Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Vulnerability Management Analyst

$125k - $131k
Full-time

The Copper River Family of Companies

Copper River Cyber Solutions is seeking a highly motivated The Vulnerability Management Analyst to support the NIH cybersecurity program by identifying, analyzing, tracking, and reporting security vulnerabilities across enterprise systems, applications, databases, cloud environments, and network infrastructure. The Analyst collaborates with system owners, security engineers, RMF personnel, and operational teams to ensure vulnerabilities are properly assessed, prioritized, remediated, and verified in accordance with NIH, HHS, and Federal cybersecurity requirements.

The position plays a key role in maintaining a strong security posture through continuous monitoring, risk analysis, remediation tracking, and compliance reporting.

Responsibilities (include but are not limited to):

  • Perform vulnerability assessments and analysis across NIH information systems and infrastructure.
  • Perform threat-informed prioritization using exploitability, threat intelligence, CISA Known Exploited Vulnerabilities (KEV), mission criticality, system exposure, and compensating controls.
  • Assess vulnerability risk within the context of system criticality, data sensitivity, and organizational risk tolerance.
  • Develop vulnerability dashboards, remediation metrics, trend analyses, and executive reporting products.
  • Review and analyze vulnerability scan results from enterprise security tools.
  • Validate findings to determine severity, exploitability, and potential impact.
  • Conduct risk-based prioritization of vulnerabilities and security weaknesses.
  • Coordinate with technical teams to assess remediation requirements and timelines.
  • Manage the full lifecycle of vulnerability identification, remediation, and closure.
  • Track vulnerabilities from discovery through remediation and validation.
  • Maintain vulnerability repositories, remediation records, and status reporting.
  • Monitor remediation progress and escalate overdue findings as appropriate.
  • Verify corrective actions and document closure activities.
  • Support continuous monitoring activities across NIH systems and applications.
  • Analyze vulnerability trends and identify recurring issues.
  • Evaluate security risks associated with discovered vulnerabilities.
  • Collaborate with RMF/A&A teams to support Authorization to Operate (ATO) activities.
  • Assist with the management and tracking of Plans of Action and Milestones (POA&Ms).
  • Provide vulnerability-related evidence and documentation for audits, assessments, and authorization activities.

Essential Job Qualifications and Requirements:

Education:

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field

Required Qualifications:

  • Minimum 5 years of experience in cybersecurity, vulnerability management, information assurance, or security operations supporting Federal environments.
  • Experience supporting POA&M development, remediation tracking, corrective action validation, or vulnerability closure activities.
  • Experience conducting vulnerability assessments and remediation tracking.
  • Familiarity with:
    • NIST RMF (SP 800-37)
    • NIST SP 800-53 Rev. 5
    • FISMA
    • Federal cybersecurity compliance requirements
    • Risk assessment methodologies
  • Experience analyzing vulnerability data and developing remediation recommendations.
  • Strong analytical, problem-solving, and communication skills.
  • Ability to obtain and maintain an NIH Public Trust.

Preferred Qualifications:

  • One or more of the following certifications:
    • Security+
    • Certified Ethical Hacker (CEH)
    • CISSP
    • GIAC Vulnerability Assessment (GVA)
    • GIAC Information Security Fundamentals (GISF)
    • GSEC
    • CAP (Certified Authorization Professional)
    • CISM
    • CRISC
  • Experience supporting NIH, HHS, or other Federal civilian agencies.
  • Experience working within FISMA-compliant environments.
  • Knowledge of cloud security and vulnerability management practices.
  • Experience supporting continuous diagnostics and mitigation (CDM) initiatives.
  • Understanding of FedRAMP and Zero Trust security principles.
  • Experience coordinating remediation activities across multiple stakeholders.

Position Pay Range

$125,000—$131,000 USD

About Copper River & The Native Village of Eyak:

Owned by the Native Village of Eyak (NVE), a federally recognized Alaska Native Tribe, the Copper River Family of Companies are a collection of entities that deliver a complementary set of solutions and services to support the diverse missions and requirements of our clients. Proud participants of the Small Business Administration’s (SBA) 8(a) Business Development Program since 2006, our companies consist of both current and graduation SBA 8(a) entities. It is our collective purpose to support the Tribe and diversify the NVE’s ability to facilitate economic advancement.

The income generated from our companies helps the Native Village of Eyak fund health and social services, economic development, natural resource/environmental education, jobs, job training, and other benefits to the NVE in a manner that is consistent with Alaskan Native cultural values and traditions.

Copper River’s Culture

The Copper River Family of Companies has a positive, supportive, and thriving culture. At the foundation of our culture is a focus on collaboration. No matter your role or which operating company you work for, we are ONE TEAM working toward the same goals for our customers and for our collective owner- The Native Village of Eyak. How we treat each other is just as important as the work we deliver.

Benefits

  • Comprehensive medical, dental, and vision coverage
  • Flexible Spending Account - healthcare and dependent care
  • Health Savings Account - high deductible medical plan
  • Retirement 401(k) with employer match
  • Open leave policy and paid holidays
  • Additional benefits including tuition reimbursement, transportation expense account, employee assistance program, and more!

Note : Benefits are offered based on employment classification and applicable contract requirements. Eligibility may vary by position.

Disclaimer:

The Copper River Family of Companies provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws.

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Vulnerability Management Analyst in Remote vacancy
  •  ...you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.We are currently seeking a Vulnerability Management Analyst- Hybrid to join our team in Dallas, Texas (US-TX), United States (US).The Vulnerability Management Analyst is... 
    Suggested
    Work at office
    Remote work
    Flexible hours

    NTT DATA

    Dallas, TX
    3 days ago
  • $106.4k - $149k

     ...you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.We are currently seeking a Vulnerability Management Analyst- Bilingual Japanese/English to join our team in Dallas, Texas (US-TX), United States (US).The Vulnerability Management... 
    Suggested
    Full time
    Temporary work
    Work at office
    Remote work
    Flexible hours

    NTT DATA

    Dallas, TX
    3 days ago
  •  ...Vulnerability Management Analyst (AI Training) About the Role We're looking for experienced security practitioners to help evaluate and improve AI systems that reason about real-world vulnerability management. Your expertise in CVEs, exposure analysis, and remediation... 
    Suggested
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    Denver, CO
    4 days ago
  •  ...Requirements: • 8-10 years of experience in vulnerability management • Proficiency with Qualys, Tenable, and Nessus • Strong background in cloud security and container security • Experience with risk assessment and vulnerability triage in enterprise technology... 
    Suggested
    Remote work

    Saxon Global

    United States
    5 days ago
  • $131.32k - $154.49k

     ...LLC. (BGS) has created this Evergreen Talent Pool post for gathering qualified candidates for a position relating to Vulnerability Management Analyst to support our clients in various locations across the US. BGS is an engineering, technology, and security... 
    Suggested
    Full time
    Contract work
    Temporary work
    Remote work
    Monday to Friday
    Night shift

    Boston Government Services

    Oak Ridge, TN
    4 days ago
  •  ...Vulnerability Management Analyst Apex Systems is a world class technology services business that incorporates industry insights and experience to deliver solutions that fulfill our clients’ digital visions. Apex has an opportunity for a remote Vulnerability Management... 
    Remote work

    Software Technology Inc

    United States
    3 days ago
  •  ...Vulnerability Management Analyst Remote 12-Month Contract 8-10 years Our client is seeking a Vulnerability Management Analyst to validate and triage vulnerability findings, assess risk-based prioritization, and engage stakeholders throughout the vulnerability lifecycle... 
    Contract work
    Remote work

    RIT Solutions

    United States
    3 days ago
  •  ...Vulnerability Management Analyst (AI Training) About the Role We partner with the world's leading AI research labs to build smarter, safer AI systems - and we need experienced security professionals to help get there. As a Vulnerability Management Analyst, you... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    Seattle, WA
    4 days ago
  •  ...Vulnerability Management Analyst Location: Crownsville, MD (Remote) Duration: 6+ Months Job Description: Need 12+ years of experience with NIST Risk Management Framework (RMF) supporting technical assessment (vulnerability scans) of control implementations... 
    Remote work
    Weekend work

    Anveta

    Crownsville, MD
    4 days ago
  •  ...benefits, and ongoing learning opportunities, backed by a culture that values and supports our team. We are seeking a Vulnerability Management Analyst (Tenable/Nessus & Metrics) to support vulnerability tracking, remediation coordination, and security metrics reporting... 
    Full time
    Work from home
    Flexible hours
    1 day per week

    Dane

    Chantilly, Loudoun County, VA
    1 day ago
  • cFocus Software seeks a Vulnerability Management Analyst to join our program supporting the United States International Defense Finance Agency (DFC). This position is remote. This position requires an Active Public Trust clearance. Qualifications: ~ Active Public... 
    Full time
    For contractors
    Remote work

    cFocus Software Incorporated

    Washington DC
    16 days ago
  • £1,500 per month

    We are looking for an enthusiastic and detail-oriented Vulnerability Management Analyst to join our information security and data protection team. This is an ideal opportunity for someone with real-world experience in information security and data protection. It's a great... 
    Full time
    Casual work
    Flexible hours

    Inspired Thinking Group

    Birmingham, AL
    2 days ago
  • Vulnerability Management Analyst (AI Training) About The Role We're looking for experienced security practitioners to help evaluate and improve AI systems that reason about real-world cybersecurity risk. Your expertise in vulnerability management, exposure analysis, and... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    New York, NY
    23 hours ago
  • $110k - $130k

     ...produce meaningful results. This is a contingent position based on contract win. SkyePoint Decisions is seeking a Vulnerability Management Analyst to support a cybersecurity program by identifying, analyzing, tracking, and reporting security vulnerabilities across... 
    Contract work
    Remote work

    SkyePoint Decisions

    Washington DC
    11 days ago
  •  ...good in the world. To that end, the Office of Information Technology (OIT) is seeking a collaborative and analytical Vulnerability Management Security Analyst to join our information security team. This position plays a key role in helping OIT and campus technology teams... 
    Work at office
    Remote work
    Visa sponsorship

    University of Notre Dame

    Notre Dame, IN
    3 days ago
  • $118k - $130k

     ...Job Description Job Description Job Title: Vulnerability Management & Offensive Security Analyst Primary Location: Remote Position Type: Direct Hire Overview TalentFish is casting a line for a Vulnerability Management & Offensive Security Analyst. This... 
    Contract work
    Work experience placement
    Internship
    Remote work
    Visa sponsorship

    Gulf Coast Automation Group

    Chicago, IL
    28 days ago
  •  ...defined problem space. We bring Public and Private, Civilian and Military expertise to every case. We are hiring a Sr. System Vulnerability Analyst to work in Fort Meade, MD. Position location is subject to change based on central MD client's needs. Required: TS/SCI... 
    Local area
    Work from home
    Flexible hours

    Themis Insight LLC

    Maryland
    2 days ago
  • $99k - $225k

    Enterprise Cybersecurity Vulnerability Risk AnalystThe Opportunity:Cyber threats are everywhere, and vulnerabilities...  ....As a Vulnerability Exception and Deferral Analyst on our Enterprise IT and Cyber Risk team, you’ll manage the operational lifecycle of vulnerability... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    4 days ago
  • $97.29k - $133.79k

     ...For more information, visit guardanthealth.com and follow the company on LinkedIn, X (Twitter) and Facebook. As a Revenue Management Systems Analyst, you will be responsible for supporting and optimizing the billing processes and systems used by the Screening... 
    Full time
    Work at office
    Remote work
    Work from home

    Guardant Health

    Palo Alto, CA
    4 days ago
  •  ...Job Description Location: Oak Ridge, TN Job Title: Vulnerability Analyst Career Level From: Associate Career Level To: Senior...  ...also assists Vulnerability and Compliance Assessment Management with cyber analysis to support requested exception requests... 
    Work from home
    Flexible hours

    National Guard Employment Network

    Oak Ridge, TN
    3 days ago
  •  ...message the job poster from Headway Tek Inc Position Title : Vulnerability Analyst (Onshore) – 2 Openings Location : McKinney, TX 4days onsite...  ...operational realities. Key Responsibilities Vulnerability Management Perform vulnerability assessments across AWS, Azure, GCP,... 
    Contract work
    Work from home

    Headway Tek Inc

    Mckinney, TX
    1 day ago
  • $55k - $75k

     ...capabilities, improving documentation, and collaborating closely with the engineering manager and other stakeholders to ensure seamless service delivery. Duties and Responsibilities: Vulnerability Assessment and Management Conduct regular vulnerability scanning... 
    Permanent employment
    Work at office
    Remote work

    Summit 7 Systems

    United States
    1 day ago
  • A cybersecurity company is seeking a Cyber Risk Analyst to identify and prioritize vulnerabilities in their systems. This full-time role requires proficiency in vulnerability assessment tools and a strong understanding of cybersecurity frameworks. The candidate will conduct... 
    Full time
    Remote work

    Delan Associates Inc

    Lemont, IL
    2 days ago
  •  ...Experience performing vulnerability assessment, analysis, and remediation activities across endpoint environments. Ability to review...  ...technical stakeholders. Experience with operating system patch management and endpoint security controls. Strong written and verbal... 
    Remote work

    Insight Global

    United States
    3 days ago
  •  ...new era in space and find a career that's built for you.The Bobcat program is seeking a Systems Administrator/Configuration Management Analyst.Your responsibilities will include the following: • Analyzes proposed changes of product design to determine effect on overall... 
    Full time
    For subcontractor
    Work at office
    Remote work
    Monday to Friday
    Flexible hours

    Lockheed Martin

    Springfield, VA
    2 days ago
  •  ...S. Government customer to provide cybersecurity vulnerability analysis support to reduce the prevalence and impact...  ...(CIKR). The Cybersecurity Vulnerability Analyst utilizes cybersecurity best practices, risk management techniques, critical thinking, and strong analytical... 

    Node.Digital

    Arlington, VA
    1 day ago
  •  ...Senior Vulnerability Analyst Location: MA / Austin TX / MD Team: Research Employment Type: Full-Time, Remote About VulnCheck Exploitation...  ...Analyst with a deep understanding of the vulnerability management ecosystem, hands-on experience with the CVE process, and... 
    Full time
    Work experience placement
    Remote work

    Ten Eleven Ventures

    Maryland, MD
    6 days ago
  •  ...gathering qualified candidates for a position relating to Vulnerability Analyst which would support our clients. BGS is an engineering, technology...  ...at every stage, from strategic planning and program management to the execution of project management, procurement, supply... 
    Temporary work
    Remote work

    Boston Government Services

    Los Alamos, NM
    1 day ago
  •  ...Vulnerability & Threat Intelligence Analyst Location: Cheltenham, UK Team: Research Employment Type: Full-Time, Remote About VulnCheck VulnCheck is transforming vulnerability intelligence by helping security teams act faster and with more confidence. Our platform... 
    Full time
    Remote work

    Ten Eleven Ventures

    United Kingdom
    6 days ago
  • Overview Title: Cyber Risk Analyst W-2 Only (no 1099) Must be a U.S. Citizen Company's Location: Lemont, IL Job Description...  ...education and awareness, cybersecurity incident management, vulnerability management, compliance, and cybersecurity risk management.... 
    Full time
    Contract work
    For contractors
    Work at office
    Remote work
    Flexible hours

    Delan Associates Inc

    Lemont, IL
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Vulnerability Management Analyst. Be the first to apply!