96 vulnerability assessment analyst jobs at 69 companies in United States
1mo
Save
Mark Applied
Hide
1mo
VULNERABILITY ASSESSMENT ANALYST
Springfield, Virginia, United States
OnsiteFull Time
Quantum Research International: Privately held defense engineering and technology contractor serving U.S. and allied governments, armed forces, and industry customers.
Perform vulnerability assessments, track and remediate findings, analyze vulnerability and STIG data, prioritize remediation, and apply cybersecurity and privacy principles for NGA systems.
ShorePoint: Privately held cybersecurity services firm helping federal civilian, defense, and intelligence agencies protect missions and critical assets.
5+ YOE5+ years experience in vulnerability management, risk assessment, scanning, and security control evaluation; bachelor’s degree required; ability to obtain and maintain U.S. security clearance.
Risk Management Framework (RMF), Authorization to Operate (ATO)
Independent Software, Inc.: Private IT services firm providing cyber, intelligence, analytics, and software engineering to government and commercial clients.
7+ YOEBachelor's degree plus 7 years of ISSE experience or 11 years relevant experience; CISSP required; active TS/SCI with appropriate polygraph; Tenable, Nessus, Linux, Windows, STIG, and vulnerability assessment experience.
Tenable Security Center, Nessus, Linux, Windows, STIG, ACAS
RiVidium: RiVidium is a privately held federal contractor providing cybersecurity, IT, human-capital, and intelligence services to government agencies.
Bachelors degree, active TS/SCI clearance, IAT/IAM Level 2, skills in vulnerability scanning, penetration testing, risk assessment, log review, and familiarity with enclave/cyber defense policy.
The Coca-Cola CompanyNYSE: KO: Global beverage refreshing the world.
2+ YOERequires 2+ years in vulnerability management, application security, SOC, or related security operations; knowledge of OWASP Top 10, vulnerability validation, severity assessment, tracking platforms, and remediation workflows.
Purple Team Lead/Sr Vulnerability Assessment Analyst
Fort Bragg, North Carolina, United States
OnsiteFull Time
Sentar: Employee-owned cyber-intelligence contractor serving U.S. national-security agencies with cybersecurity, intelligence, and systems-engineering services.
7+ YOE7+ years leading penetration testing, Red Team, or Purple Team operations in DoD or federal environments; Secret clearance; offensive security, adversary emulation, and penetration testing expertise.
Information Assurance III (Vulnerability Assessment/ACAS Security Manager)
Montgomery, Alabama, United States
$75k-$80k/yrOnsiteFull Time
DLS Engineering Associates, Inc.: Woman-owned U.S. government contractor providing engineering, cybersecurity, logistics, IT, and program-management services to federal agencies.
5+ YOE5+ years using NESSUS, ACAS, DISA STIGs, Forescout, ESS; IAT-II certification and active Secret clearance required; ability to perform vulnerability assessments and produce reports.
Arizona or North Carolina or Texas or Virginia or Plano or Raleigh or Reston or Richardson or Tempe
OnsiteFull Time
InfosysNYSE: INFY: Global leader in next-generation digital services and consulting.
Bachelor's degree or equivalent experience; expertise in vulnerability governance, risk assessment, compliance monitoring, reporting, workflow documentation, remediation tracking, and technical writing. US work authorization required.
The Swift Group: Invisible by Design. Impossible to Ignore.
2+ YOEPerform vulnerability assessments and security analysis of systems, networks, hardware and software; recommend mitigations. Requires OS/network knowledge, risk analysis skills, and active TS/SCI with Polygraph and U.S. citizenship.
Applied Network Solutions: Veteran-owned IT consulting contractor providing network engineering, cybersecurity, and data science services to government and private-sector clients.
4+ YOERequires TS/SCI clearance and polygraph, a related degree, and 4–10 years of relevant experience depending on education. Requires red team experience, vulnerability analysis, threat assessment, and cryptographic security expertise.
Somerset Trust CompanyOTC: SOME: Independent community bank serving people and businesses in Pennsylvania, Maryland, and Virginia with banking and wealth-management services.
1+ YOEBachelor's degree or equivalent education and experience; 1–2 years of related experience may qualify. Requires expertise in security frameworks, risk assessment, vulnerability tools, operating systems, networking, Active Directory, and application security.
Newark or New Jersey or New York or Pennsylvania or Connecticut or Delaware
$98k-$133k/yrRemoteFull Time
Horizon Blue Cross Blue Shield of New Jersey: Not-for-profit New Jersey health insurer providing medical, dental, vision, and prescription coverage to individuals, employers, and public programs.
5+ YOE5+ years information security experience with 3+ years focused on vulnerability identification, assessment, and remediation; HS diploma required; bachelors preferred; required/ preferred security certifications (CISSP, GCTI, GIAC, CompTIA Security+, CEH); strong knowledge of vulnerability management, CVSS, OS platforms, and threat intelligence.
Nessus, Qualys, InsightVM (Nexpose), Recorded Future, ThreatConnect/ThreatStream, H-ISAC, NJCCIC, Microsoft PowerPoint, Visio, Microsoft Excel
SOS International: Technology and services integrator for government and defense missions.
3+ YOE3–5 years security experience performing vulnerability assessments and scanning across OS, databases, web apps and cloud; troubleshooting scan tools; automation and ISVM experience; Bachelor's degree; Secret clearance eligible.
Information System Vulnerability Management (ISVM)
Markon Solutions: Government consulting firm specializing in management and technical services.
11+ YOETS/SCI with poly, Bachelor's +11 years in cybersecurity, experience with Red/Blue/Purple team assessments, network analysis, MITRE ATT&CK, NIST/ISO 27001, Python automation, technical writing, and willingness to travel OCONUS.
Sr Cyber Security Vulnerability Management Analyst
Baltimore or Houston or Houston
$123k-$137k/yrHybridFull Time
Constellation Energy Generation, LLC: Private U.S. power generator and energy supplier serving wholesale, retail, commercial, public-sector, and residential customers.
5+ YOEBachelor's in Information Systems and 5 years' experience, or 9 years without a degree; 2 years in Agile, application security, or DevOps; expertise in vulnerability assessment, cloud, DevSecOps, and security tools.
Microsoft Azure, Google Cloud Platform (GCP), Amazon Web Services (AWS), Docker, Kubernetes, Chef, Terraform, Jenkins, GitHub, TeamCity, Fortify, ShiftLeft, Checkmarx, Invicti, WhiteSource, Jira, ServiceNow, GitLab, Bitbucket, Unix, SAST, DAST, IAST, SCA, OSA, CI/CD, DevOps, SCADA, ICS, Distribution Automation, Smart Grid, DMS, ECS, SDL, Active Directory, SQL, LDAP, Microsoft SharePoint, Cisco, IDS/IPS, SSL, TLS, IPSec, APIs, Azure AD, Agile
Peraton: Provider of mission-critical national security technologies and services.
2+ YOESenior analyst with extensive space/missional protection experience, TS/SCI with poly required, 2+ years hands-on with STK/DSS/SPADOC/ATLAS/ASW, orbital analysis, I&W, conjunction assessment, and threat/vulnerability assessments.
Elizabeth River Crossings: Private toll-road operator maintaining Virginia’s Downtown and Midtown tunnels and MLK Freeway extension for regional drivers.
3+ YOEBachelor's degree or equivalent experience, 3+ years in cybersecurity or related technology, and experience with monitoring, incident response, vulnerability management, risk assessment, and security frameworks.
Endpoint protection platforms, Firewalls, Microsoft 365, Microsoft Azure, AWS, Identity and access management, Security information and event management (SIEM), NIST Cybersecurity Framework, CIS Controls, ISO 27001, PCI DSS
Goldbelt: Alaska Native providing federal contracting and commercial services.
8+ YOETS/SCI required; 8+ years intelligence analysis experience (3+ years supporting space systems/USSF); expertise in mission assurance, FMA-C, MADSS, vulnerability assessment, and leading junior analysts.
Mission Assurance Database Support System (MADSS), Functional Mission Analysis - Cyber (FMA-C)