Vulnerability Management Analyst
$125k - $131kThe Copper River Family of Companies
Copper River Cyber Solutions is seeking a highly motivated The Vulnerability Management Analyst to support the NIH cybersecurity program by identifying, analyzing, tracking, and reporting security vulnerabilities across enterprise systems, applications, databases, cloud environments, and network infrastructure. The Analyst collaborates with system owners, security engineers, RMF personnel, and operational teams to ensure vulnerabilities are properly assessed, prioritized, remediated, and verified in accordance with NIH, HHS, and Federal cybersecurity requirements.
The position plays a key role in maintaining a strong security posture through continuous monitoring, risk analysis, remediation tracking, and compliance reporting.
Responsibilities (include but are not limited to):
- Perform vulnerability assessments and analysis across NIH information systems and infrastructure.
- Perform threat-informed prioritization using exploitability, threat intelligence, CISA Known Exploited Vulnerabilities (KEV), mission criticality, system exposure, and compensating controls.
- Assess vulnerability risk within the context of system criticality, data sensitivity, and organizational risk tolerance.
- Develop vulnerability dashboards, remediation metrics, trend analyses, and executive reporting products.
- Review and analyze vulnerability scan results from enterprise security tools.
- Validate findings to determine severity, exploitability, and potential impact.
- Conduct risk-based prioritization of vulnerabilities and security weaknesses.
- Coordinate with technical teams to assess remediation requirements and timelines.
- Manage the full lifecycle of vulnerability identification, remediation, and closure.
- Track vulnerabilities from discovery through remediation and validation.
- Maintain vulnerability repositories, remediation records, and status reporting.
- Monitor remediation progress and escalate overdue findings as appropriate.
- Verify corrective actions and document closure activities.
- Support continuous monitoring activities across NIH systems and applications.
- Analyze vulnerability trends and identify recurring issues.
- Evaluate security risks associated with discovered vulnerabilities.
- Collaborate with RMF/A&A teams to support Authorization to Operate (ATO) activities.
- Assist with the management and tracking of Plans of Action and Milestones (POA&Ms).
- Provide vulnerability-related evidence and documentation for audits, assessments, and authorization activities.
Essential Job Qualifications and Requirements:
Education:
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field
Required Qualifications:
- Minimum 5 years of experience in cybersecurity, vulnerability management, information assurance, or security operations supporting Federal environments.
- Experience supporting POA&M development, remediation tracking, corrective action validation, or vulnerability closure activities.
- Experience conducting vulnerability assessments and remediation tracking.
- Familiarity with:
- NIST RMF (SP 800-37)
- NIST SP 800-53 Rev. 5
- FISMA
- Federal cybersecurity compliance requirements
- Risk assessment methodologies
- Experience analyzing vulnerability data and developing remediation recommendations.
- Strong analytical, problem-solving, and communication skills.
- Ability to obtain and maintain an NIH Public Trust.
Preferred Qualifications:
- One or more of the following certifications:
-
- Security+
- Certified Ethical Hacker (CEH)
- CISSP
- GIAC Vulnerability Assessment (GVA)
- GIAC Information Security Fundamentals (GISF)
- GSEC
- CAP (Certified Authorization Professional)
- CISM
- CRISC
- Experience supporting NIH, HHS, or other Federal civilian agencies.
- Experience working within FISMA-compliant environments.
- Knowledge of cloud security and vulnerability management practices.
- Experience supporting continuous diagnostics and mitigation (CDM) initiatives.
- Understanding of FedRAMP and Zero Trust security principles.
- Experience coordinating remediation activities across multiple stakeholders.
Position Pay Range
$125,000—$131,000 USD
About Copper River & The Native Village of Eyak:
Owned by the Native Village of Eyak (NVE), a federally recognized Alaska Native Tribe, the Copper River Family of Companies are a collection of entities that deliver a complementary set of solutions and services to support the diverse missions and requirements of our clients. Proud participants of the Small Business Administration’s (SBA) 8(a) Business Development Program since 2006, our companies consist of both current and graduation SBA 8(a) entities. It is our collective purpose to support the Tribe and diversify the NVE’s ability to facilitate economic advancement.
The income generated from our companies helps the Native Village of Eyak fund health and social services, economic development, natural resource/environmental education, jobs, job training, and other benefits to the NVE in a manner that is consistent with Alaskan Native cultural values and traditions.
Copper River’s Culture
The Copper River Family of Companies has a positive, supportive, and thriving culture. At the foundation of our culture is a focus on collaboration. No matter your role or which operating company you work for, we are ONE TEAM working toward the same goals for our customers and for our collective owner- The Native Village of Eyak. How we treat each other is just as important as the work we deliver.
Benefits
- Comprehensive medical, dental, and vision coverage
- Flexible Spending Account - healthcare and dependent care
- Health Savings Account - high deductible medical plan
- Retirement 401(k) with employer match
- Open leave policy and paid holidays
- Additional benefits including tuition reimbursement, transportation expense account, employee assistance program, and more!
Note : Benefits are offered based on employment classification and applicable contract requirements. Eligibility may vary by position.
Disclaimer:
The Copper River Family of Companies provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws.
- ...you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.We are currently seeking a Vulnerability Management Analyst- Hybrid to join our team in Dallas, Texas (US-TX), United States (US).The Vulnerability Management Analyst is...SuggestedWork at officeRemote workFlexible hours
$106.4k - $149k
...you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.We are currently seeking a Vulnerability Management Analyst- Bilingual Japanese/English to join our team in Dallas, Texas (US-TX), United States (US).The Vulnerability Management...SuggestedFull timeTemporary workWork at officeRemote workFlexible hours- ...Vulnerability Management Analyst (AI Training) About the Role We're looking for experienced security practitioners to help evaluate and improve AI systems that reason about real-world vulnerability management. Your expertise in CVEs, exposure analysis, and remediation...SuggestedHourly payOngoing contractContract workFreelanceRemote workFlexible hours
- ...Requirements: • 8-10 years of experience in vulnerability management • Proficiency with Qualys, Tenable, and Nessus • Strong background in cloud security and container security • Experience with risk assessment and vulnerability triage in enterprise technology...SuggestedRemote work
$131.32k - $154.49k
...LLC. (BGS) has created this Evergreen Talent Pool post for gathering qualified candidates for a position relating to Vulnerability Management Analyst to support our clients in various locations across the US. BGS is an engineering, technology, and security...SuggestedFull timeContract workTemporary workRemote workMonday to FridayNight shift- ...Vulnerability Management Analyst Apex Systems is a world class technology services business that incorporates industry insights and experience to deliver solutions that fulfill our clients’ digital visions. Apex has an opportunity for a remote Vulnerability Management...Remote work
- ...Vulnerability Management Analyst Remote 12-Month Contract 8-10 years Our client is seeking a Vulnerability Management Analyst to validate and triage vulnerability findings, assess risk-based prioritization, and engage stakeholders throughout the vulnerability lifecycle...Contract workRemote work
- ...Vulnerability Management Analyst (AI Training) About the Role We partner with the world's leading AI research labs to build smarter, safer AI systems - and we need experienced security professionals to help get there. As a Vulnerability Management Analyst, you...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
- ...Vulnerability Management Analyst Location: Crownsville, MD (Remote) Duration: 6+ Months Job Description: Need 12+ years of experience with NIST Risk Management Framework (RMF) supporting technical assessment (vulnerability scans) of control implementations...Remote workWeekend work
- ...benefits, and ongoing learning opportunities, backed by a culture that values and supports our team. We are seeking a Vulnerability Management Analyst (Tenable/Nessus & Metrics) to support vulnerability tracking, remediation coordination, and security metrics reporting...Full timeWork from homeFlexible hours1 day per week
- cFocus Software seeks a Vulnerability Management Analyst to join our program supporting the United States International Defense Finance Agency (DFC). This position is remote. This position requires an Active Public Trust clearance. Qualifications: ~ Active Public...Full timeFor contractorsRemote work
£1,500 per month
We are looking for an enthusiastic and detail-oriented Vulnerability Management Analyst to join our information security and data protection team. This is an ideal opportunity for someone with real-world experience in information security and data protection. It's a great...Full timeCasual workFlexible hours- Vulnerability Management Analyst (AI Training) About The Role We're looking for experienced security practitioners to help evaluate and improve AI systems that reason about real-world cybersecurity risk. Your expertise in vulnerability management, exposure analysis, and...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
$110k - $130k
...produce meaningful results. This is a contingent position based on contract win. SkyePoint Decisions is seeking a Vulnerability Management Analyst to support a cybersecurity program by identifying, analyzing, tracking, and reporting security vulnerabilities across...Contract workRemote work- ...good in the world. To that end, the Office of Information Technology (OIT) is seeking a collaborative and analytical Vulnerability Management Security Analyst to join our information security team. This position plays a key role in helping OIT and campus technology teams...Work at officeRemote workVisa sponsorship
$118k - $130k
...Job Description Job Description Job Title: Vulnerability Management & Offensive Security Analyst Primary Location: Remote Position Type: Direct Hire Overview TalentFish is casting a line for a Vulnerability Management & Offensive Security Analyst. This...Contract workWork experience placementInternshipRemote workVisa sponsorship- ...defined problem space. We bring Public and Private, Civilian and Military expertise to every case. We are hiring a Sr. System Vulnerability Analyst to work in Fort Meade, MD. Position location is subject to change based on central MD client's needs. Required: TS/SCI...Local areaWork from homeFlexible hours
$99k - $225k
Enterprise Cybersecurity Vulnerability Risk AnalystThe Opportunity:Cyber threats are everywhere, and vulnerabilities... ....As a Vulnerability Exception and Deferral Analyst on our Enterprise IT and Cyber Risk team, you’ll manage the operational lifecycle of vulnerability...Full timeContract workPart timeWork at officeLocal areaRemote work$97.29k - $133.79k
...For more information, visit guardanthealth.com and follow the company on LinkedIn, X (Twitter) and Facebook. As a Revenue Management Systems Analyst, you will be responsible for supporting and optimizing the billing processes and systems used by the Screening...Full timeWork at officeRemote workWork from home- ...Job Description Location: Oak Ridge, TN Job Title: Vulnerability Analyst Career Level From: Associate Career Level To: Senior... ...also assists Vulnerability and Compliance Assessment Management with cyber analysis to support requested exception requests...Work from homeFlexible hours
- ...message the job poster from Headway Tek Inc Position Title : Vulnerability Analyst (Onshore) – 2 Openings Location : McKinney, TX 4days onsite... ...operational realities. Key Responsibilities Vulnerability Management Perform vulnerability assessments across AWS, Azure, GCP,...Contract workWork from home
$55k - $75k
...capabilities, improving documentation, and collaborating closely with the engineering manager and other stakeholders to ensure seamless service delivery. Duties and Responsibilities: Vulnerability Assessment and Management Conduct regular vulnerability scanning...Permanent employmentWork at officeRemote work- A cybersecurity company is seeking a Cyber Risk Analyst to identify and prioritize vulnerabilities in their systems. This full-time role requires proficiency in vulnerability assessment tools and a strong understanding of cybersecurity frameworks. The candidate will conduct...Full timeRemote work
- ...Experience performing vulnerability assessment, analysis, and remediation activities across endpoint environments. Ability to review... ...technical stakeholders. Experience with operating system patch management and endpoint security controls. Strong written and verbal...Remote work
- ...new era in space and find a career that's built for you.The Bobcat program is seeking a Systems Administrator/Configuration Management Analyst.Your responsibilities will include the following: • Analyzes proposed changes of product design to determine effect on overall...Full timeFor subcontractorWork at officeRemote workMonday to FridayFlexible hours
- ...S. Government customer to provide cybersecurity vulnerability analysis support to reduce the prevalence and impact... ...(CIKR). The Cybersecurity Vulnerability Analyst utilizes cybersecurity best practices, risk management techniques, critical thinking, and strong analytical...
- ...Senior Vulnerability Analyst Location: MA / Austin TX / MD Team: Research Employment Type: Full-Time, Remote About VulnCheck Exploitation... ...Analyst with a deep understanding of the vulnerability management ecosystem, hands-on experience with the CVE process, and...Full timeWork experience placementRemote work
- ...gathering qualified candidates for a position relating to Vulnerability Analyst which would support our clients. BGS is an engineering, technology... ...at every stage, from strategic planning and program management to the execution of project management, procurement, supply...Temporary workRemote work
- ...Vulnerability & Threat Intelligence Analyst Location: Cheltenham, UK Team: Research Employment Type: Full-Time, Remote About VulnCheck VulnCheck is transforming vulnerability intelligence by helping security teams act faster and with more confidence. Our platform...Full timeRemote work
- Overview Title: Cyber Risk Analyst W-2 Only (no 1099) Must be a U.S. Citizen Company's Location: Lemont, IL Job Description... ...education and awareness, cybersecurity incident management, vulnerability management, compliance, and cybersecurity risk management....Full timeContract workFor contractorsWork at officeRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vulnerability Management Analyst. Be the first to apply!
- remote senior business analyst Remote
- senior business analyst Remote
- business strategy analyst Remote
- business analyst part time remote Remote
- business analyst work from home Remote
- medicaid business analyst Remote
- engineering business analyst Remote
- capital markets business analyst Remote
- agile business analyst Remote
- software asset management analyst Remote

