Vulnerability Analyst II
cFocus Software
Vulnerability Analyst II
Position Title: Vulnerability Analyst II Program: SBA Enterprise Cybersecurity Services (ECS)
The Vulnerability Analyst II provides cybersecurity risk, vulnerability management, and compliance support services in alignment with the SBA Enterprise Cybersecurity Services (ECS) RFQ Task Area 3.5.2. The position supports the SBA Risk Management Framework (RMF), FISMA compliance initiatives, Information System Continuous Monitoring (ISCM), vulnerability management, controls assessment activities, audit support, and continuous monitoring operations across enterprise systems and cloud environments. The analyst performs vulnerability assessments, supports POA&M development, validates security controls, coordinates remediation efforts, and assists Information System Security Officers (ISSOs) and system owners with maintaining compliant and secure systems.
Essential Duties and Responsibilities
- Perform enterprise vulnerability assessments and compliance scans using SBA-approved tools such as Tenable Security Center (SC), Nessus, and Microsoft TVM.
- Review identified vulnerabilities, assess impact and risk, and provide remediation recommendations for operating systems, applications, network devices, and cloud environments.
- Support continuous monitoring and Risk Management Framework (RMF) activities in accordance with NIST SP 800-37, NIST SP 800-53 Rev. 5, and NIST SP 800-53A.
- Assist with the creation, maintenance, and review of cybersecurity documentation including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), Configuration Management Plans (CMPs), and contingency documentation.
- Support control assessments and validation activities by documenting NIST 800-53A Determine If Statements (DISs) and mapping vulnerabilities to applicable controls.
- Conduct vulnerability scanning activities every 72 hours across workstations, servers, routers, switches, and cloud-based assets in accordance with SBA requirements.
- Monitor CISA Known Exploited Vulnerabilities (KEV) listings and Binding Operational Directives (BODs) to identify and report emerging risks.
- Track zero-day vulnerabilities, coordinate remediation activities, and provide ad hoc reporting to leadership and stakeholders.
- Generate weekly vulnerability reports, dashboards, and briefing materials for ISSOs, system owners, and management.
- Assist with audit preparation and support activities involving IG, GAO, internal auditors, and external assessors.
- Maintain scanning infrastructure including scanner deployment, configuration, plugin updates, scan repositories, and vulnerability management SOPs.
- Support FedRAMP Continuous Monitoring (CONMON) activities by reviewing vulnerability reports and assessing vendor remediation activities.
- Participate in change management, security operations meetings, and enterprise cybersecurity coordination activities.
- Ensure all deliverables are complete, accurate, aligned with agency templates, and delivered within required timeframes.
Minimum Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Assurance, or related discipline. Additional years of experience may substitute for degree requirements.
- 3–6 years of experience supporting vulnerability management, cybersecurity compliance, RMF, or information assurance activities in a federal environment.
- Experience performing vulnerability assessments and remediation activities using Tenable SC/Nessus or equivalent tools.
- Knowledge of FISMA, NIST RMF, NIST SP 800-53 Rev. 5, NIST SP 800-53A, NIST SP 800-137, and related federal cybersecurity standards.
- Experience supporting POA&M management, security assessments, continuous monitoring, and audit response activities.
- Working knowledge of Windows, Linux/Unix, network infrastructure, cloud platforms, and enterprise security technologies.
- Strong written and verbal communication skills with the ability to produce technical documentation and executive-level reports.
- Ability to analyze security findings, prioritize risks, and coordinate remediation with technical stakeholders.
Preferred Certifications
- CompTIA Security+
- Certified Information Systems Security Professional (CISSP)
- Certified Ethical Hacker (CEH)
- GIAC Security Certifications (GSEC, GPEN, or similar)
- Tenable Certified Professional or equivalent vulnerability management certification
$140.5k - $210.5k
Sr. Cybersecurity Analyst II (Sr Vulnerability Analyst) - Information Technology Primary Location: DC‑Washington Employee Status: Regular Overtime Status: Exempt Job Type: Standard Relocation Provided: Yes Compensation: $140,500 - $210,500 (FR PAY GRADE 27‑28) Posting...SuggestedWork at officeRelocation- cFocus Software Incorporated is seeking a Vulnerability Analyst II in Washington, D.C. The role involves providing cybersecurity risk, vulnerability management, and compliance support, including vulnerability assessments and remediation recommendations. Candidates should...Suggested
$60k - $180k
...Penetration Tester II M9 Solutions is dedicated to providing IT services and solutions to the Federal Government by mobilizing the right people, skills, clearance levels, and technologies to help organizations who desire improved performance and modern, sustainable...SuggestedContract work- ...trusted results to enable national security missions worldwide. Job Description Overview SOSi is seeking a Risk and Vulnerability Analyst II to support vulnerability assessment and risk analysis activities in alignment with our customer. This role is responsible...SuggestedContract workWork at officeWorldwideMonday to FridayWeekend workAfternoon shift
$159.3k - $202.4k
...Description Amazon Healthcare Security's (HealthSec) AI team is hiring a Security Engineer II to secure GenAI applications and enable secure AI adoption across Amazon Health Services (AHS). You will work at the intersection of AI for Security and Security for AI—securing...SuggestedFlexible hours- ...True Zero Vulnerability Management Position True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes. True Zero recognizes...Work at office
$97.24k - $131.56k
...review of all system assessment plans. Identify cyber security vulnerabilities and assist with the implementation of the countermeasures for... ...experience (4 years) Certifications: ~ IAT Level II or IAM Level II (Security+ CE, CCNA Security, etc.) - within 6...Temporary workWork at officeImmediate startWorldwideFlexible hours$156k - $200k
...Sr. Information Systems Security Officer II Washington, DC As an Information... ...compliance standards, identifying system vulnerabilities, threat vectors, and areas of risk... ...wide range of audiences—from engineers and analysts to government leadership and non technical...Full timeWork experience placementLocal areaFlexible hours$97.24k - $118.56k
...review of all system assessment plans Identify cyber security vulnerabilities and assist with the implementation of the countermeasures for... ...8570.01-M for Information Assurance Technician Level II or Information Assurance Manager II within 6 months of the date...Hourly payContract workFor contractorsWork experience placementWork at officeLocal area$130k - $150k
...Information Systems Security Officer II (ISSO II) Washington, DC (JUS) - Washington, DC 20032 Overview Salary Range $... ...review of all system assessment plans • Identify cyber security vulnerabilities and assist with the implementation of the countermeasures for...Full timeWork at officeShift work- ...Information System Security Officer (ISSO) II Security Clearance Requirement: TS, with SCI Eligibility ***Position Requires... ...review of all system assessment plans Identify cyber security vulnerabilities and assist with the implementation of the countermeasures for...Work at office
- ...Information System Security Officer II (Req: 26-J-1801) The ISSO is responsible for ensuring the appropriate operational... ...review of all system assessment plans. Identify cyber security vulnerabilities and assist with the implementation of the countermeasures for...Work at officeImmediate startFlexible hours
- ...Description Human Resources announces an opening for a 1.0 Network Analyst GENERAL STATEMENT OF DUTIES Responsible for the... ...; makes modifications as required. NETWORK ANALYST I/II/III (Career Ladder) • Designs, configures, and implements production...For contractorsLocal area
$3,500 per month
...ARSIEM is looking for a Network Forensics Cybersecurity Analyst . This position will support one of our Government clients in Arlington... ...Desired Certifications: DoD 8140.01 IAT Level II, IASAE II, CSSP Analyst DoD 8140.01 GCIA, GCIH, CSSP Analyst/...- ...Description Systems Analyst II Role Summary Howard University Hospital is seeking a Systems Analyst II to support the implementation, optimization, and ongoing maintenance of enterprise clinical and operational systems. This role works closely with hospital...Full timeLocal area
$130k - $147k
...Title: Systems Analyst II Job Posting Description KBR's National Security Solutions team provides high-end engineering and advanced technology solutions to our customers in the intelligence and national security communities. In this position, your work will have...Temporary workLocal areaRelocation package- ...Network Based Systems Analyst - II The client provides remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution using host-based, network-based and cloud-based cybersecurity analysis...Immediate startRemote work
$138k - $170k
...Sr. Security Systems Engineer II Washington, DC As Sr. Security Systems Engineer II , you'll design and integrate enterprise security tools into a cohesive, enclave‐based architecture supporting classified and mission‐critical operations across hybrid environments...Full timeWork experience placementLocal areaFlexible hours$18k
...Internal Review Security Engineer II (Contract Contingent) ProSidian is a Management and Operations Consulting Services Firm... ...environments. Experience using network mapping software and system vulnerability scanners. Must be a Certified Information Systems Security...Contract workFor contractorsWork at officeImmediate start- ...Senior Network Security Engineer II As a Senior Network Security Engineer II you will lead the design, implementation, and... ...activity to detect, analyze, and respond to security threats and vulnerabilities. Oversee network segmentation, encryption, and secure access...Remote workFlexible hours
- ...Senior Security Engineer II For Identity And Access Management (Iam) As a Senior Security Engineer II for Identity and Access Management... ...procedures Mentoring and coaching more junior engineers or analysts Minimum Qualifications ~ BS / BTech (or higher) in...Temporary workRemote workFlexible hours
- ...Application Systems Analyst II (Contract Contingent) ProSidian is a Management and Operations Consulting Services Firm focusing on providing value to clients through tailored solutions based on industry leading practices. ProSidian services focus on the broad spectrum...Contract workWork at office
- ...include cyber space operations, cyber defense and resiliency, vulnerability research, ubiquitous technical surveillance, data intelligence... ...restoration of services. Nightwing is seeking a Cyber Network Defense Analyst to support this critical customer mission. The CDNA uses...Contract workImmediate start
- ...Cyber Threat intelligence Analyst II Location: Onsite (CONUS) / Shift Work Clearance: Active TS/SCI (DHS EOD Suitability required... ..., and responding to cyber threats to inform the customer's vulnerability management (VM) efforts. In support of the customer's...Shift work
- ...The Cyber Security Specialist II/III supports cybersecurity engineering and compliance execution in a NAVSEA Program Office Support... ...implement controls, monitor security posture, and remediate vulnerabilities across supported systems. This position is contingent upon...Work at office
- ...forensics/incident response (DFIR) and proactively hunting for malicious cyber activity. They are seeking Cyber Network Defense Analysts (CNDA) to support this critical customer mission. The CDNA uses information collected from a variety of sources to monitor...Immediate startRemote work
$130,000 - $147,000 per week
Systems Analyst II page is loaded## Systems Analyst IIlocations: Alexandria, Virginiatime type: Full timeposted on: Posted Yesterdayjob requisition id: R2122592**Title:**Systems Analyst IIJob Posting DescriptionKBR’s National Security Solutions team provides high-end engineering...Temporary workLocal areaRelocation package- A leading academic medical center located in Washington, DC is seeking a Systems Analyst II. This role involves the implementation and optimization of clinical and operational systems, requiring collaboration with various hospital departments and vendors. Candidates should...
- ...seeking an experienced Information System Security Manager (ISSM) II to oversee and manage the implementation of cybersecurity... ...RMF lifecycle) Monitor system security posture and respond to vulnerabilities, incidents, and threats Coordinate security activities...
$9k
The ISSM II's primary function serves as a principal advisor on all matters, technical and otherwise, involving the security of information... ...or corrective measures have been taken when an incident or vulnerability has been discovered within a system Ensure that data...Full timeWork at officeLocal areaImmediate startWorldwideFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vulnerability Analyst II. Be the first to apply!


