Jobs

Vulnerability Management Analyst - Hybrid

  • Job Title: Vulnerability Management Analyst

      Location: 1155 21st St NW Washington DC, District of Columbia 20036   Clearance Level:  Public Trust   Required Certification(s):  Current industry certification such as CASP, CAP, CISSP, CISM, GSEC, GMON, or Security+.   SUMMARY: The Vulnerability Management Analyst will join a team of cross-functional cybersecurity experts in support of a government agency's Governance, Risk and Compliance Program. As a member of this team, the Vulnerability Management Analyst will support ongoing vulnerability management activities and future initiatives to achieve the agency's strategic goals and objectives.  

    The ideal Vulnerability Management Analyst candidate is an independent, strong problem solver who thrives in fast-paced and evolving security environments. The candidate has a passion for mitigating security risk and isn't deterred by the rapidly evolving nature of the threat landscape. The Vulnerability Management Analyst will join a team of cross-functional cybersecurity experts in the performance of activities, including assessments & authorization (A&A) and ongoing authorization (OA), security engineering, identity and access management (IAM), cloud security architecture, vulnerability management, cybersecurity training, and policy development for a government agency.  The Vulnerability Management Analyst must have SME knowledge of scanning applications, to include Qualys, a deep understanding of vulnerability management, and the ability to implement effective strategies and approaches to communicate, coordinate, and mitigate vulnerability-related security risks.

      JOB DUTIES AND RESPONSIBILITIES  Leverage enterprise scanning applications or tools approved by the government in support of the Vulnerability Management Program. Provide routine and ad-hoc automated vulnerability scans, scans in support of audits, scan result analysis, and validation scans of remediated vulnerabilities identified during vulnerability assessments. Support vulnerability scans of information systems for on-premise and hybrid cloud systems, as necessary. Support scanning and testing at the application and database level and refine and mature scanning metrics and thresholds to improve program maturity. Normalize data and provide results to system owners, system administrators, and Information Systems Security Officers (ISSOs) in support of change requests, ongoing authorizations, or systems undergoing authorizations to operate. Analyze weekly DHS Cyber Hygiene reports, facilitate remediation of findings therein, and promote comprehensive scanning coverage of all Internet-reachable IT assets.  Identify corrective actions, compensating controls, and assist with POA&M development in the government agency's GRC tool. Identify mitigations for non-compliance, notify stakeholders of compliance issues and, where required, perform these mitigations. Take into account any infrastructure challenges and make recommendations for improvements where needed. This includes third party service provider hosted Software as a Service (SaaS), Platform as a Service (PaaS) instances as well as Infrastructure as a Service (IaaS) Provide expertise in the review of new vulnerability technologies and capabilities and interact with other technology divisions to facilitate deployment.   SUPERVISORY DUTIES This is non-supervisory position.   QUALIFICATIONS Required Certifications Current industry certification such as CASP, CAP, CISSP, CISM, GSEC, GMON, or Security+.   Education, Background, and Years of Experience Bachelor’s Degree in Computer Science, Computer Engineering, Information Systems. 7 years of experience in Information Assurance (IA) or cybersecurity with at least 3 years of experience in vulnerability management.   ADDITIONAL SKILLS & QUALIFICATIONS Required Skills Experience with vulnerability scanning applications, to include Qualys and DBProtect. Experience analyzing results, normalizing data, and communicating with broad IT/non-IT stakeholder groups. Experience with STIG compliance baselines. Experience with NIST 800-53 security controls and compliance frameworks, such as NIST CSF and NIST RMF. Excellent communication skills, including verbal and written. Strong presentation skills required.   Preferred Skills Experience with BurpSuite preferred. Experience facilitating and/or participating in risk acceptance reviews and approvals desired.   WORKING CONDITIONS Environmental Conditions Contractor site with 0% travel possible. Possible occasional off-hours work to support non-business hours scanning for critical systems. Customer site is a general office environment. Work is generally sedentary in nature but may require standing and walking for up to 10% of the time. The working environment is generally favorable. Lighting and temperature are adequate, and there are not hazardous or unpleasant conditions caused by noise, dust, etc. Work performed at customer site is within an office environment, with standard office equipment available.   Strength Demands Sedentary – 10 lbs. Maximum lifting, occasional lift/carry of small articles.  Some occasional walking or standing may be required.   Jobs are sedentary if walking and standing are required only occasionally, and all other sedentary criteria are met.   Physical Requirements Stand or Sit; Walk; Repetitive Motion; Use Hands / Fingers to Handle or Feel; See

Closing Statement:  

XOR Security, an Agile Defense Company  offers a very competitive benefits package including health insurance coverage from the first day of employment, 401k with a vested company match, vacation and supplemental insurance benefits.  

XOR Security, An Agile Defense Company  is an Equal Opportunity Employer (EOE). M/F/D/V.  

Citizenship Clearance Requirement  Applicants selected may be subject to a government security investigation and must meet eligibility requirements - US CITIZENSHIP and PUBLIC TRUST CLEARANCE REQUIRED.  

Cyber Security Jobs by Category

Cyber Security Salaries