2

Remote Endpoint Analyst Jobs in Silver Spring, MD

IT Technician / Corporate Support

Alexandria, VA · Remote

$23 - $31.50/hr

... endpoint risk (patching, access controls, encryption, and secure remote access practices). * Strong analytical/problem-solving skills; high attention to detail; ability to prioritize in a high-volume ...

This role is remote. The Technical Project Coordinator supports IT operations by coordinating high ... network, endpoint, and IT service management teams. This role provides centralized project ...

Remote Support Technician, Journeyman

Arlington, VA · On-site +1

$43K - $54K/yr

Ability to analyze issues, identify root causes, and implement effective solutions. • Self ... Experience with cloud collaboration tools, VPNs, and endpoint management platforms is often ...

NOC Analyst

Washington, DC · Remote

$45 - $50/hr

Hybrid 2 Days Onsite/3 Days Remote in Washington, DC Our client seeks a NOC Analyst to support ... Experience with infrastructure, server, endpoint, and/or network device monitoring. * Proficiency ...

... City Remote Country United States Working time Full-time Description & Requirements Maximus is a ... across large-scale endpoint, server, cloud, and on-prem environments. Ability to obtain and ...

Coordinate efforts related to endpoint protection, permissions, device security, and local security ... Contribute to root cause analysis, change management, and technical planning efforts where security ...

Coordinate efforts related to endpoint protection, permissions, device security, and local security ... Contribute to root cause analysis, change management, and technical planning efforts where security ...

... City Remote Country United States Working time Full-time Description & Requirements Maximus is a ... across large-scale endpoint, server, cloud, and on-prem environments. Ability to obtain and ...

Showing results 21-40

Remote Endpoint Analyst information

See Silver Spring, MD salary details

$32K

$75.7K

$134.4K

How much do remote endpoint analyst jobs pay per year?

As of Aug 11, 2026, the average yearly pay for remote endpoint analyst in Silver Spring, MD is $75,735.00, according to ZipRecruiter salary data. Most workers in this role earn between $54,300.00 and $89,900.00 per year, depending on experience, location, and employer.

What is a remote endpoint analyst?

A Remote Endpoint Analyst is an IT professional responsible for monitoring, managing, and securing endpoint devices such as laptops, desktops, and mobile devices from a remote location. Their primary duties include deploying software updates, troubleshooting technical issues, ensuring endpoint compliance with security policies, and responding to cybersecurity incidents. They play a crucial role in protecting an organization’s data and network by managing endpoints that may not be physically located in a central office. This role is especially important in organizations with remote or hybrid work environments.

What is the difference between Remote Endpoint Analyst vs Remote Security Analyst?

AspectRemote Endpoint AnalystRemote Security Analyst
CertificationsCompTIA A+, Network+CompTIA Security+, CISSP
Work EnvironmentIT support, troubleshooting endpointsMonitoring security threats, incident response
Industry UsageIT departments, managed service providersCybersecurity firms, corporate security teams

While both roles involve remote work and technical skills, the Remote Endpoint Analyst focuses on managing and troubleshooting end-user devices, whereas the Remote Security Analyst specializes in protecting systems from security threats. The certifications and daily tasks differ, with the Endpoint Analyst emphasizing hardware/software support and the Security Analyst concentrating on threat detection and response.

What are some common challenges faced by remote endpoint analysts, and how can they be addressed?

Remote Endpoint Analysts often encounter challenges such as managing a diverse range of devices and operating systems, ensuring timely patching and updates, and troubleshooting issues without physical access to endpoints. Effective communication and strong documentation skills are crucial for collaborating with both technical and non-technical colleagues remotely. Leveraging remote management tools, staying updated on the latest cybersecurity threats, and participating in regular team meetings can help address these challenges and ensure smooth endpoint security operations.

What are the key skills and qualifications needed to thrive as a remote endpoint analyst, and why are they important?

To thrive as a Remote Endpoint Analyst, you need strong knowledge of endpoint security, operating systems, and network protocols, often backed by a degree in IT or cybersecurity and relevant certifications such as CompTIA Security+ or Microsoft Certified: Security, Compliance, and Identity Fundamentals. Familiarity with remote management tools, endpoint detection and response (EDR) platforms, and ticketing systems is typically required. Attention to detail, analytical thinking, and effective communication are crucial soft skills for diagnosing issues and collaborating with remote teams. These competencies are vital for protecting organizational assets, ensuring timely incident response, and maintaining productivity in distributed environments.
What job categories do people searching Remote Endpoint Analyst jobs in Silver Spring, MD look for? The top searched job categories for Remote Endpoint Analyst jobs in Silver Spring, MD are:
What cities near Silver Spring, MD are hiring for Remote Endpoint Analyst jobs? Cities near Silver Spring, MD with the most Remote Endpoint Analyst job openings:

DFC - Vulnerability Management Analyst

cFocus Software Incorporated

Washington, DC • On-site, Remote

Full-time

Posted 16 days ago


Job description

cFocus Software seeks a Vulnerability Management Analyst to join our program supporting the United States International Defense Finance Agency (DFC). This position is remote. This position requires an Active Public Trust clearance.
Qualifications:
  • Active Public Trust clearance
  • B.S. Computer Science, Information Technology, or a related field
  • 5+ years of cybersecurity experience, including three or more years in vulnerability management, security compliance, POA&M management, or a closely related function.
  • Hands-on experience analyzing authenticated scan results and validating vulnerabilities using Tenable Nessus, Qualys, Microsoft Defender, or comparable enterprise platforms.
  • Demonstrated ability to assess vulnerability risk using CVSS, exploitability, CISA KEV status, asset criticality, exposure, mission impact, threat intelligence, and compensating controls.
  • Experience creating and maintaining POA&M records, tracking remediation milestones, reconciling GRC and ticketing systems, validating closure evidence, and documenting false-positive determinations.
  • Working knowledge of FISMA, the NIST Risk Management Framework, NIST SP 800-53 controls, NIST SP 800-40 vulnerability and patch-management principles, CISA KEV/BOD 22-01 requirements, and federal continuous-monitoring expectations.
  • Ability to communicate technical risk clearly to federal cybersecurity leaders, System Owners, engineers, administrators, auditors, and nontechnical stakeholders.
  • Strong analytical writing, data-quality, documentation, prioritization, and time-management skills in a deadline-driven environment.
  • Active Security+, CySA+, CEH, GCVA, CISSP or other relevant security certifications preferred.

Duties:
  • Coordinate authenticated vulnerability scans with DFC stakeholders at frequencies aligned with policy, system criticality, exposure, threat conditions, and Government direction.
  • Analyze output from Tenable, Qualys, Microsoft Defender, and other Government-approved vulnerability, endpoint, configuration, and posture-management platforms.
  • Validate scanner findings against the operational environment and distinguish valid findings from false positives using documented rationale and supporting evidence.
  • Assess and assign severity using CVSS, DFC policy, exploitability, known-exploitation status, asset criticality, external exposure, mission impact, and relevant threat intelligence.
  • Recommend risk-informed remediation priorities, actions, timelines, evidence requirements, and closure criteria.
  • Coordinate with engineering, operations, application, cloud, endpoint, and system administration teams to establish remediation ownership, dependencies, and target completion dates
  • Provide rapid analysis and coordination for CISA Known Exploited Vulnerabilities (KEV), Binding Operational Directive 22-01 requirements, CISA Emergency Directives, vendor-declared zero-days, and vulnerabilities with active exploitation.
  • Notify the ISSM within four hours of applicable CISA notification, vendor disclosure, Government notification, or Contractor identification.
  • Verify exposure across applicable CSAM authorization boundaries and deliver a written impact assessment within one business day.
  • Document affected systems, boundaries and assets; severity; exposure; exploitability; known exploitation; mission impact; remediation ownership; required timelines; recommended action; and residual-risk considerations.
  • Track emergency remediation against CISA-, DFC-, or Government-directed deadlines and provide written confirmation of remediation status, compliance status, residual risk, and closure evidence.
  • Use CSAM as the authoritative POA&M and compliance ledger and ServiceNow as the operational remediation ticketing record.
  • Create complete POA&M items in CSAM within three business days after finding identification or Government direction, unless the Government establishes another deadline.
  • Populate and maintain required fields, including identifier, weakness description, affected system and control, severity, source, responsible owner, required resources, scheduled completion date, milestones, status, residual risk, and closure evidence.
  • Maintain bidirectional traceability so each applicable ServiceNow remediation ticket links to its CSAM POA&M item and each CSAM POA&M record references the appropriate ServiceNow ticket.
  • Track remediation through closure, monitor milestone integrity and aging, and coordinate scheduled-completion-date changes only after federal authorization.
  • Conduct monthly ServiceNow-to-CSAM reconciliation; identify stale or duplicate records, missing links or evidence, inconsistent status, inaccurate dates, and other data-quality issues; issue a written discrepancy log and track gaps to resolution.
  • Prepare risk-acceptance or exception recommendation packages when remediation cannot be completed within applicable timelines or scheduled-completion-date constraints.
  • Document the affected system and weakness, operational and mission impacts, exploitability, exposure, residual risk, compensating controls, remediation constraints, proposed duration and expiration, review interval, and conditions for continued acceptance.
  • Route recommendation packages to the AODR through the COR and ISSM for federal decision and accurately record approved decisions in CSAM.
  • Clearly preserve federal authority: do not accept risk for DFC, approve exceptions, extend POA&M dates without authorization, or make final closure decisions.