Vulnerability Management Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Vulnerability Management Analyst (Cybersecurity): Managing and analyzing vulnerability scans for the US International Defense Finance Agency (DFC) with an accent on risk assessment and POA&M management. Focus on validating scanner findings, coordinating remediation across teams, and ensuring compliance with NIST and FISMA standards.
Location: Remote (Must have an Active Public Trust clearance)
Company
provides specialized IT and cybersecurity services to federal government agencies.
What you will do
- Coordinate and analyze authenticated vulnerability scans using Tenable Nessus, Qualys, and Microsoft Defender.
- Validate findings, distinguish false positives, and assign risk severity using CVSS and threat intelligence.
- Create and maintain POA&M records in CSAM and track remediation tickets in ServiceNow.
- Coordinate with engineering, operations, and cloud teams to establish remediation ownership and timelines.
- Provide rapid analysis and impact assessments for CISA Known Exploited Vulnerabilities (KEV) and zero-day threats.
- Prepare risk-acceptance and exception packages for federal authorization.
Requirements
- Active Public Trust clearance.
- B.S. in Computer Science, IT, or a related field.
- 5+ years of cybersecurity experience, with 3+ years specifically in vulnerability management or security compliance.
- Hands-on experience with Tenable, Qualys, or Microsoft Defender.
- Working knowledge of FISMA, NIST RMF, NIST SP 800-53, and CISA KEV/BOD 22-01.
- Ability to communicate technical risks clearly to federal leaders and nontechnical stakeholders.
Nice to have
- Relevant certifications such as Security+, CySA+, CEH, GCVA, or CISSP.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →