Vulnerability Management Analyst

1 week, 1 day ago
Contract
Senior
Cybersecurity
Skyepoint Decisions

Skyepoint Decisions

Skyepoint Decisions specializes in providing comprehensive IT solutions for the federal government, focusing on cybersecurity architecture, critical infrastructure operations, and applications development and maintenance to support a secure and mobile ...

Internet Software & Services
51-250
Founded 2009

Description

  • Perform vulnerability assessments and analyze security weaknesses across information systems and infrastructure.
  • Review vulnerability scan results from enterprise security tools and validate findings for severity, exploitability, and impact.
  • Apply threat-informed prioritization using exploit intelligence, CISA KEV, mission criticality, system exposure, and compensating controls.
  • Assess vulnerability risk in the context of system criticality, data sensitivity, and organizational risk tolerance.
  • Develop dashboards, remediation metrics, trend analyses, and executive reporting products.
  • Track vulnerabilities through the full lifecycle from discovery to remediation, validation, and closure.
  • Coordinate with technical teams on remediation requirements, timelines, and escalation of overdue findings.
  • Maintain vulnerability repositories, remediation records, and status reporting.
  • Support continuous monitoring activities and analyze recurring vulnerability trends.
  • Collaborate with RMF/A&A teams on ATO activities and POA&M tracking.
  • Provide vulnerability evidence and documentation for audits, assessments, and authorization activities.

Requirements

  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Engineering, or a related field.
  • Minimum 5 years of experience in cybersecurity, vulnerability management, information assurance, or security operations supporting Federal environments.
  • Experience supporting POA&M development, remediation tracking, corrective action validation, or vulnerability closure activities.
  • Experience conducting vulnerability assessments and remediation tracking.
  • Experience analyzing vulnerability data and developing remediation recommendations.
  • Familiarity with NIST RMF (SP 800-37), NIST SP 800-53 Rev. 5, FISMA, federal cybersecurity compliance requirements, and risk assessment methodologies.
  • Strong analytical, problem-solving, and communication skills.
  • U.S. Citizenship required.
  • Ability to obtain and maintain a Public Trust.
  • One or more preferred certifications: Security+, CEH, CISSP, GVA, GISF, GSEC, CAP, CISM, or CRISC.
  • Experience supporting HHS or other Federal civilian agencies (preferred).
  • Experience working within FISMA-compliant environments (preferred).
  • Knowledge of cloud security and vulnerability management practices (preferred).
  • Experience supporting continuous diagnostics and mitigation (CDM) initiatives (preferred).
  • Understanding of FedRAMP and Zero Trust security principles (preferred).
  • Experience coordinating remediation activities across multiple stakeholders (preferred).

Benefits

  • Salary range of $110,000 to $130,000.
  • Certification incentive program.
  • Flexible work environment.
  • PTO and floating federal holiday options.
  • Medical coverage options including HMO and High Deductible plans with HSAs and FSAs.
  • Dental, vision, short-term disability, long-term disability, and life insurance.
  • 401(k) with company match.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

OSINT Trainer and Investigator - Contractor - Burmese speaker - Myanmar

Centre for Information Resilience 11-50 Diversified Consumer Services

Centre for Information Resilience is hiring a remote contractor to support Myanmar Witness’s capacity-building, open-source investigations, and engagement with civil society partners on conflict-related human rights documentation in Myanmar.

1 week, 1 day ago

Cyber Detection and Response Analyst, Asia Pacific

Control Risks 1K-5K Professional Services

Cyber Detection and Response Analyst at a global security team, supporting 24/7 threat detection, investigation, and response across a client environment.

AWS Azure CrowdStrike Cybersecurity GCP SIEM Splunk
2 weeks, 5 days ago

Fractional Cyber Security Analyst (Advisor Network)

Arootah 11-50 Professional Services

Arootah is seeking an experienced Cybersecurity Analyst to join its advisor network and support hedge fund and family office clients on project-based cybersecurity engagements.

Active Directory Azure Cybersecurity Encryption Network Security Penetration Testing SQL Windows Server
3 weeks, 1 day ago

Surveillance Officer

Prevail Partners 11-50 Professional Services

Prevail Partners is seeking experienced Surveillance Officers to support an Ultra High Net Worth client through discreet protective surveillance operations within a specialist security programme.

4 weeks, 1 day ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers