26 vulnerability management analyst jobs at 23 companies in Edgewater, MD
1w
Save
Mark Applied
Hide
1w
Vulnerability Management Analyst
Bethesda, Maryland, United States
$110k-$130k/yrRemoteFull Time
SkyePoint Decisions: Provider of cybersecurity, infrastructure, and IT development services.
5+ YOEBachelor's in relevant field, U.S. citizenship, Public Trust eligibility, 5+ years cybersecurity/vulnerability management experience in federal environments, POA&M and remediation tracking experience, strong analytical and communication skills.
TIME Systems: Provider of technology, engineering, and management solutions for federal agencies.
4+ YOE4+ years cybersecurity/systems experience with ≥1 year in vulnerability management using Tenable/Nessus/ACAS, active DoD Secret clearance, CompTIA Security+ CE, knowledge of RMF, DISA STIGs, SCAP, NIST SP 800-53, and strong reporting and communication skills.
Tenable SecurityCenter, Nessus, Assured Compliance Assessment Solution (ACAS), SCAP Compliance Checker (SCC), eMASS, HBSS, PowerShell, Nessus API, Microsoft Windows Server, Red Hat Enterprise Linux (RHEL), VMware, Active Directory
Arizona or North Carolina or Texas or Virginia or Plano or Raleigh or Reston or Richardson or Tempe
OnsiteFull Time
InfosysNYSE: INFY: Provides IT consulting, software development, and business outsourcing services.
Bachelor's degree or equivalent experience; expertise in vulnerability governance, risk assessment, compliance monitoring, reporting, workflow documentation, remediation tracking, and technical writing. US work authorization required.
cFocus Software: Provides cybersecurity compliance and enterprise IT services for government.
5+ YOEActive Public Trust, BS in CS/IT or related,5+ years cybersecurity experience including 3+ in vulnerability management, hands-on Tenable Nessus/Qualys/Microsoft Defender, knowledge of NIST/FISMA/POA&M, strong writing and communication.
Tenable Nessus, Qualys, Microsoft Defender, CSAM, ServiceNow
Peraton: National security and mission-critical government technology services provider.
8+ YOE8+ years in security operations or vulnerability management; Bachelor in Cybersecurity/IT (or 4 years additional experience); hands-on vulnerability scanning, cloud compliance, ISVM, API scanning; Secret clearance and U.S. citizenship required.
Peraton: Provides advanced technology and mission support for government agencies.
8+ YOEBachelor's in Cybersecurity/IT (or 4 years' extra experience), 8+ years in security operations/vulnerability management (reduced with advanced degrees), hands-on ISVM and API scanning experience, automation and compliance familiarity, U.S. citizenship.
Chenega Corporation: Provides professional government, defense, and facility support services.
5+ YOEHigh school diploma; 5+ years DoD RMF cybersecurity experience; strong ACAS/STIG/IAVA/IAVM experience; TS/SCI with Gold or eligibility; Security+ or equivalent.
MaximusNYSE: MMS: Provides government health and human services program administration.
7+ YOERequires active Secret clearance, US citizenship, 7+ years in cybersecurity, and 4+ years managing POA&Ms, federal security frameworks, vulnerability and risk management. Daily onsite work and 24x7x365 on-call availability required.
NIST 800-53, Risk Management Framework (RMF), Federal Information Security Modernization Act (FISMA), antivirus software, vulnerability scanners, access control, endpoint protection, Public Key Infrastructure (PKI), Security Information and Event Management (SIEM), Data Loss Prevention (DLP)
Bluehawk: Provides intelligence, technology, and training to government agencies.
12+ YOEBachelor's degree, 12+ years supporting cyber or intelligence operations, active TS/SCI CI Poly, experience with cyber threat analysis, vulnerability assessments, program management, and Microsoft 365.
Bowman Consulting GroupNASDAQ: BWMN: Provider of engineering and infrastructure consulting services.
5+ YOE5+ years cybersecurity experience, familiarity with incident investigation, vulnerability management, cloud and Microsoft security technologies; bachelor’s degree or equivalent experience; preferred Security+/CySA+/CISSP/GIAC.
CrowdStrike, Microsoft Defender, Microsoft Sentinel, SIEM, EDR
Pueo Business Solutions: Providing cybersecurity, IT, and business intelligence to government agencies.
Bachelor's degree in related field, IAT Level II/III certification per DoD 8570/8140, Top Secret clearance with SCI eligibility, knowledge of RMF/NIST, vulnerability and POA&M management.
Apavo: Provides specialized cybersecurity services to the federal defense sector.
5+ YOEActive Top Secret/SCI clearance, 5+ years DoD/IC vulnerability management and RMF experience, ACAS operator/administrator training, DoD 8570/8140 IAT II/III certification, Bachelor's in cybersecurity/IT or equivalent.
Terrestris: Providing professional services and mission support to federal agencies.
2+ YOEAuthorization to work in the U.S. without sponsorship, ability to obtain Public Trust clearance, minimum 2 years patching and vulnerability management experience; CompTIA Security+ may substitute for 1 year of experience.
Enterprise Lifecycle Management Services (ELMS), Microsoft Endpoint Configuration Manager (MECM)
Washington or Atlanta or Austin or Baltimore or Chicago or Virginia
$94k-$131k/yrHybridFull Time
DLA Piper: Global law firm providing comprehensive legal and business services.
7+ YOE7+ years in cybersecurity, Bachelor's in Information Security/Cybersecurity required, professional certs (e.g., CISSP, GIAC, SANS) preferred, SIEM/EDR/IDS/IPS and vendor tool experience, incident response and vulnerability management expertise.
Security Incident and Event Management (SIEM), Endpoint Detection and Response (EDR), Intrusion Detection/Prevention Systems (IDS/IPS), Microsoft Defender, CrowdStrike, Palo Alto Networks, malware sandbox, DNS, Active Directory, Exchange
M9 Solutions: Provides IT modernization and technology services to federal agencies.
3+ YOEActive TS/SCI clearance, 3+ years intelligence experience, knowledge of cyber intelligence lifecycle, MITRE ATT&CK and D3FEND, Diamond Model, intrusion kill chain, IOC/IOA, vulnerability management, threat hunting, and required certifications (CySA+ or GCIA plus one of CFR, Network+, Security+, CEH).
CompQsoft: Provides IT consulting and software engineering for government agencies.
Active Secret clearance, IAT Level 2, ACAS experience, RMF/FISMA and DoD security controls knowledge, audit and vulnerability assessment experience, ability to prepare RMF packages and brief management.
ACAS, DoD IT Portfolio Repository (DITPR), STIGs, Risk Management Framework (RMF), Federal Information Security Management Act (FISMA)
Philadelphia or Atlanta or Atlantic City or Montgomery County or Boston or Charlotte or Chicago or Dallas or Denver or Chester County or Greensboro or Greenville or Kansas City or Las Vegas or Los Angeles or Miami or Minneapolis or Morristown or New York or Oklahoma City or Pittsburgh or Princeton or Raleigh or San Francisco or Sarasota or Seattle or Bucks County or Washington or West Palm Beach or Wilmington
$100k-$155k/yrOnsiteFull Time
Fox Rothschild: National law firm providing comprehensive legal services.
5+ YOEBachelor's in information security (or equivalent), 5+ years information security experience including security operations/incident response, knowledge of NIST and MITRE ATT&CK, threat & vulnerability management, playbook development, strong communication.
Tharros: Provides specialized cybersecurity defense and vulnerability research services.
10+ YOEActive TS/SCI eligibility, 10+ years IA experience, IAT Level III, RMF and vulnerability assessment experience, ability to lead teams and coordinate cyber risk and authorization activities.