Назад
Company hidden
2 дня назад

Vulnerability Management Analyst (Cybersecurity)

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Vulnerability Management Analyst (Cybersecurity): Managing and analyzing vulnerability scans for the US International Defense Finance Agency (DFC) with an accent on risk assessment and POA&M management. Focus on validating scanner findings, coordinating remediation across teams, and ensuring compliance with NIST and FISMA standards.

Location: Remote (Must have an Active Public Trust clearance)

Company

hirify.global provides specialized IT and cybersecurity services to federal government agencies.

What you will do

  • Coordinate and analyze authenticated vulnerability scans using Tenable Nessus, Qualys, and Microsoft Defender.
  • Validate findings, distinguish false positives, and assign risk severity using CVSS and threat intelligence.
  • Create and maintain POA&M records in CSAM and track remediation tickets in ServiceNow.
  • Coordinate with engineering, operations, and cloud teams to establish remediation ownership and timelines.
  • Provide rapid analysis and impact assessments for CISA Known Exploited Vulnerabilities (KEV) and zero-day threats.
  • Prepare risk-acceptance and exception packages for federal authorization.

Requirements

  • Active Public Trust clearance.
  • B.S. in Computer Science, IT, or a related field.
  • 5+ years of cybersecurity experience, with 3+ years specifically in vulnerability management or security compliance.
  • Hands-on experience with Tenable, Qualys, or Microsoft Defender.
  • Working knowledge of FISMA, NIST RMF, NIST SP 800-53, and CISA KEV/BOD 22-01.
  • Ability to communicate technical risks clearly to federal leaders and nontechnical stakeholders.

Nice to have

  • Relevant certifications such as Security+, CySA+, CEH, GCVA, or CISSP.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →