123 vulnerability analyst jobs at 68 companies in Countryside, VA
1mo
Save
Mark Applied
Hide
1mo
Cybersecurity Vulnerability Analyst
Washington, District of Columbia, United States
RemoteFull Time
Covington & Burling LLP: International law firm advising sophisticated clients on complex corporate, litigation, regulatory, and policy matters.
3+ YOE3+ years vulnerability analysis (or 5+ years infosec) with hands-on scanner experience, knowledge of CVEs and risk frameworks, strong analysis and communication skills, and US export-control eligibility.
Quantum Research International: Privately held defense engineering and technology contractor serving U.S. and allied governments, armed forces, and industry customers.
Perform vulnerability assessments, track and remediate findings, analyze vulnerability and STIG data, prioritize remediation, and apply cybersecurity and privacy principles for NGA systems.
Booz Allen HamiltonNYSE: BAH: Global firm providing management, technology, and engineering consulting services.
4+ YOERequires 4+ years in vulnerability analysis, 2+ years administering Windows and UNIX, cloud security experience, vulnerability tools, networking knowledge, and ability to obtain Secret clearance.
Tenable Cloud Security, Tenable Security Center, AWS, Microsoft Azure, Google Cloud Platform, Nessus, Qualys, Splunk, OWASP, TCP, IP, UDP, HTTP, HTTPS, SSH, DNS, Windows, UNIX
Themis Insight: Private consulting firm providing business, IT, and analytics solutions to National Security clients.
5+ YOERequires TS/SCI with polygraph, relevant degree, and vulnerability analysis, penetration testing, or computer forensics experience. Level 2 or 3 experience and Information Assurance certification may be required.
DigiFlight: Veteran-owned minority U.S. defense contractor providing aviation, aerospace, intelligence, cybersecurity, and IT services.
4+ YOERequires security clearance, a relevant computer science or engineering degree, and 4–10 years of relevant experience in vulnerability analysis, penetration testing, computer forensics, or related cybersecurity fields.
Joint Cyber Analysis Course (JCAC), Undergraduate Cyber Training (UCT), Network Warfare Bridge Course (NWBC), Intermediate Network Warfare Training (INWT)
Arizona or North Carolina or Texas or Virginia or Plano or Raleigh or Reston or Richardson or Tempe
OnsiteFull Time
InfosysNYSE: INFY: Global leader in next-generation digital services and consulting.
Bachelor's degree or equivalent experience; expertise in vulnerability governance, risk assessment, compliance monitoring, reporting, workflow documentation, remediation tracking, and technical writing. US work authorization required.
The Swift Group: Invisible by Design. Impossible to Ignore.
2+ YOEPerform vulnerability assessments and security analysis of systems, networks, hardware and software; recommend mitigations. Requires OS/network knowledge, risk analysis skills, and active TS/SCI with Polygraph and U.S. citizenship.
AnaVation: Private federal IT contractor serving U.S. government agencies with intelligence, cloud, big-data, cybersecurity, and software-engineering services.
4+ YOEU.S. citizenship, TS/SCI clearance, bachelor's degree, DoD 8570 IAT Level II certification, and 4+ years of related experience. Requires ACAS, vulnerability remediation, cybersecurity operations, and communication skills.
Applied Network Solutions: Veteran-owned IT consulting contractor providing network engineering, cybersecurity, and data science services to government and private-sector clients.
4+ YOERequires TS/SCI clearance and polygraph, a related degree, and 4–10 years of relevant experience depending on education. Requires red team experience, vulnerability analysis, threat assessment, and cryptographic security expertise.
Areté: Employee-owned science and engineering developing sensing products and software for U.S. defense, intelligence, and commercial customers.
3+ YOERequires active Top Secret clearance, 3+ years in systems or vulnerability administration, Windows Server and Red Hat Linux expertise, scanning and patch management experience, and scripting skills. Security+ CE required within 120 days.
Rapid7, Tenable Security Center, Nessus, Qualys, PDQ Deploy, Microsoft System Center Configuration Manager (SCCM), Microsoft Endpoint Configuration Manager (MECM), Microsoft Windows Server Update Services (WSUS), YUM, DNF, Red Hat Satellite, PowerShell, Bash, Python, DISA STIGs, SCAP Compliance Checker, NIST 800-53, NIST 800-171, Risk Management Framework (RMF), Software Bill of Materials (SBOM), Microsoft AZ-800/801, Microsoft MD-102, GIAC GCED/GEVA, CCNA, Network+, CySA+, RHCSA
TIME Systems: Service-disabled veteran-owned IT, cybersecurity, engineering, and management consulting contractor serving government, corporate, and nonprofit clients.
4+ YOE4+ years cybersecurity/systems experience with ≥1 year in vulnerability management using Tenable/Nessus/ACAS, active DoD Secret clearance, CompTIA Security+ CE, knowledge of RMF, DISA STIGs, SCAP, NIST SP 800-53, and strong reporting and communication skills.
Tenable SecurityCenter, Nessus, Assured Compliance Assessment Solution (ACAS), SCAP Compliance Checker (SCC), eMASS, HBSS, PowerShell, Nessus API, Microsoft Windows Server, Red Hat Enterprise Linux (RHEL), VMware, Active Directory
M2 Technology Group: Private North Carolina managed IT and cybersecurity provider serving small and medium-sized businesses in the Raleigh area.
4+ YOESenior-level vulnerability analyst to perform assessments, threat/pen tests, forensic/system analysis, interface with mission partners, respond to RFIs; requires active security clearance with appropriate polygraph and advanced technical degree/experience.
RealmOne: Advanced technology services for national security and defense missions.
4+ YOEIdentify and analyze system vulnerabilities and attacks, exploit captured media, conduct incident investigations, perform vulnerability analysis/penetration testing/forensics, and produce reports and briefings; active security clearance with polygraph required.
GRVTY: Defense technology firm delivering automated intelligence and mission support.
4+ YOERequires a relevant degree and experience, red team experience, vulnerability analysis, network analysis, anomaly detection, incident investigation, and computer security expertise. Information assurance certification may be required.
Weeghman & Briggs: Veteran-owned IT consulting firm providing data analysis, cybersecurity, telematics, and training to government and private clients.
Active TS/SCI with Polygraph, experience supporting government or DoD programs, vulnerability analysis/penetration testing/forensics experience, strong written and verbal communication, ability to exploit captured media and investigate security incidents.
Independent Software, Inc.: Private IT services firm providing cyber, intelligence, analytics, and software engineering to government and commercial clients.
8+ YOERequires TS/SCI clearance with polygraph and a qualifying computer science or related degree plus relevant vulnerability analysis, penetration testing, or computer forensics experience.
Booz Allen HamiltonNYSE: BAH: Global firm providing management, technology, and engineering consulting services.
4+ YOERequires 4+ years in vulnerability analysis, 2+ years of Windows and UNIX administration, cloud security experience, Tenable tools, networking knowledge, and ability to obtain Secret clearance.
Microsoft Internet Explorer, Google Chrome, Mozilla Firefox, Microsoft Edge, Apple Safari, Opera Browser, Blackberry Browser, AWS, Azure, Google Cloud Platform, Tenable Cloud Security, Tenable Security Center, Nessus, Qualys, Splunk, TCP, IP, UDP, HTTP, HTTPS, SSH, DNS, OWASP
Absolute Business Solutions Corp: Delivering Technology Enabled Solutions to Continuously Advance Intelligence
5+ YOEBachelor's degree in a technical discipline and Security+ CE or equivalent IAT Level II certification, or qualifying master's degree or 5 years of relevant experience. Requires DoD experience and English proficiency.
Assured Compliance Assessment Solution (ACAS), Tenable Security Center, Nessus, Microsoft Endpoint Configuration Manager (MECM), SCCM, NIPRNet, SIPRNet, NIST, DISA STIGs, SRGs, RMF, POA&Ms, IAVMs, TCNOs, TASKORDs