Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Vulnerability Analyst

$69.55k - $125.73k

Careerwebsite

We are currently seeking a Vulnerability Analyst to join the Compartmented Enterprise Services Office (CESO) effort. This program is establishing a modern secure web service (SWS) operation as part of a state-of-the-art, highly automated platform capable of supporting a rapidly expanding customer population. This position is based in Arlington, VA and is 100% on-site. Requires a TS/SCI US Government Security Clearance to start. Primary Responsibilities Responsible for meeting both regulatory (Legal and Mandated Requirements) and non-regulatory (Real-World Threat Reduction) compliance demands across the CESO environment. Assist in the management and maintenance of the IAVA (Information Assurance Vulnerability Alerts) program for CESO systems. Manage and enforce information security policies, and train and educate end-users on proper security practices. Conduct security and risk assessments using established frameworks (e.g., NIST, RMF, Common Criteria), mitigating risk via security controls and testing and evaluation to certify and accredit commercial security products used within the CESO platform. Develop, update, organize, maintain, and track RMF documentation using information obtained from the customer. Ensure privacy of data throughout its lifecycle; perform vulnerability management (scanning, assessment, reporting, and mitigation verification), business continuity, and disaster recovery activities. Coordinate with infrastructure, storage, database, and application teams to align vulnerability management activities with CESO's operational and compliance requirements. Maintain documentation, operational procedures, and compliance reports supporting CESO's secure cloud migration. Responsible for a combination of duties to protect information and maintain security controls across the CESO system, site, or program in order to reduce risk. Basic Qualifications Bachelor's degree and 2+ years of related IT security experience; additional experience, education, or training may be considered in lieu of degree. Active TS/SCI security clearance required DoDD 8140 compliant certification, at minimum IAT Level II (e.g., Security+ CE), at start. Experience with the Defense Information Systems Agency (DISA) security model, controls, and authorization processes for standard computing systems and cloud computing across the Department of Defense Experience conducting activities associated with Information Assurance Vulnerability Alerts (IAVA) for example, Cybersecurity and Infrastructure Security Agency (CISA). Experience with creating Information Assurance documentation such as Security Control Traceability Metrics (SCTM), Risk Assessment Report (RAR), Security Assessment Report (SAR) and maintaining POA&Ms (Plans of Action and Milestones). Experience with ACAS and SEIM tools. Experience with application and hardware security settings for vendor and/or DISA best business practices. Candidate may be asked to obtain a CI Polygraph in the future. Preferred Qualifications Prior experience with DISA and DISA's support to mission partners. TS/SCI with CI Polygraph preferred. Experience with ACAS, SPLUNK, ACT (cybersecurity event), IAVA reporting, and eMASS. Familiarity with vulnerability management across enterprise applications and infrastructure (e.g., Oracle, SQL Server, Exchange, virtualization platforms, Windows, Red Hat). Understanding of disaster recovery and business continuity concepts as they apply to secure cloud migrations. If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares. Pay Range Pay Range $69,550.00 - $125,725.00 About Leidos Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit Pay and Benefits Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at Securing Your Data Beware of fake employment opportunities using Leidos’ name. Leidos will never ask you to provide payment‑related information during any part of the employment application process (i.e., ask you for money), nor will Leidos ever advance money as part of the hiring process (i.e., send you a check or money order before doing any work). Further, Leidos will only communicate with you through emails that are generated by the Leidos.com automated system - never from free commercial services (e.g., Gmail, Yahoo, Hotmail) or via WhatsApp, Telegram, etc. If you received an email purporting to be from Leidos that asks for payment-related information or any other personal information (e.g., about you or your previous employer), and you are concerned about its legitimacy, please make us aware immediately by emailing us at View email address on click.appcast.io. If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission. Commitment to Non-Discrimination All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws. #J-18808-Ljbffr

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Vulnerability Analyst in Arlington, VA vacancy
  • DescriptionSAIC is seeking a highly skilled Senior Vulnerability Analyst with a strong technical background to join our team in support of a critical US government agency in the National Capital Region. This is an exciting opportunity to work with a team responsible for... 
    Suggested
    2 days per week

    Science Applications International Corporation

    Washington DC
    1 day ago
  • $86.8k - $198k

    Enterprise Cybersecurity Vulnerability Analyst, SeniorThe Opportunity:Support Booz Allen Hamilton's internal Enterprise Cybersecurity team by utilizing enterprise-level vulnerability scanning and assessment tools to identify internally and externally facing vulnerabilities... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    15 hours ago
  • $110k - $120k

     ...cybersecurity firm with a mission to safeguard and protect our customers from increasing threats and vulnerabilities in this digital age. TDI is seeking a Vulnerability Analyst to join the Compartmented Enterprise Services Office (CESO) effort. This program is... 
    Suggested
    Permanent employment
    Contract work
    Work at office
    Night shift
    Day shift

    Tetrad Digital Integrity LLC

    Arlington, VA
    1 day ago
  •  ...Job Description Job Description Areté is looking for the person who makes sure vulnerabilities actually get closed — not just found. As our Vulnerability Management Analyst in Falls Church, VA, you will own the end-to-end remediation cycle — scanning, prioritization... 
    Suggested
    Full time

    Arete Associates

    Falls Church, VA
    a month ago
  • $80k - $128k

    ResponsibilitiesPeraton is currently seeking a Risk and Vulnerability Analyst.Location: Chandler, AZ or Washington DC.Role and Responsibilities: The Risk and Vulnerability Analyst supports a 24x7 Security Operations Center (SOC) by identifying, analyzing, and prioritizing... 
    Suggested
    Contract work
    Shift work

    Peraton Corporation

    Washington DC
    1 day ago
  •  ...missions worldwide.Job Description*** This position is contingent upon contract award ***Overview SOSi is seeking a Risk and Vulnerability Analyst II to support vulnerability assessment and risk analysis activities in alignment with our customer. This role is responsible... 
    Contract work
    Work at office
    Worldwide
    Monday to Friday
    Weekend work
    Afternoon shift

    SOSi

    Washington DC
    1 day ago
  • $116.35k - $210.33k

     ...operational stakeholders.Help close the sensor-to-shooter loop by connecting intelligence, engineering analysis, and operational vulnerabilities.Primary ResponsibilitiesAll-Source Intelligence ReviewReview current intelligence assessments and reconcile available source... 
    Full time
    Work at office

    Leidos

    Suitland, MD
    6 hours ago
  • $104k - $166k

     ...operations across diverse and high‑impact environments. This role supports critical national security missions by identifying vulnerabilities, emulating real‑world adversaries, and strengthening defensive cyber capabilities across enterprise, cloud, mobile, IoT, and High... 
    Contract work
    Currently hiring
    Shift work

    Peraton Corporation

    Washington DC
    1 day ago
  •  ...activities, assessing security posture across enterprise environments, and supporting identification, validation, and reporting of vulnerabilities to improve cyber defense resilience.Responsibilities· Conduct penetration testing across enterprise systems, applications, and... 
    Contract work
    Work at office
    Worldwide
    Monday to Friday
    Weekend work
    Afternoon shift

    SOSi

    Washington DC
    15 hours ago
  • $90k - $130k

     ...curated analytics tools, actively identifying and exploiting vulnerabilities to validate and strengthen the platform’s security posture against...  ...Penetration Testing Engineer (CPTE)CompTIA CyberSecurity Analyst (CySA+)Federal IT Security Professional-Auditor (FITSP-A)GIAC... 
    Full time
    Work at office

    Praescient Analytics

    Arlington, VA
    4 days ago
  • $130k - $190k

     ...systems and technologies for the Department of Homeland Security. Responsibilities may include:Conducting cybersecurity assessments, vulnerability assessments, and security control validation in support of federal acquisition-based test and evaluation activitiesPerforming... 
    Full time
    Work experience placement
    Work at office
    Local area
    Remote work
    Worldwide
    Flexible hours

    Battelle Memorial Institute

    Washington DC
    1 day ago
  •  ...business systems. The successful candidate will partner closely with business stakeholders, developers, project managers, business analysts, vendors, and subject matter experts to validate system functionality, ensure data integrity, and support successful software... 

    Navy Mutual

    Arlington, VA
    1 day ago
  •  ...join our cybersecurity team. In this role, you will identify vulnerabilities and test the security of networks, applications, and systems...  ...** SIMILAR CAREER TITLES Ethical Hacker, Vulnerability Analyst, Security Consultant, Red Team Specialist, Cybersecurity Analyst... 
    Temporary work
    For contractors
    Immediate start
    Flexible hours

    Cymertek

    McLean, VA
    4 days ago
  •  ...privilege escalation and lateral movement Examine results of web/OS scanners, scans and static source code analysis Identify vulnerabilities, misconfigurations, and compliance issues Write final reports, defend all findings to include the risk or vulnerability,... 

    General Dynamics Information Technology

    McLean, VA
    1 day ago
  • $152k - $261k

     ...candidate will be passionate around security and will love to dive deep in order to understand and exploit a potential security vulnerability. If you love finding security weaknesses and use those findings to bypass technical security controls, we would love to hear from... 
    Full time
    Temporary work
    Work experience placement
    Work at office
    Flexible hours

    Coupang

    Washington DC
    2 days ago
  •  ...penetration testing supporting PCI-DSS. ~ Technical writing skills, along with ease in communicating concepts related to security vulnerabilities and attack path scenarios. ~ Familiar with OWASP Application Security Verification Standard ( ASVS ) and MITRE ATT&CK... 
    Local area
    Remote work

    Akaasa Technologies

    Falls Church, VA
    1 day ago
  •  ...our sustained growth driven by our people-first approach and unwavering dedication to excellence. This candidate will execute vulnerability identification, scanning, analysis, and coordination to reduce system attack. Maintain disciplined vulnerability workflows from... 
    Work at office

    True Zero Technologies

    Washington DC
    16 days ago
  • $146k - $234k

    ResponsibilitiesJob Description:Peraton is seeking an Sr Information Systems Security Officer to support our Federal Strategic Cyber programs.Location: Washington, DC In this role, you will:Apply best practices for cybersecurity program standards, processes, procedures,...
    Contract work
    Work experience placement
    Shift work

    Peraton Corporation

    Washington DC
    4 days ago
  • $115k - $203k

     ...facing processes, infrastructure, and applications. This position will be tasked with developing test plans to validate identified vulnerabilities and demonstrate the exploitation of the vulnerabilities. The ability to explain the exploit to senior level management is key... 
    Hourly pay
    Full time
    Work at office
    Work from home
    Monday to Thursday

    CoStar Realty Information, Inc.

    Arlington, VA
    15 hours ago
  • $155.36k - $264.13k

     ...Lead and perform advanced security assessments, including hands-on penetration testing of systems and applications. Identify vulnerabilities, evaluate risk, and provide clear, actionable remediation recommendations. Develop and maintain assessment plans aligned... 
    3 days per week

    Jobleads-US

    Washington DC
    4 days ago
  •  ...ResponsibilitiesLead and perform advanced security assessments, including hands-on penetration testing of systems and applications.Identify vulnerabilities, assess risks, and deliver clear, actionable remediation recommendations.Develop and maintain assessment plans aligned withNIST... 
    3 days per week

    ASRC Federal Holding Company

    Washington DC
    1 day ago
  • $86.8k - $198k

     ...the team. Join us. The world can’t wait.You Have:2+ years of experience with penetration testing and red teaming Experience with vulnerability enumeration and exploitation frameworks, including Burp Suite Pro, Metasploit, Cobalt Strike, Armitage, or PowerSploit Knowledge... 
    Full time
    Contract work
    Part time
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    3 days ago
  •  ...innovation and dedication, our mission is to secure our clients' digital landscapes. Our services include Federal Security & Compliance, Vulnerability Management, Continuous Monitoring, Advanced Security Analytics, and Cloud Security, among others. Join our team and contribute... 
    Full time
    Work experience placement
    Remote work
    Monday to Friday
    Shift work
    Night shift

    Quzara LLC

    Washington DC
    1 day ago
  •  ...Information Technology (TSA IT) Task Order (TO) by performing security attacks against all types of IT assets, and exploiting vulnerabilities found to determine if further reach within the engagement scope can be obtained. Provide final reports and presentations of the... 
    Full time
    For contractors

    gTANGIBLE Corporation

    Arlington, VA
    more than 2 months ago
  • $178.4k - $226.7k

     ...identifying security issues and risks, and developing mitigation plans- Experience (non-internship) in industry-based security vulnerabilities identification, attack patterns, and remediation techniques- Experience as a mentor, tech lead or leading an engineering team-... 
    Internship
    Flexible hours

    Amazon

    Arlington, VA
    4 days ago
  •  ..., developing, and deploying large-scale distributed systems at scale.Extensive experience identifying, evaluating and triaging vulnerabilities with Static/Dynamic Application Security Testing (SAST/DAST) methodologies and tools.Proven experience conducting code reviews,... 
    Temporary work
    Work at office
    Remote work
    Work from home
    Flexible hours

    Aledade

    Washington DC
    2 days ago
  • $136k - $184k

     ...modelling exercises.- Penetration Testing: Coordinate penetration testing to validate security controls and identify exploitable vulnerabilities.- Finding Management: Document, track, and communicate security findings to service teams with clear remediation guidance, and... 
    Internship
    Flexible hours

    Amazon

    Arlington, VA
    4 days ago
  • $136k - $184k

     ...non-internship) experience- Bachelor's degree in Engineering, Computer Science, or a related field- Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits or equivalent- Experience with web... 
    Internship
    Flexible hours
    Shift work

    Amazon

    Arlington, VA
    4 days ago
  • Dexis is a dynamic professional services firm dedicated to partnering with government and community leaders both in the U.S. and internationally to achieve critical social outcomes in a rapidly changing world.At Dexis, you will experience a corporate culture of inclusiveness...
    Contract work
    Work at office

    Dexis Consulting Group

    Washington DC
    1 day ago
  • $178.4k - $226.7k

    AHAS reduces the risk of human and operator access to AWS production systems and customer environments. As the Senior Security Engineer embedded with an AHAS software development team, you own the security design decisions for the operator-access tooling this team builds...
    Internship
    Remote work
    Flexible hours

    Amazon

    Arlington, VA
    6 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Vulnerability Analyst. Be the first to apply!