Summary Cybersecurity Analyst (Vulnerability Management & Continuous Monitoring) Oakton, VA Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you ...
Summary Cybersecurity Analyst (Vulnerability Management & Continuous Monitoring) Oakton, VA Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you ...
Vulnerability Researcher
Reston, VA · On-site +1
Reverse engineering, vulnerability research, malware analysis, and/or CNO tool development * Computer networking fundamentals, Windows and *NIX operating systems, X86(64) and ARM or MIPS ...
Vulnerability Researcher
Reston, VA · On-site +1
Reverse engineering, vulnerability research, malware analysis, and/or CNO tool development * Computer networking fundamentals, Windows and *NIX operating systems, X86(64) and ARM or MIPS ...
Vulnerability Researcher
Reston, VA · On-site +1
Reverse engineering, vulnerability research, malware analysis, and/or CNO tool development * Computer networking fundamentals, Windows and *NIX operating systems, X86(64) and ARM or MIPS ...
Vulnerability Researcher
Reston, VA · On-site +1
Reverse engineering, vulnerability research, malware analysis, and/or CNO tool development * Computer networking fundamentals, Windows and *NIX operating systems, X86(64) and ARM or MIPS ...
Overview Cybersecurity Analyst (Vulnerability Management & Continuous Monitoring) Oakton, VA Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you ...
Overview Cybersecurity Analyst (Vulnerability Management & Continuous Monitoring) Oakton, VA Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you ...
RF Analyst - Senior
$183K - $224K/yr
Develop and refine RF threat models and vulnerability analysis methodologies (e.g., coupling pathways, susceptibility thresholds, system-level impacts). * Provide expert guidance on protective ...
RF Analyst - Senior
$183K - $224K/yr
Develop and refine RF threat models and vulnerability analysis methodologies (e.g., coupling pathways, susceptibility thresholds, system-level impacts). * Provide expert guidance on protective ...
RF Analyst - Senior
Springfield, VA · On-site
$183K - $224K/yr
Develop and refine RF threat models and vulnerability analysis methodologies (e.g., coupling pathways, susceptibility thresholds, system-level impacts). * Provide expert guidance on protective ...
RF Analyst - Senior
Springfield, VA · On-site
$183K - $224K/yr
Develop and refine RF threat models and vulnerability analysis methodologies (e.g., coupling pathways, susceptibility thresholds, system-level impacts). * Provide expert guidance on protective ...
• Primary cyber vulnerability analysis and remediation. • Supports a 24x7x365 Security Operations Center and monitors security tools, assesses threats, and risks involving client's network ...
• Primary cyber vulnerability analysis and remediation. • Supports a 24x7x365 Security Operations Center and monitors security tools, assesses threats, and risks involving client's network ...
Information Assurance Analyst
Reston, VA · On-site
Conduct system vulnerability assessments * Monitor compliance with security policies * Implement ... Risk assessment and analysis * Incident response techniques * Proficiency in security tools
Information Assurance Analyst
Reston, VA · On-site
Conduct system vulnerability assessments * Monitor compliance with security policies * Implement ... Risk assessment and analysis * Incident response techniques * Proficiency in security tools
Information Assurance Analyst
Tysons, VA · On-site
Conduct system vulnerability assessments * Monitor compliance with security policies * Implement ... Risk assessment and analysis * Incident response techniques * Proficiency in security tools
Information Assurance Analyst
Tysons, VA · On-site
Conduct system vulnerability assessments * Monitor compliance with security policies * Implement ... Risk assessment and analysis * Incident response techniques * Proficiency in security tools
Information Assurance Analyst
Chantilly, VA · On-site
Conduct system vulnerability assessments * Monitor compliance with security policies * Implement ... Risk assessment and analysis * Incident response techniques * Proficiency in security tools
Information Assurance Analyst
Chantilly, VA · On-site
Conduct system vulnerability assessments * Monitor compliance with security policies * Implement ... Risk assessment and analysis * Incident response techniques * Proficiency in security tools
They are seeking a Cybersecurity Analyst to support Department of Defense cybersecurity operations by executing vulnerability management, security compliance, and Continuous Monitoring activities in ...
They are seeking a Cybersecurity Analyst to support Department of Defense cybersecurity operations by executing vulnerability management, security compliance, and Continuous Monitoring activities in ...
Network Security Analyst
Reston, VA · On-site
Familiarity with vulnerability scanning tools DESIRED SKILLS * Experience with advanced threat ... analyst workforce development. At our company, you come first. We're committed to creating an ...
Network Security Analyst
Reston, VA · On-site
Familiarity with vulnerability scanning tools DESIRED SKILLS * Experience with advanced threat ... analyst workforce development. At our company, you come first. We're committed to creating an ...
Physical Security Risk & Compliance Analyst (TS/SCI #26-127) with Security Clearance
Arlington, VA · On-site
This position provides expert analysis of physical security programs by conducting inspections, compliance assessments, risk evaluations, and vulnerability analyses to ensure adherence to applicable ...
Physical Security Risk & Compliance Analyst (TS/SCI #26-127) with Security Clearance
Arlington, VA · On-site
This position provides expert analysis of physical security programs by conducting inspections, compliance assessments, risk evaluations, and vulnerability analyses to ensure adherence to applicable ...
Network Security Analyst
Tysons, VA · On-site
Familiarity with vulnerability scanning tools DESIRED SKILLS * Experience with advanced threat ... analyst workforce development. At our company, you come first. We're committed to creating an ...
Network Security Analyst
Tysons, VA · On-site
Familiarity with vulnerability scanning tools DESIRED SKILLS * Experience with advanced threat ... analyst workforce development. At our company, you come first. We're committed to creating an ...
Network Security Analyst
Chantilly, VA · On-site
Familiarity with vulnerability scanning tools DESIRED SKILLS * Experience with advanced threat ... analyst workforce development. At our company, you come first. We're committed to creating an ...
Network Security Analyst
Chantilly, VA · On-site
Familiarity with vulnerability scanning tools DESIRED SKILLS * Experience with advanced threat ... analyst workforce development. At our company, you come first. We're committed to creating an ...
Cybersecurity Analyst (Vulnerability Management & Continuous Mon with Security Clearance
Oakton, VA · On-site
Summary Cybersecurity Analyst (Vulnerability Management & Continuous Monitoring) Oakton, VA Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you ...
Cybersecurity Analyst (Vulnerability Management & Continuous Mon with Security Clearance
Oakton, VA · On-site
Summary Cybersecurity Analyst (Vulnerability Management & Continuous Monitoring) Oakton, VA Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you ...
Mission Technologies, a division of HII, is seeking a Junior Vulnerability Management Analyst to support the DoD/DoW Advana War Data Platform. The role involves managing enterprise vulnerability ...
Mission Technologies, a division of HII, is seeking a Junior Vulnerability Management Analyst to support the DoD/DoW Advana War Data Platform. The role involves managing enterprise vulnerability ...
Title Vulnerability Assessment Analyst - Intermediate Full-Time/Part-Time Full-Time Description RiVidium Inc. is seeking a Vulnerability Assessment Analyst who will perform assessments of systems and ...
Title Vulnerability Assessment Analyst - Intermediate Full-Time/Part-Time Full-Time Description RiVidium Inc. is seeking a Vulnerability Assessment Analyst who will perform assessments of systems and ...
Engineering Laser Analyst - Intermediate
$155K - $189K/yr
Develop detailed vulnerability test plans and procedures for mission-critical systems. * Execute operational vulnerability tests under simulated and real-world conditions. * Analyze test results ...
Engineering Laser Analyst - Intermediate
$155K - $189K/yr
Develop detailed vulnerability test plans and procedures for mission-critical systems. * Execute operational vulnerability tests under simulated and real-world conditions. * Analyze test results ...
Engineering Laser Analyst - Intermediate
Springfield, VA · On-site
$155K - $189K/yr
Develop detailed vulnerability test plans and procedures for mission-critical systems. * Execute operational vulnerability tests under simulated and real-world conditions. * Analyze test results ...
Engineering Laser Analyst - Intermediate
Springfield, VA · On-site
$155K - $189K/yr
Develop detailed vulnerability test plans and procedures for mission-critical systems. * Execute operational vulnerability tests under simulated and real-world conditions. * Analyze test results ...
Vulnerability Analyst information
See Virginia salary details
$30.7K - $39.7K
11% of jobs
$39.7K - $48.6K
9% of jobs
$51.6K is the 25th percentile. Wages below this are outliers.
$48.6K - $57.5K
15% of jobs
$57.5K - $66.4K
15% of jobs
The median wage is $66.7K / yr.
$66.4K - $75.3K
18% of jobs
$81.8K is the 75th percentile. Wages above this are outliers.
$75.3K - $84.3K
11% of jobs
$84.3K - $93.2K
7% of jobs
$93.2K - $102.1K
5% of jobs
$102.1K - $111K
4% of jobs
$111K - $120K
2% of jobs
$120K - $128.9K
3% of jobs
$30.7K
$72.6K
$128.9K
How much do vulnerability analyst jobs pay per year?
What are the key skills and qualifications needed to thrive as a vulnerability analyst, and why are they important?
To thrive as a Vulnerability Analyst, you need expertise in cybersecurity principles, risk assessment, and vulnerability management, often supported by a degree in information security or a related field. Familiarity with vulnerability scanning tools (such as Nessus, Qualys, or Rapid7), knowledge of operating systems, and certifications like CompTIA Security+ or CEH are commonly required. Strong analytical thinking, attention to detail, and effective communication skills set top candidates apart. These abilities are crucial for accurately identifying system weaknesses and effectively advising teams on how to remediate security threats.
What are the typical day-to-day responsibilities of a vulnerability analyst?
As a Vulnerability Analyst, your daily tasks often include running vulnerability scans, analyzing findings, prioritizing risks based on severity, and working with IT or development teams to coordinate remediation efforts. You will also document your findings, prepare reports for stakeholders, and stay informed about the latest security threats and exploits. Collaboration with other security professionals and IT staff is common, as resolving vulnerabilities often requires cross-functional teamwork. This role requires a balance of technical analysis and effective communication to ensure organizational security posture is continuously improved.
What is a vulnerability analyst?
A Vulnerability Analyst is a cybersecurity professional responsible for identifying, assessing, and mitigating security weaknesses in an organization's systems, networks, and applications. They use tools like vulnerability scanners, penetration testing frameworks, and security assessments to identify potential threats. Their role includes analyzing vulnerabilities, prioritizing risks, and working with IT and security teams to implement necessary patches or fixes. They also stay up to date with emerging threats and ensure compliance with security policies and regulations.

Cybersecurity Analyst (Vulnerability Management & Continuous Monitoring)
Oakton, VA
Full-time
Re-posted 2 days ago
Job description
Cybersecurity Analyst (Vulnerability Management & Continuous Monitoring)
Oakton, VA
Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you looking for a career where professional development is embedded in your employer’s core culture? If so, Chenega Military, Intelligence & Operations Support (MIOS) could be the place for you! Join our team of professionals who support large-scale government operations by leveraging cutting-edge technology and take your career to the next level!Â
SecuriGence delivers essential technology services supporting critical national security missions. We are seeking a Cybersecurity Analyst (Vulnerability Management & Continuous Monitoring) to support Department of Defense (DoD) cybersecurity operations by executing vulnerability management, security compliance, and Continuous Monitoring (ConMon) activities in accordance with the Risk Management Framework (RMF). This role is responsible for identifying, assessing, prioritizing, and tracking vulnerabilities using enterprise tools, ensuring compliance with Security Technical Implementation Guides (STIGs), and responding to Information Assurance Vulnerability Alerts (IAVAs).
Responsibilities
- Vulnerability Management
- Perform vulnerability scanning using Assured Compliance Assessment Solution (ACAS) (e.g., Tenable.sc / Nessus).
- Enforcing the ACAS best practice guide requirements when performing vulnerability scans in ACAS
- Analyze scan results to identify vulnerabilities, misconfigurations, and compliance gaps.
- Validate findings against the latest released DISA STIGs and applicable security baselines.
- Review of provided checklists and working with system admins in identifying gaps for POA&M creation.
- Assess and track vulnerabilities in accordance with DoD timelines and risk severity.
- Correlate vulnerabilities with IAVA/IAVM notices and ensure timely remediation or mitigation.
- Develop and maintain Plan of Action and Milestones (POA&M) documentation.
- Maintenance of Risk Acceptance (RA) POA&M items within SOR (System of Record) and coordinating with System administrators to validate that RA is required instead of a POA&M.
- STIG Compliance & Hardening
- Apply and validate Security Technical Implementation Guides (STIGs) across operating systems, applications, and network devices.
- Conduct manual and automated STIG compliance checks using tools such as ACAS Audit checks, STIG Viewer, SCAP Compliance Checker (SCC), and Evaluate-STIG.
- Document compliance status and provide remediation guidance to system administrators.
- Support system hardening efforts aligned with DoD baseline configurations.
- Ensure that golden images are maintained for Servers (RHEL and Windows) and Workstations following STIG guidance.
- IAVA/IAVM Management
- Monitor and assess Information Assurance Vulnerability Alerts (IAVAs) and Bulletins (IAVBs).
- Determine system applicability and operational impact.
- Coordinate remediation actions and track compliance deadlines.
- Maintain IAVA compliance reporting and documentation for audits.
- Continuous Monitoring (ConMon)
- Execute Continuous Monitoring activities in accordance with RMF Step 6.
- Monitor security controls for effectiveness and ongoing compliance.
- Conduct control assessments and assist with periodic security reviews.
- Support automated and manual data collection for ConMon dashboards and reporting.
- Identify trends, recurring issues, and systemic risks across systems.
- RMF & Compliance Support
- Support RMF activities across all six steps, with emphasis on:
- Control implementation validation
- Security control assessment support
- Ongoing authorization (ATO sustainment)
- Update and maintain RMF artifacts, including:
- System Security Plan (SSP)
- Security Assessment Report (SAR)
- Plan of Action and Milestones (POA&M)
- Security Assessment Plan (SAP)
- Map vulnerabilities and findings to NIST SP 800-53 controls.
- Reporting & Documentation
- Generate vulnerability and compliance reports for leadership and Authorizing Officials (AOs).
- Provide risk-based recommendations and remediation strategies.
- Maintain audit-ready documentation in accordance with DoD and agency requirements
- Other duties as assigned
Qualifications
- High school diploma or GED equivalent
- 5+ years of experience in DoD cybersecurity or RMF-based environments
- Hands-on experience with:
- ACAS (Nessus / Tenable.sc)
- STIG implementation and validation
- IAVA/IAVM processes
- Experience with vulnerability assessment, risk analysis, and remediation tracking.
- DoD 8570/8140 Compliance: Must meet IAT Level II requirements (e.g., Security+)
- Active DoD Top Secret clearance with SCI eligibility.
Knowledge, Skills, and Abilities:
- Strong understanding of:
- DoD RMF (DoDI 8510.01)
- NIST SP 800-53 security controls
- Ability to manage multiple systems and priorities in a regulated environment
- Strong analytical and problem-solving skills
- Attention to detail and compliance rigor
- Ability to translate technical risk into mission impact
- Effective communication with technical and non-technical stakeholders
- Relevant certifications:
- Certified Information Systems Security Professional (CISSP)
- Certified Ethical Hacker (CEH) or equivalent
- DISA ACAS Training Certificate
- Experience with:
- ACAS
- SCAP Compliance Checker (SCC) / Evaluate-STIG
- STIG Viewer
- eMASS, Xacta
- Trellix, MDE
- Splunk, Elastic
- Familiarity with scripting (e.g., PowerShell, Python) for automation.
- Experience in enterprise-level ConMon programs or NOSC/SOC environments.
How you’ll growÂ
At Chenega MIOS, our professional development plan focuses on helping our team members at every level of their careers to identify and use their strengths to do their best work every day. From entry-level employees to senior leaders, we believe there’s always room to learn.Â
We offer opportunities to help sharpen skills in addition to hands-on experience in the global, fast-changing business world. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their careers.Â
BenefitsÂ
At Chenega MIOS, we know that great people make a great organization. We value our team members and offer them a broad range of benefits.Â
Learn more about what working at Chenega MIOS can mean for you.Â
Chenega MIOS’s cultureÂ
Our positive and supportive culture encourages our team members to do their best work every day. We celebrate individuals by recognizing their uniqueness and offering them the flexibility to make daily choices that can help them be healthy, centered, confident, and aware. We offer well-being programs and continuously look for new ways to maintain a culture where we excel and lead healthy, happy lives.Â
Corporate citizenshipÂ
Chenega MIOS is led by a purpose to make an impact that matters. This purpose defines who we are and extends to relationships with our clients, our team members, and our communities. We believe that business has the power to inspire and transform. We focus on education, giving, skill-based volunteerism, and leadership to help drive positive social impact in our communities.Â
Learn more about Chenega’s impact on the world.Â
Chenega MIOS News-Â https://chenegamios.com/news/Â
Tips from your Talent Acquisition TeamÂ
We want job seekers exploring opportunities at Chenega MIOS to feel prepared and confident. To help you with your research, we suggest you review the following links:Â
Chenega MIOS web site -Â www.chenegamios.comÂ
Glassdoor -Â https://www.glassdoor.com/Overview/Working-at-Chenega-MIOS-EI_IE369514.11,23.htmÂ
LinkedIn -Â https://www.linkedin.com/company/1472684/Â
Facebook -Â https://www.facebook.com/chenegamios/Â
Estimated Salary/Wage
USD $120,000.00/Yr. Up to USD $184,000.00/Yr.Qualifications:
- High school diploma or GED equivalent
- 5+ years of experience in DoD cybersecurity or RMF-based environments
- Hands-on experience with:
- ACAS (Nessus / Tenable.sc)
- STIG implementation and validation
- IAVA/IAVM processes
- Experience with vulnerability assessment, risk analysis, and remediation tracking.
- DoD 8570/8140 Compliance: Must meet IAT Level II requirements (e.g., Security+)
- Active DoD Top Secret clearance with SCI eligibility.
Knowledge, Skills, and Abilities:
- Strong understanding of:
- DoD RMF (DoDI 8510.01)
- NIST SP 800-53 security controls
- Ability to manage multiple systems and priorities in a regulated environment
- Strong analytical and problem-solving skills
- Attention to detail and compliance rigor
- Ability to translate technical risk into mission impact
- Effective communication with technical and non-technical stakeholders
- Relevant certifications:
- Certified Information Systems Security Professional (CISSP)
- Certified Ethical Hacker (CEH) or equivalent
- DISA ACAS Training Certificate
- Experience with:
- ACAS
- SCAP Compliance Checker (SCC) / Evaluate-STIG
- STIG Viewer
- eMASS, Xacta
- Trellix, MDE
- Splunk, Elastic
- Familiarity with scripting (e.g., PowerShell, Python) for automation.
- Experience in enterprise-level ConMon programs or NOSC/SOC environments.
How you’ll growÂ
At Chenega MIOS, our professional development plan focuses on helping our team members at every level of their careers to identify and use their strengths to do their best work every day. From entry-level employees to senior leaders, we believe there’s always room to learn.Â
We offer opportunities to help sharpen skills in addition to hands-on experience in the global, fast-changing business world. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their careers.Â
BenefitsÂ
At Chenega MIOS, we know that great people make a great organization. We value our team members and offer them a broad range of benefits.Â
Learn more about what working at Chenega MIOS can mean for you.Â
Chenega MIOS’s cultureÂ
Our positive and supportive culture encourages our team members to do their best work every day. We celebrate individuals by recognizing their uniqueness and offering them the flexibility to make daily choices that can help them be healthy, centered, confident, and aware. We offer well-being programs and continuously look for new ways to maintain a culture where we excel and lead healthy, happy lives.Â
Corporate citizenshipÂ
Chenega MIOS is led by a purpose to make an impact that matters. This purpose defines who we are and extends to relationships with our clients, our team members, and our communities. We believe that business has the power to inspire and transform. We focus on education, giving, skill-based volunteerism, and leadership to help drive positive social impact in our communities.Â
Learn more about Chenega’s impact on the world.Â
Chenega MIOS News-Â https://chenegamios.com/news/Â
Tips from your Talent Acquisition TeamÂ
We want job seekers exploring opportunities at Chenega MIOS to feel prepared and confident. To help you with your research, we suggest you review the following links:Â
Chenega MIOS web site -Â www.chenegamios.comÂ
Glassdoor -Â https://www.glassdoor.com/Overview/Working-at-Chenega-MIOS-EI_IE369514.11,23.htmÂ
LinkedIn -Â https://www.linkedin.com/company/1472684/Â
Facebook -Â https://www.facebook.com/chenegamios/Â
Education:UNAVAILABLEEmployment Type: FULL_TIMEAbout Chenega
Sourced by ZipRecruiter
Industry
It services
Company size
5,001 - 10,000 Employees
Headquarters location
Anchorage, AK, US