1

Vulnerability Management Jobs (NOW HIRING)

Vulnerability Management Analyst Location- Joint Base Andrews, MD Clearance- Secret Certifications- CompTIA Security+ or equivalent About TIME Systems At TIME Systems, we are at the forefront of ...

Vulnerability Management Analyst Location- Joint Base Andrews, MD Clearance- Secret Certifications- CompTIA Security+ or equivalent About TIME Systems At TIME Systems, we are at the forefront of ...

Vulnerability Management Engineer- Hybrid | Cary, NC We're a leader in data and AI. Through our software and services, we inspire customers around the world to transform data into intelligence - and ...

ISSO - Vulnerability Management

MD ยท On-site

$100K - $114K/yr

The ISSO - Vulnerability Management will play a critical role in maintaining the cybersecurity posture of enterprise systems supporting national defense missions. This position is responsible for ...

Job Summary The Vulnerability Management Manager is responsible for identifying, assessing, prioritizing, and driving remediation of security vulnerabilities across the organization's infrastructure ...

Vulnerability Management Engineer Client: ATL - AIM General Location: 55 Trinity Avenue, Suite G700 Atlanta, Georgia 30303-0000 Duration:07+ Months Position Summary The Vulnerability Management ...

Job Summary The Vulnerability Management Manager is responsible for identifying, assessing, prioritizing, and driving remediation of security vulnerabilities across the organization's infrastructure ...

Showing results 21-40

Vulnerability Management information

What are the common challenges faced in a vulnerability management role?

Professionals in Vulnerability Management often encounter challenges such as rapidly evolving threat landscapes, prioritizing remediation efforts among numerous vulnerabilities, and ensuring continuous communication between technical and non-technical stakeholders. They may also need to adapt to changing regulatory requirements and work within tight deadlines to protect the organization from emerging risks. As part of this role, you'll collaborate regularly with IT, security, and business teams to ensure remediation steps are effectively implemented. Continuous learning and adaptability are important, as technologies and attack vectors change frequently in this field. Being proactive and detail-oriented will help you address these challenges and advance your career in cybersecurity.

What does a vulnerability management do?

A vulnerability management professional is responsible for identifying, assessing, and prioritizing security vulnerabilities in an organization's systems and networks. They use tools like vulnerability scanners and follow best practices to mitigate risks, often working closely with security teams and maintaining documentation for compliance. This role requires technical knowledge of cybersecurity principles and may involve certifications such as CISSP or CompTIA Security+.

What are the key skills and qualifications needed to thrive in a vulnerability management position?

To thrive in Vulnerability Management, you need a strong understanding of cybersecurity principles, network protocols, and risk assessment, typically supported by a relevant degree and experience in information security. Familiarity with vulnerability scanning tools (such as Nessus or Qualys), security frameworks, and industry certifications like CISSP or CompTIA Security+ is highly valued. Exceptional analytical thinking, communication skills, and an ability to work collaboratively across IT and business teams help professionals excel in this field. These competencies are crucial to effectively identifying, prioritizing, and mitigating security risks in dynamic organizational environments.

Is vulnerability management a good career?

Vulnerability management is a valuable cybersecurity role focused on identifying and mitigating security weaknesses in systems. It requires knowledge of security tools, risk assessment, and often certifications like CISSP or CompTIA Security+; the field offers strong job growth and demand for skilled professionals.

What is vulnerability management?

A Vulnerability Management job involves identifying, assessing, prioritizing, and mitigating security vulnerabilities in an organization's systems, networks, and applications. Professionals in this role use tools like vulnerability scanners and threat intelligence to detect weaknesses and coordinate remediation efforts with IT and security teams. They also establish policies, monitor security risks, and ensure compliance with industry standards. The goal is to reduce the organization's exposure to cyber threats and improve overall security posture.

More about Vulnerability Management jobs
What cities are hiring for Vulnerability Management jobs? Cities with the most Vulnerability Management job openings:
What are the most commonly searched types of Vulnerability Management jobs? The most popular types of Vulnerability Management jobs are:
What states have the most Vulnerability Management jobs? States with the most job openings for Vulnerability Management jobs include:
Infographic showing various Vulnerability Management job openings in the United States as of August 2026, with employment types broken down into 68% Full Time, and 32% Contract. Highlights an 80% In-person, and 20% Remote job distribution.

Vulnerability Management Analyst

TIME Systems

MD โ€ข On-site

Other

Medical, Dental, Vision, Life, Retirement

Posted 21 days ago


Job description

Vulnerability Management Analyst

Location- Joint Base Andrews, MD
Clearance- Secret
Certifications- CompTIA Security+ or equivalent



About TIME Systems
At TIME Systems, we are at the forefront of Technology, Innovation, Management, and Engineering solutions. Our commitment to empowering our team and fostering impactful leadership has established us as a leader in our field. Our work extends beyond business, actively contributing to local charities. We are proud of our CMMI Level 3 for Services and Development, ISO 9001:2015 certification, and our regular presence on Inc. Magazine’s “Inc. 5000 List” and Syracuse University’s IVMF “Vet 100 List."

Benefits

When you join our team, you’re joining a company that prioritizes your health, well-being, and financial security. Here’s a quick overview of our benefits: 

  • Health Coverage: Select from three plans, including a 100% company-funded employee-only plan.
  • Dental Coverage: Our dental plan offers extensive care with no annual maximum.
  • Vision: Our vision plan covers regular eye exams and corrective eyewear.
  • Life Insurance and AD&D and other customizable coverage options!
  • 401(k) Retirement Plan
  • Health Savings Account (HSA), Flexible Spending Account (FSA), Short- and Long-Term Disability Insurance, Employee Assistance Plan, and more!

Why Join Us
Veteran Preference – Strong value placed on military veterans and their skills.
Career Growth – Opportunities for professional development in a supportive environment.
Innovative Culture – Be part of a team that pushes boundaries and makes tangible impacts.


Role Summary


TIME Systems is looking for a Vulnerability Management Analyst to join our Cybersecurity Operations team supporting the Air Force National Capital Region (AFNCR) Information Technology Services (ITS) program. The selected candidate will support enterprise vulnerability management operations by performing vulnerability assessments, reviewing DISA STIG compliance, coordinating remediation activities, and assisting with Risk Management Framework (RMF) compliance across Department of Defense environments. This role will work closely with cybersecurity engineers, ISSOs, system administrators, and engineering teams to improve the organization’s security posture while supporting mission-critical systems throughout the AFNCR enterprise.


Key Responsibilities

  • Perform vulnerability assessments utilizing Tenable SecurityCenter, Nessus, and Assured Compliance Assessment Solution (ACAS) across classified and unclassified environments.
  • Review vulnerability scan results to identify CAT I, CAT II, and CAT III vulnerabilities, validate findings, identify false positives, and prioritize remediation activities.
  • Coordinate vulnerability remediation efforts with system administrators, ISSOs, engineering teams, and Queue Managers to ensure timely resolution of identified security findings.
  • Support the development, maintenance, and tracking of Plans of Action and Milestones (POA&Ms) in accordance with Risk Management Framework (RMF) requirements.
  • Validate and review DISA Security Technical Implementation Guides (STIGs), Security Content Automation Protocol (SCAP) results, and secure configuration baselines.
  • Generate vulnerability assessment reports, compliance metrics, executive summaries, and dashboards supporting leadership reporting and cybersecurity readiness inspections, including CCRI and CORA assessments.
  • Maintain ACAS asset inventories, credentialed scan configurations, asset groups, repositories, scan zones, and vulnerability data accuracy.
  • Assist with vulnerability trend analysis, risk scoring, and continuous monitoring activities to improve enterprise cybersecurity posture.
  • Support cybersecurity audits, inspections, accreditation activities, and system authorization efforts by providing required vulnerability documentation and evidence.
  • Collaborate with cybersecurity engineers, system administrators, network engineers, and ISSOs to implement remediation strategies and security best practices.
  • Maintain documentation including Standard Operating Procedures (SOPs), vulnerability management processes, scan schedules, and operational procedures.
  • Ensure compliance with Department of Defense (DoD), Air Force, DISA, RMF, and organizational cybersecurity policies and standards.


Requirements

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related technical discipline; equivalent education and experience may be substituted.
  • Minimum of four (4) years of professional cybersecurity or systems administration experience with at least one (1) year supporting vulnerability management, ACAS, Nessus, or Tenable SecurityCenter.
  • Active DoD Secret Security Clearance.
  • Current CompTIA Security+ CE or higher certification meeting DoD 8570/8140 IAT Level II requirements.
  • Hands-on experience performing vulnerability assessments using Tenable SecurityCenter, Nessus, or ACAS.
  • Working knowledge of DISA Security Technical Implementation Guides (STIGs), SCAP Compliance Checker (SCC), and secure system configuration practices.
  • Understanding of Risk Management Framework (RMF), NIST SP 800-53 security controls, POA&M management, and Air Force cybersecurity policies.
  • Experience reviewing vulnerability findings, validating scan results, identifying false positives, and supporting remediation efforts.
  • Strong analytical, troubleshooting, documentation, and organizational skills with excellent attention to detail.
  • Experience preparing technical reports, compliance documentation, vulnerability metrics, and executive summaries.
  • Excellent written and verbal communication skills with the ability to effectively communicate technical information to both technical and non-technical personnel.
  • Ability to work independently while managing multiple priorities in a fast-paced cybersecurity operations environment.


Preferred Qualifications

  • Experience supporting United States Air Force (USAF), Department of Defense (DoD), DISA, or other federal government cybersecurity environments.
  • Experience utilizing eMASS, SCAP Compliance Checker (SCC), HBSS, or other enterprise cybersecurity management tools.
  • Experience supporting Command Cyber Readiness Inspection (CCRI), Command Cyber Operational Readiness Assessment (CORA), or similar cybersecurity inspections.
  • Knowledge of Continuous Monitoring (ConMon) processes and vulnerability lifecycle management.
  • Experience developing PowerShell scripts, Nessus API integrations, or automation solutions to streamline vulnerability management processes.
  • Familiarity with Microsoft Windows Server, Red Hat Enterprise Linux (RHEL), VMware, Active Directory, and enterprise network infrastructure.
  • Understanding of cybersecurity risk assessment methodologies, CVSS scoring, threat prioritization, and risk-based remediation strategies.
  • Experience supporting Authorization to Operate (ATO) packages, security control assessments, and continuous authorization activities.
  • Demonstrated ability to collaborate across cybersecurity, engineering, and operations teams supporting mission-critical enterprise environments.



We are TIME Systems: Committed to Excellence, Dedicated to Service.


TIME Systems, LLC is an equal opportunity/affirmative action employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected veteran status, age, or any other characteristic protected by law.