Logo for Invicta Solutions Group

Senior Security Consultant – Tenable One / Exposure Management

Role overview

Qualifications

  • 5+ years of cybersecurity engineering, vulnerability management, security consulting, or related experience
  • 3+ years of hands-on enterprise vulnerability-management platform experience
  • Demonstrated hands-on experience with Tenable Vulnerability Management and/or Tenable One
  • Strong understanding of credentialed Windows and Linux vulnerability scanning

Responsibilities

  • Serve as the technical lead and design authority for the Tenable One implementation and provide technical direction to implementation consultants and engineers
  • Develop and govern the high-level and detailed solution architecture
  • Lead architecture and design for Tenable Vulnerability Management, including scanner sizing and placement
  • Define integration architecture between Tenable and other required enterprise platforms

Key facts

Other skills

  • Collaboration
  • Problem Solving

About the company

Invicta Solutions Group logo

Invicta Solutions Group

IT Services & IT Consulting

We are the tool chest for working CISO’s. Process, platforms, and people that simplify business technology security.Challenges with cyber security operations, cloud security, resource management, or technology selection are resolved with our mix of uniquely qualified staff or through our formal partner network.Our ISO 9001 certified, SDVOSB, HUBZone organization offers strategic and tactical solutions to both commercial enterprises and federal contractors. Invicta Solutions Group provides resource expertise in cloud security, cybersecurity, and emerging technologies. With a mature business model, past performance, and technical certifications we help Prime Contractors achieve small business goals while delivering projects on time and on budget.

Company details

Company typeScaleup
IndustryIT Services & IT Consulting
Company size11 - 50

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

This is a remote position.

Position Summary

Invicta Solutions Group is seeking experienced Senior Security Consultants – Tenable One / Exposure Management to provide hands-on technical implementation, engineering, testing, documentation, and operationalization support for a comprehensive enterprise Tenable One deployment.

Senior Security Consultants will work under the technical direction of the Principal Security Architect and will be responsible for implementing and validating individual exposure-management workstreams.

The engagement requires strong hands-on expertise with Tenable One and the broader Tenable product ecosystem, particularly Tenable Vulnerability Management. Depending upon specialization, consultants may also support Tenable Web Application Scanning, Attack Surface Management, Tenable Cloud Security/CNAPP, Tenable Identity Exposure, Exposure View, Attack Path Analysis, CrowdStrike integrations, Falcon Next-Gen SIEM, Jira, APIs, reporting, testing, documentation, training, and operational transition.

Primary Responsibilities

·        Serve as the technical lead and design authority for the Tenable One implementation and provide technical direction to implementation consultants and engineers.

·        Develop and govern the high-level and detailed solution architecture, including Tenable tenant design, scanner topology, network flows, credential architecture, RBAC, service accounts, asset taxonomy, tagging, ownership, criticality, and asset matching/deduplication.

·        Lead architecture and design for Tenable Vulnerability Management, including scanner sizing and placement, authenticated scanning, credential strategy, scan policies, asset discovery, risk-based prioritization, and vulnerability-management workflows.

·        Provide architecture oversight for Tenable Web Application Scanning, Attack Surface Management, Cloud Security/CNAPP, and Identity Exposure, including hybrid Active Directory/Entra ID environments and Secure Relay architecture.

·        Design and govern Exposure View and Attack Path Analysis, including critical assets, business services, risk scoring, identity/cloud context, critical targets, choke points, and infrastructure/identity/cloud-enriched Attack Paths.

·        Define integration architecture between Tenable and CrowdStrike Falcon, Falcon Next-Gen SIEM, Jira, Azure, Microsoft Graph, Active Directory, Entra ID, and other required enterprise platforms.

·        Establish standards for asset correlation, API integrations, event schemas, CVE/KEV/VPR mappings, remediation routing, exception workflows, SLA management, and validation processes.

·        Coordinate technical dependencies and architectural decisions across parallel implementation workstreams and serve as the escalation point for complex technical issues.

·        Lead technical design reviews, testing strategy, production-readiness assessments, UAT oversight, cutover planning, rollback planning, and technical solution acceptance.

·        Provide technical oversight for operational policies, SOPs, runbooks, dashboards, KPIs/SLAs, governance processes, administrator training, knowledge transfer, transition, and production hypercare.

Required Technical Skills

  • 5+ years of cybersecurity engineering, vulnerability management, security consulting, or related experience.
  • 3+ years of hands-on enterprise vulnerability-management platform experience.
  • Demonstrated hands-on experience with Tenable Vulnerability Management and/or Tenable One.
  • Experience deploying and configuring Tenable scanners.
  • Strong understanding of credentialed Windows and Linux vulnerability scanning.
  • Experience developing and tuning vulnerability scan policies.
  • Understanding of enterprise network technologies including routing, firewalls, DNS, proxies, authentication, and network segmentation.
  • Experience troubleshooting scan connectivity and credential failures.
  • Strong understanding of vulnerability-management lifecycle processes.
  • Knowledge of CVSS, VPR, EPSS, KEV, exploitability, and risk-based vulnerability prioritization.
  • Experience with asset tagging, ownership, reconciliation, and deduplication.
  • Experience creating technical dashboards and security reports.
  • Experience integrating enterprise security platforms through APIs.
  • Strong technical troubleshooting capabilities.
  • Strong technical documentation skills.
  • Ability to work effectively in a complex enterprise environment involving security, infrastructure, identity, cloud, application, and operations teams.

 

Required Experience

·        8-10 years of cybersecurity experience, with significant experience in security architecture, vulnerability management, exposure management, security engineering, or enterprise security consulting.

·        5+ years designing or leading enterprise vulnerability-management or exposure-management implementations, preferably in large, complex environments.

·        Demonstrated architecture and implementation experience with Tenable One and Tenable Vulnerability Management, including enterprise scanner architecture, authenticated scanning, asset management, tagging, dashboards, and reporting.

·        Strong experience designing risk-based vulnerability-management programs using VPR, CVSS, CISA KEV, EPSS, exploitability, internet exposure, business criticality, and asset context.

·        Experience with one or more advanced Tenable capabilities, preferably Tenable Identity Exposure, Tenable Cloud Security/CNAPP, Web Application Scanning, Attack Surface Management, Exposure View, or Attack Path Analysis.

·        Experience designing integrations between vulnerability/exposure-management platforms and enterprise technologies such as CrowdStrike, SIEM platforms, Jira, Azure, Active Directory, Entra ID, Microsoft Graph, and REST APIs.

·        Strong experience with enterprise asset discovery, reconciliation, matching, deduplication, ownership, criticality, and business-service mapping.

·        Experience designing security architectures across hybrid infrastructure, cloud, identity, endpoint, and application environments.

·        Demonstrated experience leading multi-workstream security implementations involving architecture, engineering, integration, testing, production rollout, and operational transition.

·        Experience conducting technical design reviews, production-readiness assessments, UAT, cutover planning, technical acceptance, and executive/technical stakeholder presentations.

·        Strong technical documentation skills, including development or oversight of architecture documents, detailed designs, operational standards, SOPs, runbooks, and technical acceptance criteria.

Preferred Qualifications

·        Tenable product certifications or equivalent demonstrated Tenable implementation expertise.

·        CISSP, ISSAP, CCSP, GIAC, Microsoft Azure security, or comparable security certifications.

·        Previous experience implementing exposure-management capabilities within a managed security services or large enterprise operating model.

Ideal Candidate Profile

The strongest candidates will be Tenable practitioners rather than candidates whose experience is limited to reviewing vulnerability reports or operating scanners. They should understand how to design, configure, integrate, troubleshoot, and operationalize Tenable within a large enterprise environment.



Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Consultant Related jobs

Other jobs at Invicta Solutions Group

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.