2

Full Time Vulnerability Analyst Jobs in Kentucky

Perform security control assessments and vulnerability analyses * Identify, document, and track ... This is a full-time onsite position located in Washington, D.C., New York Avenue facility. The ...

Full Time Vulnerability Analyst information

What is the difference between Full Time Vulnerability Analyst vs Penetration Tester?

AspectFull Time Vulnerability AnalystPenetration Tester
CertificationsCompTIA Security+, CISSP, CEHOSCP, CEH, GPEN
Work EnvironmentIn-house security teams, continuous monitoringProject-based, simulated attacks
Employer & IndustryCorporate, government, cybersecurity firmsConsulting firms, security service providers

Full Time Vulnerability Analysts focus on identifying and prioritizing security weaknesses through ongoing assessments, while Penetration Testers simulate attacks to test defenses. Both roles require similar certifications and often work within the same industry sectors, but their daily tasks and objectives differ. Vulnerability Analysts maintain security posture, whereas Penetration Testers evaluate system resilience through active testing.

What are the most commonly searched types of Vulnerability Analyst jobs in Kentucky?

The most popular types of Vulnerability Analyst jobs in Kentucky are:

What job categories do people searching Full Time Vulnerability Analyst jobs in Kentucky look for?

The top searched job categories for Full Time Vulnerability Analyst jobs in Kentucky are:

What cities in Kentucky are hiring for Full Time Vulnerability Analyst jobs?

Cities in Kentucky with the most Full Time Vulnerability Analyst job openings:

FISMA Support Analyst (Northern)

Eastern, KY • On-site

$133K - $1M/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

This job post has expired today. Applications are no longer accepted.


Job description

Overview

We are seeking FISMA Support Analyst(s) to support the Governance, Risk and Compliance (GRC) team within the IT division at the Board of Governors of the Federal Reserve. This team is responsible for defining, implementing, and managing processes that support compliance, policy, outreach, and privacy-related work across the organization. Only candidates that currently reside within a 50 mile radius of DC will be considered.


Period of Performance 9/14/26 – 12/31/26 with the possibility of an additional 12-month extension.


Work Location: On-site in Washington, DC without remote or hybrid work options.


Responsibilities
Security Authorization & Compliance

  • Manage the security authorization lifecycle for information systems under NIST RMF (SP 800-37)

  • Prepare and maintain security authorization packages, including System Security Plans, Security Assessment Reports, and Plans of Action and Milestones

  • Conduct continuous monitoring activities and maintain Authority to Operate status

  • Ensure compliance with FISMA, NIST SP 800-53 security controls, and agency-specific policies


Risk Management

  • Perform security control assessments and vulnerability analyses

  • Identify, document, and track security weaknesses and deficienciesDevelop and maintain Plans of Action and Milestones (POA&Ms)

  • Conduct risk assessments and recommend risk-mitigation strategies

  • Support annual security reviews and security authorization updates


Documentation & Reporting

  • Develop and maintain System Security Plans (SSPs)

  • Create and update security-related documentation, including standard operating procedures, diagrams, and inventories

  • Generate security metrics and reports for management and auditors

  • Maintain system security authorization documentation in compliance repositories


Security Operations Support

  • Coordinate security scans and penetration-testing activities

  • Review and analyze vulnerability scan results

  • Assist with incident response and security event investigations

  • Support security tool implementation and configuration


Stakeholder Coordination

  • Serve as the primary liaison among system owners, authorizing officials, and security teams

  • Coordinate with vendors, contractors, and technical teams on security requirements

  • Provide security guidance to development and operations teams


Qualifications

  • U.S. Citizenship

  • Bachelor's degree in Computer Science, Information Security, or a related field

  • Three to five years of experience in information security or cybersecurity compliance

  • Experience with federal government systems and FISMA compliance


Technical Skills

  • Strong knowledge of NIST frameworks, including SP 800-53, SP 800-37, and SP 800-171

  • Familiarity with security assessment tools such as Nessus, ACAS, and SCAP

  • Understanding of cloud security; FedRAMP experience is preferred

  • Experience with compliance management tools such as Xacta or similar platforms

  • Knowledge of security control implementation across various platforms

  • Hands-on experience with Risk Management Framework (RMF) and Authority to Operate (ATO) processes


Place or Work: This is a full-time onsite position located in Washington, D.C., New York Avenue facility. The selected candidate will work a set first-shift schedule, Monday through Friday, and may be required to participate in an on-call rotation for emergency hardware issues, travel occasionally, and work weekends or overtime as needed.


Salary: $133,099 - $136,0527


Additional benefits include:



  • Paid Time Off & Holiday Pay

  • Medical Insurance

  • Dental Insurance

  • Vision Insurance

  • Disability, Life Insurance, and AD&D

  • Flexible Spending Accounts

  • Pre-Tax 401K and/or After-Tax Roth IRA (with employer matching contribution)

  • Tuition and Technical Training Reimbursement

  • Exercise Reimbursement

  • Computer Reimbursement

  • Employee Assistance Program


About Us:


Edgewater Federal Solutions is a privately held government contracting firm located in Frederick, MD. The company was founded in 2002 with the vision of being highly recognized and admired for supporting customer missions through employee empowerment, exceptional services and timely delivery. Edgewater Federal Solutions is ISO 9001, 20000-1, 270001 certified, appraised at CMMI Level 3 Maturity for Development and Services, and has been named in the Top Workplaces in the Greater Washington Area Small Companies for 2018 through 2025.


It has been and continues to be the policy of Edgewater Federal Solutions to provide equal employment opportunities to all employees and applicants for employment without regard to race, color, religion, gender, sexual orientation, national origin, age, disability, marital status, veteran status, and/or other statuses protected by applicable law.

#J-18808-Ljbffr