24 vulnerability management analyst jobs at 20 companies in Countryside, VA
3w
Save
Mark Applied
Hide
3w
Vulnerability Management Analyst
Bethesda, Maryland, United States
$110k-$130k/yrRemoteFull Time
SkyePoint Decisions: Provider of cybersecurity, infrastructure, and IT development services.
5+ YOEBachelor's in relevant field, U.S. citizenship, Public Trust eligibility, 5+ years cybersecurity/vulnerability management experience in federal environments, POA&M and remediation tracking experience, strong analytical and communication skills.
TIME Systems: Provider of technology, engineering, and management solutions for federal agencies.
4+ YOE4+ years cybersecurity/systems experience with ≥1 year in vulnerability management using Tenable/Nessus/ACAS, active DoD Secret clearance, CompTIA Security+ CE, knowledge of RMF, DISA STIGs, SCAP, NIST SP 800-53, and strong reporting and communication skills.
Tenable SecurityCenter, Nessus, Assured Compliance Assessment Solution (ACAS), SCAP Compliance Checker (SCC), eMASS, HBSS, PowerShell, Nessus API, Microsoft Windows Server, Red Hat Enterprise Linux (RHEL), VMware, Active Directory
Arizona or North Carolina or Texas or Virginia or Plano or Raleigh or Reston or Richardson or Tempe
OnsiteFull Time
InfosysNYSE: INFY: Provides IT consulting, software development, and business outsourcing services.
Bachelor's degree or equivalent experience; expertise in vulnerability governance, risk assessment, compliance monitoring, reporting, workflow documentation, remediation tracking, and technical writing. US work authorization required.
cFocus Software: Provides cybersecurity compliance and enterprise IT services for government.
5+ YOEActive Public Trust, BS in CS/IT or related,5+ years cybersecurity experience including 3+ in vulnerability management, hands-on Tenable Nessus/Qualys/Microsoft Defender, knowledge of NIST/FISMA/POA&M, strong writing and communication.
Tenable Nessus, Qualys, Microsoft Defender, CSAM, ServiceNow
Absolute Business Solutions Corp: Provides technology and intelligence services to the US government.
5+ YOEBachelor's degree in a technical discipline and Security+ CE or equivalent IAT Level II certification, or qualifying master's degree or 5 years of relevant experience. Requires DoD experience and English proficiency.
Assured Compliance Assessment Solution (ACAS), Tenable Security Center, Nessus, Microsoft Endpoint Configuration Manager (MECM), SCCM, NIPRNet, SIPRNet, NIST, DISA STIGs, SRGs, RMF, POA&Ms, IAVMs, TCNOs, TASKORDs
Peraton: National security and mission-critical government technology services provider.
8+ YOE8+ years in security operations or vulnerability management; Bachelor in Cybersecurity/IT (or 4 years additional experience); hands-on vulnerability scanning, cloud compliance, ISVM, API scanning; Secret clearance and U.S. citizenship required.
Peraton: Provides advanced technology and mission support for government agencies.
8+ YOEBachelor's in Cybersecurity/IT (or 4 years' extra experience), 8+ years in security operations/vulnerability management (reduced with advanced degrees), hands-on ISVM and API scanning experience, automation and compliance familiarity, U.S. citizenship.
Chenega Corporation: Provides professional government, defense, and facility support services.
5+ YOEHigh school diploma; 5+ years DoD RMF cybersecurity experience; strong ACAS/STIG/IAVA/IAVM experience; TS/SCI with Gold or eligibility; Security+ or equivalent.
American Systems: Providing engineering and IT solutions to federal government agencies.
1+ YOEU.S. citizen with active Secret clearance (Top Secret/SCI desired), 1+ year cybersecurity analyst experience, familiarity with Splunk/ACAS/Nessus/Qualys, strong incident response and vulnerability management skills, and relevant security certifications (CompTIA Security+, CASP, or CISSP).
Bluehawk: Provides intelligence, technology, and training to government agencies.
12+ YOEBachelor's degree, 12+ years supporting cyber or intelligence operations, active TS/SCI CI Poly, experience with cyber threat analysis, vulnerability assessments, program management, and Microsoft 365.
MaximusNYSE: MMS: Provides government health and human services program administration.
7+ YOERequires active Secret clearance, US citizenship, 7+ years in cybersecurity, and 4+ years managing POA&Ms, federal security frameworks, vulnerability and risk management. Daily onsite work and 24x7x365 on-call availability required.
NIST 800-53, Risk Management Framework (RMF), Federal Information Security Modernization Act (FISMA), antivirus software, vulnerability scanners, access control, endpoint protection, Public Key Infrastructure (PKI), Security Information and Event Management (SIEM), Data Loss Prevention (DLP)
Bowman Consulting GroupNASDAQ: BWMN: Provider of engineering and infrastructure consulting services.
5+ YOE5+ years cybersecurity experience, familiarity with incident investigation, vulnerability management, cloud and Microsoft security technologies; bachelor’s degree or equivalent experience; preferred Security+/CySA+/CISSP/GIAC.
CrowdStrike, Microsoft Defender, Microsoft Sentinel, SIEM, EDR
Pueo Business Solutions: Providing cybersecurity, IT, and business intelligence to government agencies.
Bachelor's degree in related field, IAT Level II/III certification per DoD 8570/8140, Top Secret clearance with SCI eligibility, knowledge of RMF/NIST, vulnerability and POA&M management.
A3 Technology: Provides engineering and technical services for federal aviation programs.
2+ YOEExperience in security analysis, risk assessment, or related analytical role; strong security principles, controls, and vulnerability management; ability to communicate findings clearly; strong written/verbal communication; ability to work independently and collaboratively.
Terrestris: Providing professional services and mission support to federal agencies.
2+ YOEAuthorization to work in the U.S. without sponsorship, ability to obtain Public Trust clearance, minimum 2 years patching and vulnerability management experience; CompTIA Security+ may substitute for 1 year of experience.
Enterprise Lifecycle Management Services (ELMS), Microsoft Endpoint Configuration Manager (MECM)
Washington or Atlanta or Austin or Baltimore or Chicago or Virginia
$94k-$131k/yrHybridFull Time
DLA Piper: Global law firm providing comprehensive legal and business services.
7+ YOE7+ years in cybersecurity, Bachelor's in Information Security/Cybersecurity required, professional certs (e.g., CISSP, GIAC, SANS) preferred, SIEM/EDR/IDS/IPS and vendor tool experience, incident response and vulnerability management expertise.
Security Incident and Event Management (SIEM), Endpoint Detection and Response (EDR), Intrusion Detection/Prevention Systems (IDS/IPS), Microsoft Defender, CrowdStrike, Palo Alto Networks, malware sandbox, DNS, Active Directory, Exchange
APV: Provides information technology and consulting services to government agencies.
8+ YOEBachelor's degree preferred, 8–10 years of federal cybersecurity experience, end-to-end ATO leadership, NIST and FISMA expertise, SIEM and vulnerability scanning experience, cloud security, U.S. citizenship, and DHS Public Trust eligibility.
Splunk, AWS Security Hub, Microsoft Sentinel, Nessus, Qualys, AWS GovCloud, Microsoft Azure Government, Microsoft SharePoint, REST, SOAP, SFTP, ETL, ELT, iPaaS, DevSecOps, NIST SP 800-37, NIST SP 800-53, NIST SP 800-218, FIPS 140-2, FIPS 140-3, FedRAMP, FISMA, CDM, TIC 3.0, SORN, NFC EmpowHR, USA Staffing, FedTalent, OPM eOPF, OPM Retirement Services Online, webTA, BENEFEDS, TSP, OMB M-22-09
Staff Mult Fnc Info Sys Analyst- TS/SCI W/Poly - Littleton, CO
Littleton or Denver or Bethesda
$118k-$219k/yrOnsiteFull Time
Lockheed MartinNYSE: LMT: Designs and manufactures advanced aerospace, defense, and security systems.
5+ YOEActive TS/SCI clearance with CI Poly, U.S. citizenship, Security+ certification, and 5+ years administering Linux and Windows servers. Requires DISA STIG, security hardening, virtualization, vulnerability remediation, and configuration management experience.
Windows Server, Linux, Microsoft Windows, Red Hat Enterprise Linux (RHEL), VMware, Hyper-V, Nessus, Trellix, Windows Server Update Services (WSUS), YUM, Microsoft System Center Configuration Manager (SCCM), Splunk, Assured Compliance Assessment Solution (ACAS), Security Content Automation Protocol (SCAP), Host-Based Security System (HBSS), Active Directory, NetApp, EMC, Ansible, Perl, Bash, PowerShell, Shell Scripting