Cybersecurity Risk Analysis and Vulnerability Management: Analyzes security findings and vulnerabilities identified through cybersecurity assessments and scanning tools. Determines the operational ...
Cybersecurity Risk Analysis and Vulnerability Management: Analyzes security findings and vulnerabilities identified through cybersecurity assessments and scanning tools. Determines the operational ...
Solutions Architect (REMOTE)
OR · Remote
$63 - $83/hr
... vulnerability management with data insights gleaned from assets, users, malware, attackers, and ... As a result, organizations can increase speed and accuracy while reducing costs and analyst burnout.
Solutions Architect (REMOTE)
OR · Remote
$63 - $83/hr
... vulnerability management with data insights gleaned from assets, users, malware, attackers, and ... As a result, organizations can increase speed and accuracy while reducing costs and analyst burnout.
... vulnerability management, antivirus, SIEM, firewalls, IPS/IDS monitoring, and techniques for analyzing TCP/IP network traffic and event logs * Knowledge of Linux network functions; Saas/Cloud-based ...
... controls spanning vulnerability management (A.8.8), secure development (A.8.25-A.8.29), and ... Analytical Thinking: Applies a structured, adversarial mindset to both offensive assessments and ...
... controls spanning vulnerability management (A.8.8), secure development (A.8.25-A.8.29), and ... Analytical Thinking: Applies a structured, adversarial mindset to both offensive assessments and ...
... controls spanning vulnerability management (A.8.8), secure development (A.8.25-A.8.29), and ... Analytical Thinking: Applies a structured, adversarial mindset to both offensive assessments and ...
... controls spanning vulnerability management (A.8.8), secure development (A.8.25-A.8.29), and ... Analytical Thinking: Applies a structured, adversarial mindset to both offensive assessments and ...
Senior IT Analyst
Portland, OR · Hybrid
Vulnerability, Patch, and Secure Configuration Management: Coordinates vulnerability identification ... Systems and Business Analysis: Facilitates requirements discovery, process analysis, fit-gap ...
Senior IT Analyst
Portland, OR · Hybrid
Vulnerability, Patch, and Secure Configuration Management: Coordinates vulnerability identification ... Systems and Business Analysis: Facilitates requirements discovery, process analysis, fit-gap ...
Vulnerability management: Run the vulnerability scanning program across AWS and Azure cloud ... Lead investigations into security events, perform forensic analysis, document findings, and ...
Vulnerability management: Run the vulnerability scanning program across AWS and Azure cloud ... Lead investigations into security events, perform forensic analysis, document findings, and ...
OR · On-site
$114K - $156K/yr
... vulnerability management, API security, CI/CD protections, secrets management, and developer ... analysis, remediation tracking, and durable improvements that prevent repeat issues. * Foster a ...
Senior IT Analyst
Portland, OR · On-site
$117K - $154K/yr
Vulnerability, Patch, and Secure Configuration Management: Coordinates vulnerability identification ... Systems and Business Analysis: Facilitates requirements discovery, process analysis, fit-gap ...
Senior IT Analyst
Portland, OR · On-site
$117K - $154K/yr
Vulnerability, Patch, and Secure Configuration Management: Coordinates vulnerability identification ... Systems and Business Analysis: Facilitates requirements discovery, process analysis, fit-gap ...
$108K - $147K/yr
What You'll Do: Vulnerability Management Research and download all patches for the Compute ... cause analysis, and continuous improvements to reduce repeat issues. Establish runbooks ...
$108K - $147K/yr
What You'll Do: Vulnerability Management Research and download all patches for the Compute ... cause analysis, and continuous improvements to reduce repeat issues. Establish runbooks ...
Senior Information Security Engineer (ISSO)
OR · On-site
$99K - $135K/yr
... analysis, and security documentation activities. * Contribute RMF and compliance expertise to ... Proficiency with technologies, tools, and processes supporting GRC, vulnerability management, and ...
New
Senior Information Security Engineer (ISSO)
OR · On-site
$99K - $135K/yr
... analysis, and security documentation activities. * Contribute RMF and compliance expertise to ... Proficiency with technologies, tools, and processes supporting GRC, vulnerability management, and ...
New
Senior IT Security Engineer
OR · Remote
$130K - $155K/yr
... analysis and control design through evidence collection, audit coordination, and successful ... Own the vulnerability management lifecycle - deploy and operate scanning tools, define remediation ...
Senior IT Security Engineer
OR · Remote
$130K - $155K/yr
... analysis and control design through evidence collection, audit coordination, and successful ... Own the vulnerability management lifecycle - deploy and operate scanning tools, define remediation ...
Assess operational practices related to change control, patching, vulnerability management, backup ... Analysis & Documentation * Document assessment activities, evidence reviewed, testing approach ...
Assess operational practices related to change control, patching, vulnerability management, backup ... Analysis & Documentation * Document assessment activities, evidence reviewed, testing approach ...
Assess operational practices related to change control, patching, vulnerability management, backup ... Analysis & Documentation * Document assessment activities, evidence reviewed, testing approach ...
Assess operational practices related to change control, patching, vulnerability management, backup ... Analysis & Documentation * Document assessment activities, evidence reviewed, testing approach ...
Own all operational aspects of network security infrastructure - OS maintenance, vulnerability ... Demonstrated experience with incident response, root cause analysis, change management, and ...
Senior Information Security Engineer
$116K - $140K/yr
... and access management, vulnerability management, cloud security, application security, data ... Strong analytical and problem-solving skills with the ability to evaluate complex security and ...
Senior Information Security Engineer
$116K - $140K/yr
... and access management, vulnerability management, cloud security, application security, data ... Strong analytical and problem-solving skills with the ability to evaluate complex security and ...
SOC Tier 1 Analyst
Portland, OR · On-site
The SOC Analyst 1 supports the organization's security operations by monitoring security events ... case management systems, and vulnerability platforms in accordance with approved procedures.
SOC Tier 1 Analyst
Portland, OR · On-site
The SOC Analyst 1 supports the organization's security operations by monitoring security events ... case management systems, and vulnerability platforms in accordance with approved procedures.
Senior Contracts Manager (REMOTE)
OR · Remote
... vulnerability management with data insights gleaned from assets, users, malware, attackers, and ... As a result, organizations can increase speed and accuracy while reducing costs and analyst burnout.
Senior Contracts Manager (REMOTE)
OR · Remote
... vulnerability management with data insights gleaned from assets, users, malware, attackers, and ... As a result, organizations can increase speed and accuracy while reducing costs and analyst burnout.
Participate in vulnerability management, audit, and assessment efforts as required. * Perform all ... analysis, endpoint and other network and security products. Excellent communication skills.
Participate in vulnerability management, audit, and assessment efforts as required. * Perform all ... analysis, endpoint and other network and security products. Excellent communication skills.
Workplace Security Analyst
$88K - $135K/yr
Department of County Management (DCM) Job Type: Regular Non-Represented Exemption Status: United ... Conduct security vulnerability assessments using the Crime Prevention Through Environmental Design ...
Workplace Security Analyst
$88K - $135K/yr
Department of County Management (DCM) Job Type: Regular Non-Represented Exemption Status: United ... Conduct security vulnerability assessments using the Crime Prevention Through Environmental Design ...
Vulnerability Management Analyst information
What is a vulnerability management analyst?
A Vulnerability Management Analyst is responsible for identifying, assessing, and mitigating security vulnerabilities within an organization's IT infrastructure. They use scanning tools, analyze threat data, and collaborate with teams to prioritize and remediate risks. Their role is crucial in maintaining cybersecurity by ensuring systems are patched and configured securely. Additionally, they may develop reports and provide recommendations to improve security posture. This position requires knowledge of security frameworks, risk assessment, and vulnerability management tools.
What are the typical daily responsibilities of a vulnerability management analyst?
On a typical day, a Vulnerability Management Analyst reviews system scans, analyzes reports for potential vulnerabilities, and works with IT or security teams to prioritize remediation efforts. They may also track the status of vulnerabilities, ensure timely patch application, and help develop or update security policies. Collaboration with various departments is common to coordinate testing, remediation, and communicate risk summary findings. This role requires keeping up with emerging threats and sometimes participating in security audits or compliance reviews, making it both dynamic and integral to the organization's overall cybersecurity posture.
What are the key skills and qualifications needed to thrive as a vulnerability management analyst?
A Vulnerability Management Analyst requires a strong background in cybersecurity principles, risk assessment, and IT networking, often supported by a relevant degree or certifications like CompTIA Security+, CISSP, or CEH. Experience with vulnerability scanning tools (such as Nessus, Qualys, or Rapid7) and familiarity with ticketing systems or SIEM platforms is essential. Strong analytical skills, attention to detail, effective communication, and the ability to work collaboratively help individuals succeed in this role. These capabilities are vital to proactively identify, assess, and mitigate security vulnerabilities, ensuring the organization's digital assets remain secure and compliant.

Cybersecurity Assessment and Authorization Subject Matter Expert (SME) (59788)
Remote
Full-time
Medical, Dental, Vision, Retirement
Re-posted 12 days ago
Job description
BMA is seeking a Cybersecurity Assessment and Authorization Subject Matter Expert (SME) to support the DLA JETS Cybersecurity Assessment and Authorization Support Services program. This is a fully remote position and contingent on contract award.
Job SummaryÂ
BMA is seeking a Cybersecurity Assessment and Authorization Subject Matter Expert (SME) to support the DLA Cybersecurity Assessment and Authorization Support Services contract. This is a Key Personnel position for the upcoming bid proposal for this work. The analyst serves as a cybersecurity Subject Matter Expert (SME) supporting the DLA J6 Cybersecurity Program, providing technical expertise in the authorization of information systems and cybersecurity compliance activities across DLA’s enterprise IT and Operational Technology (OT) environments. This role supports the assessment, authorization, and continuous monitoring of information systems under the Risk Management Framework (RMF) and ensures compliance with DoD cybersecurity policies, federal information security regulations, and DLA cybersecurity implementation guidance. The analyst performs cybersecurity validation activities throughout the DoD System Development Life Cycle (SDLC) and assists program offices, Information System Security Managers (ISSMs), and Authorizing Officials (AOs) in maintaining the security posture of DLA systems. The position supports complex enterprise environments including large and small enclaves, applications, and outsourced IT services, ensuring security controls are implemented, assessed, and monitored in accordance with NIST SP 800-53, DoD cybersecurity policy, and the DLA RMF Implementation Process Guide.
Key Responsibilities include but are not limited to:
- Cybersecurity Assessment and Authorization Support: Provides cybersecurity subject matter expertise supporting authorization and accreditation activities for DLA information systems. Assists ISSMs and AOs with implementation of the DoD Risk Management Framework throughout the system development lifecycle, conducts security control reviews and authorization package analysis, and supports cybersecurity activities across IT, Platform IT (PIT), and Operational Technology / Facility Related Control Systems environments.
- RMF Execution: Supports execution of all phases of the RMF authorization process, including system categorization, security control selection, implementation validation, security control assessment, authorization, and continuous monitoring. Assists in the development and maintenance of RMF documentation and supports system registration and cybersecurity documentation management within the Enterprise Mission Assurance Support Service environment.
- Security Control Assessment and Compliance Validation: Evaluates the implementation and effectiveness of security controls defined in NIST SP 800-53 and DoD cybersecurity guidance. Conducts security control validation reviews, identifies non-compliant controls and vulnerabilities, determines severity levels, assesses impacts to system authorization status, and provides mitigation strategies and remediation recommendations.
- Cybersecurity Risk Analysis and Vulnerability Management: Analyzes security findings and vulnerabilities identified through cybersecurity assessments and scanning tools. Determines the operational and security impact of vulnerabilities on system authorization and risk posture, supports remediation activities, tracks vulnerabilities through Plans of Action and Milestones (POA&M), and assists with monitoring vulnerabilities identified through ACAS scans and IAVA alerts.
- Documentation, Reporting, and Briefings: Develops cybersecurity assessment documentation supporting system authorization packages, maintains documentation repositories for system and organizational artifacts, prepares and delivers briefings to government stakeholders and senior leadership, and provides cybersecurity status reports and recommendations to Program Managers, ISSMs, and Authorizing Officials.
- Cybersecurity Program Coordination: Coordinates cybersecurity activities with program offices, system managers, and security personnel across the DLA enterprise to support effective execution of authorization and compliance efforts.
Clearance RequirementsÂ
There is a Secret Security clearance requirement for this position.Â
Required Skills & CertificationsÂ
- Current DoD 8570.01/8140 IAM Level III certification that includes one or more of the following: CISM, CISSP, GSLC, or CCISO.
- Five or more years of relevant Certification and Accreditation (C&A) and/or RMF cybersecurity experience.
- Demonstrated experience supporting DoD cybersecurity programs and system authorization processes.
- Strong understanding of Risk Management Framework (RMF) implementation and NIST cybersecurity standards.
- Experience assessing security controls and conducting authorization reviews within large, complex enterprise environments.
- Ability to evaluate vulnerabilities, assess risk, and determine impacts to system authorization status.
- Strong analytical, technical documentation, and communication skills.
Desired Skills & CertificationsÂ
- Experience supporting DoD or DLA program offices.
- Experience supporting DoD or DLA environments.
- Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, Engineering, Business Administration, or a related field.
- Five or more years of leadership experience with progressively increasing responsibility managing technical teams, programs, or contracts.
- At least one year of program or project management experience.
- Current Project Management Professional (PMP) certification or an equivalent recognized project management certification.
- Current Risk Management Professional certification such as PMP-RMP, CRISC, CISA, CISM, CGRC, or RIMS-CRMP.
Other Duties
- Able to travel within a week's notice.
- This job description is not designed to cover or contain a comprehensive listing of activities, duties, or responsibilities that are required of the employee for this job.
- Duties, responsibilities, and activities may change at any time with or without notice.Â
Overview
BMA is an employee-owned small business headquartered in Huntsville, AL that provides superior customer service by empowering all levels of our staff to make timely decisions to produce high-quality results. BMA fosters an environment of passion, precision, and dedication in order to fulfill our commitments to our partners, government, and country.
Benefits
We believe that our employees well-being is paramount to our success so our benefits package has been crafted with that in mind. We offer multiple healthcare coverage options to include low deductible, high deductible, and plans eligible for our Health Savings Account (HSA) option. Along with medical coverage, employees have dental, vision, accident & illness, short- and long-term disability all available to them. BMA proudly maintains a 401(k) plan with an industry leading 6% match that can include profit sharing based on company performance. Lastly, being an employee-owned company means that BMA offers a 100% Employee Stock Ownership Plan (ESOP), providing eligible employees the opportunity to earn stock in BMA, subject to plan eligibility and vesting requirements.Â
AAP & EEO Statement
 Beshenich Muir & Associates, LLC (BMA) is an Equal opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regards to race, color, religion, religious creed, gender, sexual orientation, gender identity, gender expression, transgender, pregnancy, marital status, national origin, ancestry, citizenship status, age, disability, protected Veteran Status, genetics or any other characteristics protected by applicable Federal, State, or Local Law.Â