing DMZ and remote-access architectures
  • Experience identifying unintended access paths across network security zones
  • Experience working with penetration testers and SOC personnel during security assessments
  • Experience developing practical network remediation recommendations

Desired Experience

  • Experience with OT or ICS network segmentation
  • Knowledge of the Purdue Model and industrial network zones
  • Experience assessing Azure network controls and cloud-connected environments
  • Experience with LTE-connected field environments
  • Familiarity with industrial protocols and field-connected devices
  • Experience supporting transportation, public safety, critical infrastructure, or government networks
  • Familiarity with NIST SP 800-82, NIST SP 800-53, CIS Controls, and MITRE ATT&CK for ICS

Desired Certifications

  • Certified Information Systems Security Professional, CISSP
  • Certified Ethical Hacker, CEH
  • CompTIA Security+
📍 Virginia, United States💼 Hybrid⏰ Full Time
Apply
Lead Penetration Tester

Job Title: Lead Penetration Tester

Duration: 3 Months

Location: Richmond, VA

Work Module: Hybrid

Position Summary

The Lead Penetration Tester will direct and perform the authorized gray-box penetration testing activities. The role covers targeted external exposure testing, internal assumed-breach testing, credential and access-path validation, TOC reachability testing, controlled adversarial scenarios, and attack-path analysis.

This individual will work closely with the Network Security Engineer and OT Security Specialist to ensure that testing is technically thorough without affecting traffic operations, OT availability, or public safety.

Job Description

  • Support development of the technical testing methodology and Rules of Engagement.
  • Confirm approved targets, test accounts, starting points, testing windows, prohibited techniques, and stop conditions before testing begins.
  • Conduct targeted discovery and enumeration of approved external OT-associated IP addresses and Azure-facing endpoints.
  • Identify externally exposed services, access points, authentication mechanisms, and potential attack paths.
  • Perform controlled exploitation of approved public-facing systems and services.
  • Conduct internal testing from -provided OT VDI, workstation, field-laptop, or equivalent approved starting points.
  • Evaluate credential exposure, credential reuse, local protections, host hardening, trust relationships, and access controls.
  • Assess whether an approved internal starting point can be used to reach in-scope TOC, DMZ, remote-access, or OT resources.
  • Evaluate whether testing activities generate the expected logs, alerts, analyst actions, and escalation activities .
  • Coordinate exploitation activity with the OT Security Specialist before interacting with operational systems.
  • Avoid denial-of-service testing, credential spraying, persistence installation, PLC logic changes, firmware changes, and other prohibited actions.
  • Stop testing immediately if operational instability, unsafe conditions, or unintended access is identified.
  • Document affected assets, timestamps, tools used, proof of exploitation, attack paths, and reproducible validation steps.
  • Assign CVSS scores and map relevant adversary behavior to MITRE ATT&CK or MITRE ATT&CK for ICS.
  • Develop practical remediation recommendations and identify opportunities to improve detection, logging, triage, and escalation.
  • Lead the preparation of external, internal, and consolidated penetration testing findings.
  • Support the final debrief and retesting of remediated Critical and High findings.

Required Skills

  • External and internal penetration testing
  • Gray-box security assessment
  • Ethical hacking and controlled exploitation
  • Assumed-breach testing
  • Attack-path development and validation
  • Credential exposure and credential-reuse testing
  • Host and application service enumeration
  • Windows and Linux security assessment
  • Active Directory security fundamentals
  • Remote-access and VPN security testing
  • Evidence collection and chain-of-custody practices
  • Vulnerability validation and CVSS scoring
  • MITRE ATT&CK and MITRE ATT&CK for ICS mapping
  • Technical report writing and remediation development
  • Safe penetration testing in operationally sensitive environments

Required Experience

  • Minimum five years of penetration testing, ethical hacking, or offensive security experience
  • Demonstrated experience performing external and internal penetration tests
  • Experience validating multi-stage attack paths rather than relying only on automated vulnerability scans
  • Experience conducting authenticated testing using approved accounts
  • Experience working under formal Rules of Engagement and defined stop-work procedures
  • Experience producing repeatable evidence and defensible technical findings
  • Experience presenting technical findings to security teams, system owners, and leadership

Desired Experience

  • OT or ICS penetration testing experience
  • Experience testing segmented networks that follow the Purdue Model
  • Experience working with SOC teams during controlled adversarial exercises
  • Experience assessing Azure-hosted boundary or DMZ environments
  • Experience supporting government or critical infrastructure clients
  • Familiarity with NIST SP 800-82, NIST SP 800-53, CIS Controls, SEC530, SEC520, and SEC502

Desired Certifications

  • Offensive Security Certified Professional, OSCP
  • Certified Ethical Hacker, CEH
  • CompTIA Security+
  • Equivalent penetration testing certifications may be presented where they demonstrate comparable technical capability.
📍 Virginia, United States💼 Hybrid⏰ Full Time
Apply

About us

Empresa registrada en Saplic