Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Vulnerability Analyst II

cFocus Software

Vulnerability Analyst II

Position Title: Vulnerability Analyst II Program: SBA Enterprise Cybersecurity Services (ECS)

The Vulnerability Analyst II provides cybersecurity risk, vulnerability management, and compliance support services in alignment with the SBA Enterprise Cybersecurity Services (ECS) RFQ Task Area 3.5.2. The position supports the SBA Risk Management Framework (RMF), FISMA compliance initiatives, Information System Continuous Monitoring (ISCM), vulnerability management, controls assessment activities, audit support, and continuous monitoring operations across enterprise systems and cloud environments. The analyst performs vulnerability assessments, supports POA&M development, validates security controls, coordinates remediation efforts, and assists Information System Security Officers (ISSOs) and system owners with maintaining compliant and secure systems.

Essential Duties and Responsibilities
  • Perform enterprise vulnerability assessments and compliance scans using SBA-approved tools such as Tenable Security Center (SC), Nessus, and Microsoft TVM.
  • Review identified vulnerabilities, assess impact and risk, and provide remediation recommendations for operating systems, applications, network devices, and cloud environments.
  • Support continuous monitoring and Risk Management Framework (RMF) activities in accordance with NIST SP 800-37, NIST SP 800-53 Rev. 5, and NIST SP 800-53A.
  • Assist with the creation, maintenance, and review of cybersecurity documentation including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), Configuration Management Plans (CMPs), and contingency documentation.
  • Support control assessments and validation activities by documenting NIST 800-53A Determine If Statements (DISs) and mapping vulnerabilities to applicable controls.
  • Conduct vulnerability scanning activities every 72 hours across workstations, servers, routers, switches, and cloud-based assets in accordance with SBA requirements.
  • Monitor CISA Known Exploited Vulnerabilities (KEV) listings and Binding Operational Directives (BODs) to identify and report emerging risks.
  • Track zero-day vulnerabilities, coordinate remediation activities, and provide ad hoc reporting to leadership and stakeholders.
  • Generate weekly vulnerability reports, dashboards, and briefing materials for ISSOs, system owners, and management.
  • Assist with audit preparation and support activities involving IG, GAO, internal auditors, and external assessors.
  • Maintain scanning infrastructure including scanner deployment, configuration, plugin updates, scan repositories, and vulnerability management SOPs.
  • Support FedRAMP Continuous Monitoring (CONMON) activities by reviewing vulnerability reports and assessing vendor remediation activities.
  • Participate in change management, security operations meetings, and enterprise cybersecurity coordination activities.
  • Ensure all deliverables are complete, accurate, aligned with agency templates, and delivered within required timeframes.
Minimum Qualifications
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Assurance, or related discipline. Additional years of experience may substitute for degree requirements.
  • 3–6 years of experience supporting vulnerability management, cybersecurity compliance, RMF, or information assurance activities in a federal environment.
  • Experience performing vulnerability assessments and remediation activities using Tenable SC/Nessus or equivalent tools.
  • Knowledge of FISMA, NIST RMF, NIST SP 800-53 Rev. 5, NIST SP 800-53A, NIST SP 800-137, and related federal cybersecurity standards.
  • Experience supporting POA&M management, security assessments, continuous monitoring, and audit response activities.
  • Working knowledge of Windows, Linux/Unix, network infrastructure, cloud platforms, and enterprise security technologies.
  • Strong written and verbal communication skills with the ability to produce technical documentation and executive-level reports.
  • Ability to analyze security findings, prioritize risks, and coordinate remediation with technical stakeholders.
Preferred Certifications
  • CompTIA Security+
  • Certified Information Systems Security Professional (CISSP)
  • Certified Ethical Hacker (CEH)
  • GIAC Security Certifications (GSEC, GPEN, or similar)
  • Tenable Certified Professional or equivalent vulnerability management certification
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Vulnerability Analyst II in Washington DC vacancy
  • $140.5k - $210.5k

    Sr. Cybersecurity Analyst II (Sr Vulnerability Analyst) - Information Technology Primary Location: DC‑Washington Employee Status: Regular Overtime Status: Exempt Job Type: Standard Relocation Provided: Yes Compensation: $140,500 - $210,500 (FR PAY GRADE 27‑28) Posting... 
    Suggested
    Work at office
    Relocation

    Federal Reserve System

    Washington DC
    3 days ago
  • cFocus Software Incorporated is seeking a Vulnerability Analyst II in Washington, D.C. The role involves providing cybersecurity risk, vulnerability management, and compliance support, including vulnerability assessments and remediation recommendations. Candidates should... 
    Suggested

    cFocus Software Incorporated

    Washington DC
    1 day ago
  • $60k - $180k

     ...Penetration Tester II M9 Solutions is dedicated to providing IT services and solutions to the Federal Government by mobilizing the right people, skills, clearance levels, and technologies to help organizations who desire improved performance and modern, sustainable... 
    Suggested
    Contract work

    M9 Solutions

    Washington DC
    6 hours ago
  •  ...trusted results to enable national security missions worldwide. Job Description Overview SOSi is seeking a Risk and Vulnerability Analyst II to support vulnerability assessment and risk analysis activities in alignment with our customer. This role is responsible... 
    Suggested
    Contract work
    Work at office
    Worldwide
    Monday to Friday
    Weekend work
    Afternoon shift

    SOSi

    Washington DC
    7 days ago
  • $159.3k - $202.4k

     ...Description Amazon Healthcare Security's (HealthSec) AI team is hiring a Security Engineer II to secure GenAI applications and enable secure AI adoption across Amazon Health Services (AHS). You will work at the intersection of AI for Security and Security for AI—securing... 
    Suggested
    Flexible hours

    Amazon

    Arlington, VA
    1 day ago
  •  ...True Zero Vulnerability Management Position True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes. True Zero recognizes... 
    Work at office

    True Zero Technologies, LLC

    Washington DC
    1 day ago
  • $97.24k - $131.56k

     ...review of all system assessment plans. Identify cyber security vulnerabilities and assist with the implementation of the countermeasures for...  ...experience (4 years) Certifications: ~ IAT Level II or IAM Level II (Security+ CE, CCNA Security, etc.) - within 6... 
    Temporary work
    Work at office
    Immediate start
    Worldwide
    Flexible hours

    General Dynamics Information Technology

    Washington DC
    4 days ago
  • $156k - $200k

     ...Sr. Information Systems Security Officer II Washington, DC As an Information...  ...compliance standards, identifying system vulnerabilities, threat vectors, and areas of risk...  ...wide range of audiences—from engineers and analysts to government leadership and non technical... 
    Full time
    Work experience placement
    Local area
    Flexible hours

    MetroStar Corporation

    Washington DC
    6 days ago
  • $97.24k - $118.56k

     ...review of all system assessment plans Identify cyber security vulnerabilities and assist with the implementation of the countermeasures for...  ...8570.01-M for Information Assurance Technician Level II or Information Assurance Manager II within 6 months of the date... 
    Hourly pay
    Contract work
    For contractors
    Work experience placement
    Work at office
    Local area

    Watermark Risk Management International, LLC

    Washington DC
    14 hours ago
  • $130k - $150k

     ...Information Systems Security Officer II (ISSO II) Washington, DC (JUS) - Washington, DC 20032 Overview Salary Range $...  ...review of all system assessment plans • Identify cyber security vulnerabilities and assist with the implementation of the countermeasures for... 
    Full time
    Work at office
    Shift work

    System High Corp

    Washington DC
    13 hours ago
  •  ...Information System Security Officer (ISSO) II Security Clearance Requirement: TS, with SCI Eligibility ***Position Requires...  ...review of all system assessment plans Identify cyber security vulnerabilities and assist with the implementation of the countermeasures for... 
    Work at office

    RedTrace Technologies

    Washington DC
    14 hours ago
  •  ...Information System Security Officer II (Req: 26-J-1801) The ISSO is responsible for ensuring the appropriate operational...  ...review of all system assessment plans. Identify cyber security vulnerabilities and assist with the implementation of the countermeasures for... 
    Work at office
    Immediate start
    Flexible hours

    Targeted Solutions Inc

    Washington DC
    6 hours ago
  •  ...Description Human Resources announces an opening for a 1.0 Network Analyst GENERAL STATEMENT OF DUTIES Responsible for the...  ...; makes modifications as required. NETWORK ANALYST I/II/III (Career Ladder) • Designs, configures, and implements production... 
    For contractors
    Local area

    Arlington Public Schools

    Arlington, VA
    4 days ago
  • $3,500 per month

     ...ARSIEM is looking for a Network Forensics Cybersecurity Analyst . This position will support one of our Government clients in Arlington...  ...Desired Certifications: DoD 8140.01 IAT Level II, IASAE II, CSSP Analyst DoD 8140.01 GCIA, GCIH, CSSP Analyst/... 

    ARSIEM Corporation

    Arlington, VA
    4 days ago
  •  ...Description Systems Analyst II Role Summary Howard University Hospital is seeking a Systems Analyst II to support the implementation, optimization, and ongoing maintenance of enterprise clinical and operational systems. This role works closely with hospital... 
    Full time
    Local area

    Howard University Hospital

    Washington DC
    3 days ago
  • $130k - $147k

     ...Title: Systems Analyst II Job Posting Description KBR's National Security Solutions team provides high-end engineering and advanced technology solutions to our customers in the intelligence and national security communities. In this position, your work will have... 
    Temporary work
    Local area
    Relocation package

    KBR

    Alexandria, VA
    2 days ago
  •  ...Network Based Systems Analyst - II The client provides remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution using host-based, network-based and cloud-based cybersecurity analysis... 
    Immediate start
    Remote work

    Beyond SOF

    Arlington, VA
    1 day ago
  • $138k - $170k

     ...Sr. Security Systems Engineer II Washington, DC As Sr. Security Systems Engineer II , you'll design and integrate enterprise security tools into a cohesive, enclave‐based architecture supporting classified and mission‐critical operations across hybrid environments... 
    Full time
    Work experience placement
    Local area
    Flexible hours

    MetroStar Corporation

    Washington DC
    3 days ago
  • $18k

     ...Internal Review Security Engineer II (Contract Contingent) ProSidian is a Management and Operations Consulting Services Firm...  ...environments. Experience using network mapping software and system vulnerability scanners. Must be a Certified Information Systems Security... 
    Contract work
    For contractors
    Work at office
    Immediate start

    ProSidian Consulting

    Arlington, VA
    1 day ago
  •  ...Senior Network Security Engineer II As a Senior Network Security Engineer II you will lead the design, implementation, and...  ...activity to detect, analyze, and respond to security threats and vulnerabilities. Oversee network segmentation, encryption, and secure access... 
    Remote work
    Flexible hours

    Aledade, Inc.

    Washington DC
    1 day ago
  •  ...Senior Security Engineer II For Identity And Access Management (Iam) As a Senior Security Engineer II for Identity and Access Management...  ...procedures Mentoring and coaching more junior engineers or analysts Minimum Qualifications ~ BS / BTech (or higher) in... 
    Temporary work
    Remote work
    Flexible hours

    Aledade, Inc.

    Bethesda, MD
    1 day ago
  •  ...Application Systems Analyst II (Contract Contingent) ProSidian is a Management and Operations Consulting Services Firm focusing on providing value to clients through tailored solutions based on industry leading practices. ProSidian services focus on the broad spectrum... 
    Contract work
    Work at office

    ProSidian Consulting

    Arlington, VA
    1 day ago
  •  ...include cyber space operations, cyber defense and resiliency, vulnerability research, ubiquitous technical surveillance, data intelligence...  ...restoration of services. Nightwing is seeking a Cyber Network Defense Analyst to support this critical customer mission. The CDNA uses... 
    Contract work
    Immediate start

    Nightwing

    Arlington, VA
    3 days ago
  •  ...Cyber Threat intelligence Analyst II Location: Onsite (CONUS) / Shift Work Clearance: Active TS/SCI (DHS EOD Suitability required...  ..., and responding to cyber threats to inform the customer's vulnerability management (VM) efforts. In support of the customer's... 
    Shift work

    Argo Cyber Systems

    Arlington, VA
    4 days ago
  •  ...The Cyber Security Specialist II/III supports cybersecurity engineering and compliance execution in a NAVSEA Program Office Support...  ...implement controls, monitor security posture, and remediate vulnerabilities across supported systems. This position is contingent upon... 
    Work at office

    Warrant Technologies LLC

    Washington DC
    4 days ago
  •  ...forensics/incident response (DFIR) and proactively hunting for malicious cyber activity. They are seeking Cyber Network Defense Analysts (CNDA) to support this critical customer mission. The CDNA uses information collected from a variety of sources to monitor... 
    Immediate start
    Remote work

    New Gen

    Arlington, VA
    1 day ago
  • $130,000 - $147,000 per week

    Systems Analyst II page is loaded## Systems Analyst IIlocations: Alexandria, Virginiatime type: Full timeposted on: Posted Yesterdayjob requisition id: R2122592**Title:**Systems Analyst IIJob Posting DescriptionKBR’s National Security Solutions team provides high-end engineering... 
    Temporary work
    Local area
    Relocation package

    KBR, Inc

    Alexandria, VA
    1 day ago
  • A leading academic medical center located in Washington, DC is seeking a Systems Analyst II. This role involves the implementation and optimization of clinical and operational systems, requiring collaboration with various hospital departments and vendors. Candidates should... 

    Page Mechanical Group, Inc.

    Washington DC
    4 days ago
  •  ...seeking an experienced  Information System Security Manager (ISSM) II to oversee and manage the implementation of cybersecurity...  ...RMF lifecycle) Monitor system security posture and respond to vulnerabilities, incidents, and threats Coordinate security activities... 

    Provato HR

    Washington DC
    20 days ago
  • $9k

    The ISSM II's primary function serves as a principal advisor on all matters, technical and otherwise, involving the security of information...  ...or corrective measures have been taken when an incident or vulnerability has been discovered within a system Ensure that data... 
    Full time
    Work at office
    Local area
    Immediate start
    Worldwide
    Flexible hours

    Modern Technology Solutions Inc

    Arlington, VA
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Vulnerability Analyst II. Be the first to apply!