Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

VULNERABILITY MGMT ANALYST

Arete Associates

Job Description

Job Description

Areté is looking for the person who makes sure vulnerabilities actually get closed — not just found. As our Vulnerability Management Analyst in Falls Church, VA, you will own the end-to-end remediation cycle — scanning, prioritization, patch qualification, deployment, and verification — across desktops, servers, network devices, and standalone systems on multiple sites and networks, working closely with Areté's Cyber Security staff.

This is a hands-on execution role, and you will be measured on whether vulnerabilities close on a recurring, risk-prioritized cadence. Equally important is doing so without breaking the business: qualifying patches before they are pushed, understanding which applications depend on pinned or vendor-locked component versions, coordinating maintenance windows with system owners, and having a tested rollback path when a patch goes wrong.

The selected candidate must hold an active Top Secret clearance and be able to maintain it. This position is onsite at our Falls Church, VA facility. The candidate may be required to travel occasionally and provide some afterhours support. This is an exempt non-supervisory full-time position.

Primary Responsibilities:

•    Conduct regular vulnerability assessments and serve as the technical expert with primary responsibility for vulnerability scanning and remediation of desktops, servers, network devices, and other systems across multiple sites, networks, and standalone environments.

•    Analyze scan results from Rapid7 and Tenable Security Center (ACAS) and produce a risk-prioritized remediation plan that accounts for severity, exploitability, exposure, asset criticality, and known-exploited-vulnerability status — not raw CVSS alone.

•    Execute continuous, recurring patching schedules against that prioritization, within maintenance windows authorized by the appropriate change control board.

•    Qualify patches before deployment: test in a representative environment, identify dependencies on pinned or vendor-supported component versions, assess impact to line-of-business and server applications, and document a rollback plan.

•    Identify vulnerabilities that cannot be resolved by patching alone — pinned application dependencies, end-of-life software, vendor-locked systems — and develop compensating controls, mitigation strategies, or upgrade recommendations in coordination with system owners and Cyber Security.

•    Coordinate with system owners and end users on upcoming patches and projected impacts, including reboots, service interruptions, and network-wide effects.

•    Verify remediation through rescanning and closure validation; track exceptions, deviations, and accepted risks through to resolution or formal acceptance.

•    Automate recurring scanning, patching, reporting, and remediation workflows to reduce manual effort and improve consistency.

•    Maintain vulnerability management processes and standard operating procedures, and maintain and report metrics for the function — remediation timeliness, aging, coverage, patch success and failure rates, and recurring problem areas.

•    Prepare and present reports on vulnerability management activities to IT and senior management, communicating complex technical information to non-technical stakeholders.

•    Stay current on emerging threats, actively exploited vulnerabilities, and vendor advisories, and recommend proactive measures.

•    Other duties, as assigned.

Experiences and Background We Look For:

•    Active Top Secret clearance, with the ability to maintain it.

•    Must have or be able to obtain a CompTIA Security+ CE certification within 120 days of employment, in accordance with DoDM 8140.03 and DFARS View phone number on ziprecruiter.com.

•    Minimum of 3 years working as a System Administrator, Systems Engineer, Network Administrator, Vulnerability Analyst, or similar role.

•    Proficient understanding of computer hardware, software, and operating systems — primarily Microsoft Windows Server and Red Hat Enterprise Linux — with strong system troubleshooting skills across both.

•    Working knowledge of vulnerability scanning products such as Rapid7 (preferred), Tenable Security Center/Nessus (ACAS), or Qualys.

•    Experience with patch management tools such as PDQ Deploy, SCCM/MECM, WSUS, YUM/DNF, or Red Hat Satellite — including testing and qualifying patches prior to deployment, coordinating change-managed maintenance windows, and executing rollback when required.

•    Working scripting ability in PowerShell, Bash, or Python sufficient to automate recurring scan parsing, patch orchestration, and reporting tasks.

•    Strong interpersonal and written communication skills, with the ability to work autonomously, produce technical documentation, and negotiate remediation timelines with system owners who have competing priorities.

Nice to Have:

•    TS/SCI access with polygraph.

•    Advanced automation experience building patch orchestration or vulnerability reporting tooling.

•    Experience patching and maintaining airgapped, standalone, or classified systems, including offline content management and update ingestion.

•    Familiarity with DISA STIGs, SCAP Compliance Checker, and DoD or federal compliance frameworks (NIST 800-53, NIST 800-171, RMF).

•    Experience with container and application dependency scanning, and with SBOM-based vulnerability identification.

•    Experience managing vulnerabilities in third-party and line-of-business applications where a vendor pins supported runtime or library versions.

•    Industry certifications such as CySA+, Network+, CCNA, RHCSA, Microsoft AZ-800/801 or MD-102, GIAC GCED/GEVA, or vendor certifications in Rapid7 or Tenable/ACAS.

•    Bachelor's Degree in an Information Technology related discipline.

We have an impressive range of benefits, programs, and perks that we offer:

Generous PTO and Leave Times

•    Flextime Scheduling

•    Bereavement

•    Paid Time Off (PTO)

•    Paid Parental Leave

Financial Benefits

•    Company-funded 5% contribution to your 401(k) retirement plan

•    Company-funded 5% contribution to your Employee Stock Ownership Plan

•    Continuing Education Assistance

Health, Medical, and Wellness Benefits

•    Medical Insurance

•    Dental & Vision Insurance

•    Life Insurance and Long-Term Disability (LTD)

•    Vision Reimbursement

Vacancy posted 10 days ago
Similar jobs that could be interesting for youBased on the VULNERABILITY MGMT ANALYST in Falls Church, VA vacancy
  •  ...Job Description Job Description Areté is looking for the person who makes sure vulnerabilities actually get closed — not just found. As our Vulnerability Management Analyst in Falls Church, VA, you will own the end-to-end remediation cycle — scanning, prioritization... 
    Suggested
    Full time

    Arete Associates

    Falls Church, VA
    a month ago
  • $69.55k - $125.73k

    We are currently seeking a Vulnerability Analyst to join the Compartmented Enterprise Services Office (CESO) effort. This program is establishing a modern secure web service (SWS) operation as part of a state-of-the-art, highly automated platform capable of supporting a... 
    Suggested
    Work at office
    Local area
    Immediate start

    Careerwebsite

    Arlington, VA
    2 days ago
  •  ...supporting a U.S. Government customer to provide cybersecurity vulnerability analysis support to reduce the prevalence and impact of...  ...Infrastructure Key Resources (CIKR). The Cybersecurity Vulnerability Analyst utilizes cybersecurity best practices, risk management... 
    Suggested

    Node.Digital LLC

    Arlington, VA
    3 days ago
  • $86.8k - $198k

    Penetration TesterThe Opportunity:Conduct testing and analysis to identify vulnerabilities and potential threat vectors in systems and networks, develop exploits, and engineer attack methodologies. Apply advanced advising skills, extensive technical expertise, and full... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Herndon, VA
    13 hours ago
  •  ...MANTECH seeks a motivated, career and customer-oriented Cyber Network Threat Analyst to join our team in Springfield, VA .   The Counterintelligence Threat Technical Analyst will leverage their strong technical background and knowledge to support the Sponsor... 
    Suggested
    Work at office

    MANTECH

    Springfield, VA
    11 hours ago
  • Driven by Innovation and built on Trust, rockITdata is a unique SDVOSB services company that partners with leading commercial healthcare/life sciences organizations on cutting edge innovations - think AI, automation and data transformation. We then bring those commercially...
    Full time

    rockITdata

    Arlington, VA
    11 days ago
  • $110k - $160k

     ...curated analytics tools, actively identifying and exploiting vulnerabilities to validate and strengthen the platform’s security posture against...  ...Penetration Testing Engineer (CPTE)CompTIA CyberSecurity Analyst (CySA+)Federal IT Security Professional-Auditor (FITSP-A)GIAC... 
    Full time
    Work at office

    Praescient Analytics

    Arlington, VA
    3 days ago
  •  ...(no c2c) Great opportunity with top-tier financial institution! We are currently seeking a Software Test Analyst/QA Analyst with 2–5 years of professional, hands-on QA/testing experience, in banking or financial services, with demonstrated experience... 
    Contract work
    Temporary work
    Local area
    3 days per week

    System One

    Merrifield, VA
    a month ago
  • $86.8k - $198k

     ...the team. Join us. The world can’t wait.You Have:2+ years of experience with penetration testing and red teaming Experience with vulnerability enumeration and exploitation frameworks, including Burp Suite Pro, Metasploit, Cobalt Strike, Armitage, or PowerSploit Knowledge... 
    Full time
    Contract work
    Part time
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    3 days ago
  •  ...facing processes, infrastructure, and applications. This position will be tasked with developing test plans to validate identified vulnerabilities and demonstrate the exploitation of the vulnerabilities. The ability to explain the exploit to senior level management is key... 
    Work at office
    Work from home
    Monday to Thursday

    Visual Lease Services Inc

    Arlington, VA
    14 hours ago
  •  ...privilege escalation and lateral movement Examine results of web/OS scanners, scans and static source code analysis Identify vulnerabilities, misconfigurations, and compliance issues Write final reports, defend all findings to include the risk or vulnerability,... 

    Jobleads-US

    McLean, VA
    1 day ago
  • $127.05k - $180k

    Requisition Number: 30466 Required Travel: 0 - 10%Employment Type: Full Time/Salaried/ExemptAnticipated Salary Range: $127,045.00 - $180,000.00 Security Clearance: Ability to Obtain Level of Experience: Senior Meet HII’s Mission Technologies DivisionOur team of more than...
    Full time
    Work experience placement
    Work at office
    Local area
    Worldwide

    HII Mission Technologies Division

    Fairfax, VA
    1 day ago
  •  ...penetration testing supporting PCI-DSS. ~ Technical writing skills, along with ease in communicating concepts related to security vulnerabilities and attack path scenarios. ~ Familiar with OWASP Application Security Verification Standard ( ASVS ) and MITRE ATT&CK... 
    Local area
    Remote work

    Akaasa Technologies

    Falls Church, VA
    2 days ago
  • Company Description KRG Technologies Inc. Job Description Job Title: Network and security Admin Location: Herndon, Virginia Duration: CONTRACT(6-12months) Job Description: ~ Minimum 5 years of hands-on skills on one or more of the following...
    Full time
    Contract work
    Work at office

    krg technology

    Herndon, VA
    more than 2 months ago
  •  ...Information Technology (TSA IT) Task Order (TO) by performing security attacks against all types of IT assets, and exploiting vulnerabilities found to determine if further reach within the engagement scope can be obtained. Provide final reports and presentations of the... 
    Full time
    For contractors

    gTANGIBLE Corporation

    Arlington, VA
    more than 2 months ago
  • $94k - $112k

     ...documentation to include SSP, Contingency, Incident & Configuration Mgmt planning and execution  ~ Experience working on multiple...  ...network scanning software (Nessus, Security Center, Tenable Vulnerability Management, nmap, Wiz, burp)  ~ Experience with Endpoint... 
    Full time
    Temporary work
    Work at office
    Immediate start
    Shift work
    Night shift

    Solutions³ LLC

    Arlington, VA
    10 days ago
  • $500 per month

    Become a Professional Game Tester We're looking for passionate gamers to join our elite team of mobile game testers. Get paid to play and test the latest games before they launch. $500+ Avg Monthly Pay 5-10 Hours/Week 100% Remote Position Requirements: ...
    Remote work
    10 hours per week

    Babki

    Arlington, VA
    2 days ago
  • $140k - $190k

    Job Description Job Description About Agile Defense At Agile Defense we know that action defines the outcome and new challenges require new solutions. That’s why we always look to the future and embrace change with an unmovable spirit and the courage to build for...
    Temporary work
    Immediate start
    Remote work
    Relocation package
    Day shift

    Agile Defense

    Reston, VA
    a month ago
  •  ...Cyber Network Defense Analyst II page is loaded## Cyber Network Defense Analyst IIlocations: Arlington, VAtime type: Full timeposted...  ...include cyber space operations, cyber defense and resiliency, vulnerability research, ubiquitous technical surveillance, data intelligence... 
    Contract work
    Immediate start

    Nightwing Group

    Arlington, VA
    4 days ago
  • $197.3k - $225.1k

     ..., MITRE ATTCK, CMMC, FedRAMP, etc. ~5+ years of experience performing analysis of or developing solutions for cyber threats, vulnerabilities, risks, or, events ~5+ years of experience working on teams and presenting to stakeholders cybersecurity information such as... 
    Full time
    Part time
    H1b
    Local area

    ITSMF

    McLean, VA
    1 day ago
  • $136k - $184k

     ...non-internship) experience- Bachelor's degree in Engineering, Computer Science, or a related field- Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits or equivalent- Experience with web... 
    Internship
    Flexible hours

    Amazon

    Arlington, VA
    13 hours ago
  • General Dynamics Information Technology, Inc. is seeking a Penetration Tester to join our Cyber Security team at the McLean, VA client site. You will perform internal and external evaluations of networks, applications, databases, and cloud services, and articulate clear...

    Jobleads-US

    McLean, VA
    1 day ago
  • $97.3k - $119.1k

     ...missions and the government forward! Job Description: Accenture Federal Services is seeking a Software System Tester/Business Analyst to help our federal clients tackle their toughest challenges while unleashing their fullest potential…and then some. What makes our... 
    Full time
    Live in
    Work at office
    Local area
    Sleeping nights
    Night shift

    Accenture Federal Services

    Springfield, VA
    3 days ago
  •  ...Job Description Job Description Cyber Network Defense Analyst (CNDA) - Cloud Forensics Location: Remote / Onsite (as required) Clearance: Active TS/SCI (DHS EOD eligibility required) Company: Argo Cyber Systems, LLC - A Service-Disabled Veteran-Owned Small... 
    Remote work

    Argo Cyber Systems

    Arlington, VA
    3 days ago
  •  ...digital forensics/incident response (DFIR) and proactively hunting for malicious cyber activity. They are seeking Cyber Network Defense Analysts (CNDA) to support this critical customer mission. Responsibilities Assistthe Government lead in coordinating teams in preliminary... 
    Immediate start
    Remote work

    NewGen Technologies (Maryland)

    Arlington, VA
    4 days ago
  • Cyber Network Forensic Analyst III, TS/SCI Raytheon Technologies provides remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution using host-based, network-based and cloud-based cybersecurity... 
    Immediate start
    Remote work

    Raytheon Technologies

    Arlington, VA
    4 days ago
  •  ...Government agencies and critical infrastructure owners who experience cyber-attacks. Solutions³ LLC is seeking a Cyber Network Defense Analysts (CNDA) to support this critical mission by providing front line response for digital forensics/incident response (DFIR) and... 
    For contractors

    Solutions3

    Arlington, VA
    4 days ago
  • Solutions³ LLC is seeking a Cyber Network Defense Analyst II to support a government mission, performing investigations to assess breach severity and develop mitigation plans. The role requires US citizenship, active TS/SCI clearance, and DHS suitability prior to start,... 

    Solutions3

    Arlington, VA
    4 days ago
  • $82.6k - $162.8k

    Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions...
    Local area
    Visa sponsorship

    Deloitte

    Rosslyn, VA
    11 hours ago
  • $105.4k - $207.8k

    Position Summary Cyber Palo Alto Networks Security Engineer/ Senior Consultant, Strategy, Growth, and TransformationDeloitte’s Cyber business is passionate about making an impact with lasting change. Delivering our industry leading services requires fresh thinking...
    Work experience placement
    Local area
    Remote work

    Deloitte

    McLean, VA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to VULNERABILITY MGMT ANALYST. Be the first to apply!