S. Citizenship is required due to federal contract obligations, along with the ability to ... Deliver threat modeling analysis for critical applications and ensure WASP findings feed ...
S. Citizenship is required due to federal contract obligations, along with the ability to ... Deliver threat modeling analysis for critical applications and ensure WASP findings feed ...
The CE performs CS engineering and vulnerability analysis activities to ensure the confidentiality ... contract). * Computing Environment (CE) Certification: one or more of the following Microsoft ...
The CE performs CS engineering and vulnerability analysis activities to ensure the confidentiality ... contract). * Computing Environment (CE) Certification: one or more of the following Microsoft ...
... App Vulnerability Management Support Services contract. The TOPM provides overall leadership ... and CS analysts who conduct vulnerability assessments, security engineering analysis, risk ...
... App Vulnerability Management Support Services contract. The TOPM provides overall leadership ... and CS analysts who conduct vulnerability assessments, security engineering analysis, risk ...
This is a fully remote position and contingent on contract award. Job Summary BMA is seeking a ... Continuous Monitoring and Vulnerability Analysis: Conduct cybersecurity control validation ...
This is a fully remote position and contingent on contract award. Job Summary BMA is seeking a ... Continuous Monitoring and Vulnerability Analysis: Conduct cybersecurity control validation ...
SOC Tier 1 Analyst
Portland, OR · On-site
This position is contingent upon contract award. The SOC Analyst 1 supports the organization ... vulnerability platforms in accordance with approved procedures. * Follow playbooks, standard ...
SOC Tier 1 Analyst
Portland, OR · On-site
This position is contingent upon contract award. The SOC Analyst 1 supports the organization ... vulnerability platforms in accordance with approved procedures. * Follow playbooks, standard ...
Security Engineer
Portland, OR · On-site
This position is contingent upon contract award. The Security Engineer supports the design ... Vulnerability, Risk & Remediation Support * Analyze vulnerability scan results, configuration ...
Security Engineer
Portland, OR · On-site
This position is contingent upon contract award. The Security Engineer supports the design ... Vulnerability, Risk & Remediation Support * Analyze vulnerability scan results, configuration ...
Senior Contracts Manager (REMOTE)
OR · On-site +1
... vulnerability management with data insights gleaned from assets, users, malware, attackers, and ... As a result, organizations can increase speed and accuracy while reducing costs and analyst burnout.
Senior Contracts Manager (REMOTE)
OR · On-site +1
... vulnerability management with data insights gleaned from assets, users, malware, attackers, and ... As a result, organizations can increase speed and accuracy while reducing costs and analyst burnout.
Senior Security Engineer
Portland, OR · On-site
$121K - $166K/yr
Note: This position is contingent upon contract award. The Senior Security Engineer plays a ... Oversee vulnerability management efforts, including prioritization and remediation guidance
Senior Security Engineer
Portland, OR · On-site
$121K - $166K/yr
Note: This position is contingent upon contract award. The Senior Security Engineer plays a ... Oversee vulnerability management efforts, including prioritization and remediation guidance
Cybersecurity Risk Analysis and Vulnerability Management: Analyzes security findings and ... contracts. * At least one year of program or project management experience. * Current Project ...
Cybersecurity Risk Analysis and Vulnerability Management: Analyzes security findings and ... contracts. * At least one year of program or project management experience. * Current Project ...
OR · On-site
$110 - $160/hr
... service contracts and licensing. * Collaborate with business leaders to align work with the ... analysis. * Strong understanding of network transport protocols, ITIL concepts, vulnerability ...
OR · On-site
$110 - $160/hr
... service contracts and licensing. * Collaborate with business leaders to align work with the ... analysis. * Strong understanding of network transport protocols, ITIL concepts, vulnerability ...
Enterprise Security Engineer II
OR · On-site +1
... contracts, invoices, employee records, financials, product specs, marketing assets, and more. Our ... vulnerability management, endpoint management, and system hardening * SIEM and security analytics ...
New
Enterprise Security Engineer II
OR · On-site +1
... contracts, invoices, employee records, financials, product specs, marketing assets, and more. Our ... vulnerability management, endpoint management, and system hardening * SIEM and security analytics ...
New
This is a fully remote position and contingent on contract award. Job Summary BMA is seeking a ... Strategic Analysis and Innovation: Conducts research and analysis of emerging cybersecurity threats ...
This is a fully remote position and contingent on contract award. Job Summary BMA is seeking a ... Strategic Analysis and Innovation: Conducts research and analysis of emerging cybersecurity threats ...
Patch Plan Program Manager
Portland, OR · On-site
$54 - $64/hr
Employment Type: Long-Term Contract Pay Rate: $64/hour W2 Location: Hybrid in Portland, Oregon ... Strong analytical, problem-solving, and critical-thinking skills with excellent attention to detail.
Quick apply
Patch Plan Program Manager
Portland, OR · On-site
$54 - $64/hr
Employment Type: Long-Term Contract Pay Rate: $64/hour W2 Location: Hybrid in Portland, Oregon ... Strong analytical, problem-solving, and critical-thinking skills with excellent attention to detail.
Cyber Security Tutor
Eugene, OR · Remote
$18 - $40/hr
Deep knowledge of network security, cryptography, threat analysis, vulnerability assessment ... Varsity Tutors does not contract in: Alaska, California, Colorado, Delaware, Hawaii, Maine, New ...
Cyber Security Tutor
Eugene, OR · Remote
$18 - $40/hr
Deep knowledge of network security, cryptography, threat analysis, vulnerability assessment ... Varsity Tutors does not contract in: Alaska, California, Colorado, Delaware, Hawaii, Maine, New ...
Cyber Security Tutor
Portland, OR · Remote
$18 - $40/hr
Deep knowledge of network security, cryptography, threat analysis, vulnerability assessment ... Varsity Tutors does not contract in: Alaska, California, Colorado, Delaware, Hawaii, Maine, New ...
Cyber Security Tutor
Portland, OR · Remote
$18 - $40/hr
Deep knowledge of network security, cryptography, threat analysis, vulnerability assessment ... Varsity Tutors does not contract in: Alaska, California, Colorado, Delaware, Hawaii, Maine, New ...
Cyber Security Tutor
OR · Remote
$18 - $40/hr
Deep knowledge of network security, cryptography, threat analysis, vulnerability assessment ... Varsity Tutors does not contract in: Alaska, California, Colorado, Delaware, Hawaii, Maine, New ...
Cyber Security Tutor
OR · Remote
$18 - $40/hr
Deep knowledge of network security, cryptography, threat analysis, vulnerability assessment ... Varsity Tutors does not contract in: Alaska, California, Colorado, Delaware, Hawaii, Maine, New ...
Note: This position is contingent upon contract award. The Operational Technology (OT) Control ... OT/ICS Environment Analysis * Review OT architecture, network segmentation, data flows, asset ...
Note: This position is contingent upon contract award. The Operational Technology (OT) Control ... OT/ICS Environment Analysis * Review OT architecture, network segmentation, data flows, asset ...
$134K - $192K/yr
... Data Analytics and Visualization, Information Assurance, and Business Process Re-Engineering ... Perform regular security assessments and vulnerability scans. * Maintain comprehensive ...
$134K - $192K/yr
... Data Analytics and Visualization, Information Assurance, and Business Process Re-Engineering ... Perform regular security assessments and vulnerability scans. * Maintain comprehensive ...
Both positions are designated Key Personnel under the contract. Duties and Responsibilities ... Use JAMF and Microsoft Intune for endpoint automation and configuration management; analyze Windows ...
Both positions are designated Key Personnel under the contract. Duties and Responsibilities ... Use JAMF and Microsoft Intune for endpoint automation and configuration management; analyze Windows ...
Analyze business needs; partner with leaders across the organization in order to research and ... Maintain service contracts and licensing; negotiate with outside parties; escalate issues as needed.
Analyze business needs; partner with leaders across the organization in order to research and ... Maintain service contracts and licensing; negotiate with outside parties; escalate issues as needed.
Contract Vulnerability Analyst information
What are some common challenges faced by contract vulnerability analysts, and how can they overcome them?
What is a contract vulnerability analyst?
What is the difference between Contract Vulnerability Analyst vs Security Analyst?
| Aspect | Contract Vulnerability Analyst | Security Analyst |
|---|---|---|
| Certifications | CompTIA Security+, CEH, CISSP (preferred) | CompTIA Security+, CISSP, CISA |
| Work Environment | Contract-based, project-specific roles, often remote or on-site | Full-time, in-house or remote security teams within organizations |
| Industry Usage | IT security firms, consulting companies, tech organizations | Corporate, government, financial institutions |
| Search & Comparison Intent | Focus on vulnerability assessment, penetration testing, security gaps | Broader security management, incident response, policy enforcement |
The Contract Vulnerability Analyst primarily focuses on identifying and mitigating security vulnerabilities through assessments and testing, often working on a contractual basis. In contrast, a Security Analyst typically handles ongoing security monitoring, incident response, and policy implementation within an organization. While both roles require similar certifications and work in the cybersecurity field, their scope and employment structure differ significantly.
What are the key skills and qualifications needed to thrive as a contract vulnerability analyst, and why are they important?
What are the most commonly searched types of Vulnerability Analyst jobs in Oregon?
The most popular types of Vulnerability Analyst jobs in Oregon are:
What are popular job titles related to Contract Vulnerability Analyst jobs in Oregon?
For Contract Vulnerability Analyst jobs in Oregon, the most frequently searched job titles are:
What job categories do people searching Contract Vulnerability Analyst jobs in Oregon look for?
The top searched job categories for Contract Vulnerability Analyst jobs in Oregon are:
What cities in Oregon are hiring for Contract Vulnerability Analyst jobs?
Cities in Oregon with the most Contract Vulnerability Analyst job openings:

Full-time
Medical, Dental, Vision, Life
Re-posted 11 days ago
Job description
Valiant Solutions is seeking a Vulnerability Management Lead to join our rapidly growing and innovative cybersecurity team!
The Vulnerability Management Lead directs client's vulnerability management program across the Continuous Diagnostics and Mitigation (CDM), Web Application Surveillance Program (WASP), and Cyber Hygiene workstreams within the Cybersecurity Services Division. The lead owns the end-to-end process from discovery and scanning through remediation tracking and Plan of Action and Milestones (POA&M) closure, working across Information System Owners (ISOs), Information System Security Officers (ISSOs), the Policy, Risk & Compliance branch, and engineering teams. The role produces the dashboards, metrics, and reporting that give client leadership a current view of agency risk and progress against remediation targets.
Named one of the Best Places to Work in the Washington DC area for 12 consecutive years, Valiant is proud of our employee-centric culture and commitment to excellence. If you are interested in learning more about Valiant and this opportunity, we invite you to apply now!
Location: The Vulnerability Management Lead can expect 100% telework. Remote work requires a high level of trust in our employees, and we strictly adhere to the details outlined in our Remote Work Policy below.Â
Eligibility Requirements: U.S. Citizenship is required due to federal contract obligations, along with the ability to successfully pass a federal background investigation.
Required Experience:
- Six or more years of cybersecurity experience, including hands-on work with operating systems (Windows, Linux) and networking (TCP/IP, routing, firewalls, segmentation).
- At least one of the following certifications: GCIH, CISSP, CISM, or CRISC.
- Hands-on experience with Tenable (Tenable ONE, Nessus, or Tenable.io), AquaSec, and CDM integration in a federal or large enterprise environment.
- Working knowledge of DHS CDM Program requirements, NIST SP 800-137 (Information Security Continuous Monitoring), NIST SP 800-53 controls (in particular RA-5 and SA-11), DHS BOD 18-01, and CISA Cyber Hygiene Services.
- Experience supporting POA&M development, remediation tracking, and closure within Cyber Security Assessment and Management (CSAM) or a comparable governance, risk, and compliance system.
- Demonstrated ability to build dashboards and metrics that translate scan output into prioritized, executable remediation work for technical and executive audiences.
- Strong written and verbal communication skills, with the ability to coordinate across ISOs, ISSOs, compliance, and engineering stakeholders.
- Required to obtain and maintain a Non-Sensitive / High Risk (Public Trust) security clearance, Tier 4/6c.
Preferred Qualifications:
- Experience with AWS GovCloud and cloud-native vulnerability scanning, including container image and Infrastructure-as-Code (IaC) assessment.
- Familiarity with CI/CD pipeline security controls and policy-as-code enforcement.
- Experience integrating vulnerability data with SIEM and ticketing platforms such as ServiceNow.
- Familiarity with the client Technology Standards and Products Guide and client Lifecycle Management Methodology (LMM).
Â
Responsibilities:
- Oversee enterprise vulnerability scanning across infrastructure, web applications, containers, and cloud workloads using Tenable ONE, AquaSec, and integrated CDM tooling.
- Direct remediation tracking from finding to closure, including communication and coordination with POA&M support within the Policy, Risk & Compliance branch.
- Coordinate with ISOs, ISSOs, compliance teams, and engineering teams to triage findings, assign ownership, and close gaps within agency and federal timelines.
- Lead Cyber Hygiene activities, including weekly scans of internet-facing interfaces and URLs, review of CISA Cyber Hygiene reports, and distribution of issue reports to ISSOs within two business days of receipt.
- Maintain the authoritative inventory of externally facing IPs and URLs, updated in real time and reconciled monthly.
- Monitor digital certificate expiration, generate alerts 30 days prior to expiration, and escalate unresolved items within 10 days.
- Lead WASP activities, including static and dynamic scans of client web applications in development and production environments, vendor plugin updates, and integration of CISA Known Exploited Vulnerabilities (KEVs) into scan coverage.
- Deliver threat modeling analysis for critical applications and ensure WASP findings feed remediation and Cyber Hygiene dashboards.
- Operate and maintain the CDM integration layer and ensure CDM data flows into SIEM for centralized visibility, supporting the Vulnerability (VUL) capability area and AWARE-based prioritization.
- Develop and maintain dashboards and metrics for vulnerability management, including remediation cycle time, scan coverage, KEV exposure, certificate health, and POA&M aging.
- Coordinate with OCIO, Cyber Risk, client Vulnerability Management, and the DHS CDM PMO on program reporting and integration changes.
- Update Vulnerability Management standard operating procedures, playbooks, and runbooks at least quarterly, or sooner when a gap or improvement is identified, with major changes reviewed by the Change Control Board.
About Valiant Solutions
Valiant Solutions is a security-focused IT solutions provider with public clients nationwide. Named one of the fastest growing privately held companies by Inc. 5000, Washington Technology's Fast 50, and Washington Business Journal's Best Places to Work in the D.C. area, Valiant Solutions prides itself on providing its employees with great benefits and career development opportunities. As a company, we are just as committed to growing careers as we are to building world-class IT solutions, all while enjoying an unparalleled work-life balance. We are in a phase of tremendous growth and building the team that will take us to the next level. We seek people whose talents and accomplishments will contribute to a thriving company, who have the character to support their capacity, and can make a positive impact on our culture. Alongside our talented team, you'll learn to think quickly on your feet and expand your own personal and professional skill set. Our management team will inspire you to consider new perspectives and challenge you to become a better practitioner in the fast-paced industry of IT security. We hire people we respect - and we trust them to deliver results leveraging their expertise. If you would enjoy working in a dynamic environment as part of a stellar team of professionals, then we invite you to apply online today.
Benefits Snapshot (includes, but not limited to)Valiant pays 99% of the Medical, Dental, and Vision Coverage for Full-time EmployeesValiant contributes 25% towards Health Coverage for Family and Dependents100% Paid Short Term Disability and Life Insurance Policy for Full-time Employees100% Paid Certifications401K Matching up to 4%Paid Time OffPaid Federal HolidaysWellness & Fitness ProgramValiant University - Online Education and Training PortalFSA programs for: Medical Costs, Dependent Care, Transit, and ParkingReferral Bonuses
Remote Work PolicyÂ
Remote work necessitates a high level of trust in our employees. To ensure that employee performance does not suffer in a remote work environment, all employees who telecommute are expected to have a quiet and distraction-free workspace with adequate internet, dedicate their full attention and availability to their job duties during working hours, and maintain a schedule during core business hours that align with those of their coworkers and Valiant's clients. In alignment with Valiant's inclusive and engaging environment, cameras are encouraged and can be required to be on during virtual video conferences. Additionally, in alignment with the Office of the Inspector General's effort to eliminate conflicting employment, all Valiant employees are required to disclose any current or future outside employment engagements. During onboarding and throughout employment, employees must disclose any current activities or intent to engage in outside employment or other professional activities and obtain written approval. Employees may not solicit or conduct any outside business during core business hours for Valiant Solutions and our clients.
Equal Employment Opportunity
Valiant Solutions is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, genetic information, marital status, or veteran status, in accordance with applicable law.
Physical Demands
Sitting or standing at a desk for prolonged periods of time and consistent operation of a computer. Frequent communication and exchanging of accurate information via electronic communication, phones, and in person. Occasionally lift and/or move moderate amounts of weight, typically less than 20 pounds. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of the job.
Authorization to Share Resume and Personal Information
By submitting your resume for this position, you authorize Valiant Solutions to share your resume, as well as, personal information included on the resume, with its subsidiaries, affiliates and teaming partners for the purpose of considering you for this position and other available positions requiring comparable skills, education and experience. Should Valiant Solutions or its affiliates and teaming partners wish to initiate pre-employment discussions, you will be asked to complete an employment application and related employment documents.
#LI-JM1
Employment Type: FULL_TIMEAbout Valiant Solutions
Sourced by ZipRecruiter
Company size
51 - 200 Employees
Headquarters location
Henderson, NC, US
Year founded
2005