Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

VULNERABILITY MGMT ANALYST

Arete Associates

Job Description

Job Description

Areté is looking for the person who makes sure vulnerabilities actually get closed — not just found. As our Vulnerability Management Analyst in Falls Church, VA, you will own the end-to-end remediation cycle — scanning, prioritization, patch qualification, deployment, and verification — across desktops, servers, network devices, and standalone systems on multiple sites and networks, working closely with Areté's Cyber Security staff.

This is a hands-on execution role, and you will be measured on whether vulnerabilities close on a recurring, risk-prioritized cadence. Equally important is doing so without breaking the business: qualifying patches before they are pushed, understanding which applications depend on pinned or vendor-locked component versions, coordinating maintenance windows with system owners, and having a tested rollback path when a patch goes wrong.

The selected candidate must hold an active Top Secret clearance and be able to maintain it. This position is onsite at our Falls Church, VA facility. The candidate may be required to travel occasionally and provide some afterhours support. This is an exempt non-supervisory full-time position.

Primary Responsibilities:

•    Conduct regular vulnerability assessments and serve as the technical expert with primary responsibility for vulnerability scanning and remediation of desktops, servers, network devices, and other systems across multiple sites, networks, and standalone environments.

•    Analyze scan results from Rapid7 and Tenable Security Center (ACAS) and produce a risk-prioritized remediation plan that accounts for severity, exploitability, exposure, asset criticality, and known-exploited-vulnerability status — not raw CVSS alone.

•    Execute continuous, recurring patching schedules against that prioritization, within maintenance windows authorized by the appropriate change control board.

•    Qualify patches before deployment: test in a representative environment, identify dependencies on pinned or vendor-supported component versions, assess impact to line-of-business and server applications, and document a rollback plan.

•    Identify vulnerabilities that cannot be resolved by patching alone — pinned application dependencies, end-of-life software, vendor-locked systems — and develop compensating controls, mitigation strategies, or upgrade recommendations in coordination with system owners and Cyber Security.

•    Coordinate with system owners and end users on upcoming patches and projected impacts, including reboots, service interruptions, and network-wide effects.

•    Verify remediation through rescanning and closure validation; track exceptions, deviations, and accepted risks through to resolution or formal acceptance.

•    Automate recurring scanning, patching, reporting, and remediation workflows to reduce manual effort and improve consistency.

•    Maintain vulnerability management processes and standard operating procedures, and maintain and report metrics for the function — remediation timeliness, aging, coverage, patch success and failure rates, and recurring problem areas.

•    Prepare and present reports on vulnerability management activities to IT and senior management, communicating complex technical information to non-technical stakeholders.

•    Stay current on emerging threats, actively exploited vulnerabilities, and vendor advisories, and recommend proactive measures.

•    Other duties, as assigned.

Experiences and Background We Look For:

•    Active Top Secret clearance, with the ability to maintain it.

•    Must have or be able to obtain a CompTIA Security+ CE certification within 120 days of employment, in accordance with DoDM 8140.03 and DFARS View phone number on ziprecruiter.com.

•    Minimum of 3 years working as a System Administrator, Systems Engineer, Network Administrator, Vulnerability Analyst, or similar role.

•    Proficient understanding of computer hardware, software, and operating systems — primarily Microsoft Windows Server and Red Hat Enterprise Linux — with strong system troubleshooting skills across both.

•    Working knowledge of vulnerability scanning products such as Rapid7 (preferred), Tenable Security Center/Nessus (ACAS), or Qualys.

•    Experience with patch management tools such as PDQ Deploy, SCCM/MECM, WSUS, YUM/DNF, or Red Hat Satellite — including testing and qualifying patches prior to deployment, coordinating change-managed maintenance windows, and executing rollback when required.

•    Working scripting ability in PowerShell, Bash, or Python sufficient to automate recurring scan parsing, patch orchestration, and reporting tasks.

•    Strong interpersonal and written communication skills, with the ability to work autonomously, produce technical documentation, and negotiate remediation timelines with system owners who have competing priorities.

Nice to Have:

•    TS/SCI access with polygraph.

•    Advanced automation experience building patch orchestration or vulnerability reporting tooling.

•    Experience patching and maintaining airgapped, standalone, or classified systems, including offline content management and update ingestion.

•    Familiarity with DISA STIGs, SCAP Compliance Checker, and DoD or federal compliance frameworks (NIST 800-53, NIST 800-171, RMF).

•    Experience with container and application dependency scanning, and with SBOM-based vulnerability identification.

•    Experience managing vulnerabilities in third-party and line-of-business applications where a vendor pins supported runtime or library versions.

•    Industry certifications such as CySA+, Network+, CCNA, RHCSA, Microsoft AZ-800/801 or MD-102, GIAC GCED/GEVA, or vendor certifications in Rapid7 or Tenable/ACAS.

•    Bachelor's Degree in an Information Technology related discipline.

We have an impressive range of benefits, programs, and perks that we offer:

Generous PTO and Leave Times

•    Flextime Scheduling

•    Bereavement

•    Paid Time Off (PTO)

•    Paid Parental Leave

Financial Benefits

•    Company-funded 5% contribution to your 401(k) retirement plan

•    Company-funded 5% contribution to your Employee Stock Ownership Plan

•    Continuing Education Assistance

Health, Medical, and Wellness Benefits

•    Medical Insurance

•    Dental & Vision Insurance

•    Life Insurance and Long-Term Disability (LTD)

•    Vision Reimbursement

Vacancy posted 9 days ago
Similar jobs that could be interesting for youBased on the VULNERABILITY MGMT ANALYST in Falls Church, VA vacancy
  • $86.8k - $198k

    Enterprise Cybersecurity Vulnerability Analyst, SeniorThe Opportunity:Support Booz Allen Hamilton's internal Enterprise Cybersecurity team by utilizing enterprise-level vulnerability scanning and assessment tools to identify internally and externally facing vulnerabilities... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    4 days ago
  •  ...through innovative solutions and an engaging culture.  Description of Task to be Performed: AnaVation is seeking a Cyber Vulnerability Analyst to join our team and support our mission critical customer in Reston, VA or Colorado Springs, CO. In this role you will... 
    Suggested
    Full time
    Temporary work
    Immediate start

    AnaVation

    Reston, VA
    8 days ago
  • Cybersecurity Vulnerability Analyst (Incident Manager III) Description Supporting our prime contractor and their U.S. Government customer to provide cybersecurity vulnerability analysis support to reduce the prevalence and impact of vulnerabilities and exploitable conditions... 
    Suggested
    For contractors

    kozmetickesluzby.vecnakraska.sk - Jobboard

    Arlington, VA
    1 day ago
  • A leading cybersecurity consultancy is seeking a Cybersecurity Vulnerability Analyst based in Arlington, VA. The role requires an active Top Secret Security Clearance and 5+ years of experience, focusing on vulnerability analysis for federal clients. Candidates must exhibit... 
    Suggested

    Node.Digital LLC

    Arlington, VA
    2 days ago
  •  ...supporting a U.S. Government customer to provide cybersecurity vulnerability analysis support to reduce the prevalence and impact of...  ...Infrastructure Key Resources (CIKR). The Cybersecurity Vulnerability Analyst utilizes cybersecurity best practices, risk management... 
    Suggested

    Node.Digital LLC

    Arlington, VA
    2 days ago
  • NTT DATA seeks a Cybersecurity and Risk Analyst to join the VAPT team, identifying and mitigating cybersecurity risks across enterprise systems, networks, and applications. You will perform vulnerability assessments, risk evaluations, and threat simulations aligned with... 

    NTT DATA North America

    Arlington, VA
    15 hours ago
  • Njvc LLC is looking for a Cybersecurity Analyst (Vulnerability Management & Continuous Monitoring) in Oakton, VA. This role supports DoD cybersecurity operations, focusing on vulnerability management and compliance activities. Candidates must have 5+ years of experience... 

    Njvc LLC

    Oakton, VA
    4 days ago
  • $86.8k - $198k

    Penetration TesterThe Opportunity:Conduct testing and analysis to identify vulnerabilities and potential threat vectors in systems and networks, develop exploits, and engineer attack methodologies. Apply advanced advising skills, extensive technical expertise, and full... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Herndon, VA
    4 days ago
  • $86k - $138k

     ...will: Support the Red Cell Team by performing and leading penetration tests to assess the security of customer systems.Identify vulnerabilities and develop recommended remediations to satisfy mandated NIST 800-53 security controls.Report and demonstrate findings to... 
    Contract work
    Flexible hours
    Shift work

    Peraton Corporation

    Arlington, VA
    15 hours ago
  • $90k - $130k

     ...curated analytics tools, actively identifying and exploiting vulnerabilities to validate and strengthen the platform’s security posture against...  ...Penetration Testing Engineer (CPTE)CompTIA CyberSecurity Analyst (CySA+)Federal IT Security Professional-Auditor (FITSP-A)GIAC... 
    Full time
    Work at office

    Praescient Analytics

    Arlington, VA
    3 days ago
  •  ...Vulnerability Management Analyst ID 2025-3164 Job Locations US Category Information Technology Type Regular Full-Time Overview DecisionPoint seeks a Vulnerability Management Analyst to support enterprise cybersecurity... 
    Full time
    Contract work
    For contractors
    Local area
    Remote work

    Decision Point

    Reston, VA
    15 hours ago
  • $90k - $155k

     ...another tech company. We're a community of innovators, engineers, analysts and business professionals working together with our...  ...professionals to join our team. ABSC is seeking a Vulnerability Management Analyst to join our team supporting the Air Force... 
    Contract work
    Remote work
    Flexible hours

    Absolute Business Solutions Corp

    Arlington, VA
    4 days ago
  •  ...requirements, and internal policy standards • Assist in governance activities, risk assessments, and reporting processes • Maintain vulnerability management standard, procedures, and guidelines • Identify vulnerabilities requiring risk escalation and exception review •... 
    Full time
    Temporary work
    Relocation

    Infosys

    Reston, VA
    1 day ago
  • Absolute Business Solutions Corp (ABSC) seeks a Vulnerability Management Analyst to strengthen Air Force networks in the AFNCR ITS2 program. On-site work in the National Capital Region with some remote tasks possible with client approval. You will support vulnerability... 
    Remote work

    absc-us

    Arlington, VA
    2 days ago
  • DescriptionSAIC is seeking a highly skilled Senior Vulnerability Analyst with a strong technical background to join our team in support of a critical US government agency in the National Capital Region. This is an exciting opportunity to work with a team responsible for... 
    2 days per week

    Science Applications International Corporation

    Washington DC
    15 hours ago
  •  ...business systems. The successful candidate will partner closely with business stakeholders, developers, project managers, business analysts, vendors, and subject matter experts to validate system functionality, ensure data integrity, and support successful software... 

    Navy Mutual

    Arlington, VA
    15 hours ago
  •  ...join our cybersecurity team. In this role, you will identify vulnerabilities and test the security of networks, applications, and systems...  ...SIMILAR CAREER TITLES Ethical Hacker, Vulnerability Analyst, Security Consultant, Red Team Specialist, Cybersecurity Analyst... 
    Temporary work
    For contractors
    Immediate start
    Flexible hours

    Cymertek

    Reston, VA
    2 days ago
  •  ...Familiarity with emerging threats and attack vectors in cloud and containerized environments Experience with automated vulnerability scanning and exploitation platforms Knowledge of security frameworks and regulations relevant to commercial companies Track... 

    Altus Consulting Corp

    Herndon, VA
    4 days ago
  •  ...join our cybersecurity team. In this role, you will identify vulnerabilities and test the security of networks, applications, and systems...  ...consulting services in information technology, cybersecurity, and analyst workforce development. At our company, you come first. We'... 
    Temporary work
    For contractors
    Immediate start
    Flexible hours

    Cymertek

    McLean, VA
    4 days ago
  • Overview: Job Title: Penetration Tester Location: Reston, VA Work Mode - Hybrid role, 2 days' Work from Office (Wednesday and Thursday) Must have Skill Set - Red team pentester Job Description: Network penetration testing and experience working with...
    Work at office

    Orison

    Reston, VA
    2 days ago
  • Absolute Business Solutions Corp (ABSC) is recruiting a Vulnerability Management Analyst to strengthen cybersecurity for the AFNCR ITS2 program, supporting the Pentagon, JB Andrews, and JBAB. The role emphasizes vulnerability detection, remediation, and compliance across... 
    Remote job

    Absolute Business Solutions Corp

    Arlington, VA
    1 day ago
  • $106.3k - $221.1k

     ...Penetration Tester will conduct comprehensive penetration tests on applications, networks, and systems. Identify and exploit security vulnerabilities to assess risk, developing detailed reports on findings, and providing recommendations for remediation. Collaborate with other... 
    Live in
    Work at office
    Local area

    Accenture

    Arlington, VA
    15 hours ago
  • $115k - $203k

     ...facing processes, infrastructure, and applications. This position will be tasked with developing test plans to validate identified vulnerabilities and demonstrate the exploitation of the vulnerabilities. The ability to explain the exploit to senior level management is key... 
    Hourly pay
    Full time
    Work at office
    Work from home
    Monday to Thursday

    CoStar Realty Information, Inc.

    Arlington, VA
    1 day ago
  •  ...Senior Vulnerability Analyst This position supports the Information Risk Strategy Management (IRSM) Vulnerability Management (VM) program reporting to the Vulnerability Management Team Lead. Responsibilities include managing the vulnerability remediation process to... 

    Software Technology Inc

    Washington DC
    4 days ago
  • blueStone is seeking a Cyber Security Operations Analyst in Alexandria, Virginia, to support operations for a major government client...  ...in data security administration and a strong skill set in vulnerability scanning, operating systems, and security tools. This opportunity... 

    Bluestone.com

    Alexandria, VA
    15 hours ago
  •  ...security testing and auditing methods. This senior level cyber TE analysts engage with senior leadership to identify, report, and...  ...Strong logical/critical thinking abilities, especially analyzing vulnerability information and current adversarial TTPs and IOCs. Strong... 
    For contractors
    Work at office

    Agile Defense

    Springfield, VA
    6 days ago
  •  ...Specialist to join our cybersecurity team. This role involves performing detailed security assessments, penetration tests, and vulnerability analyses to protect critical systems and data. The ideal candidate is hands-on, highly technical, and experienced in identifying... 
    Flexible hours

    Falls Technology

    McLean, VA
    8 days ago
  •  ...Information Technology (TSA IT) Task Order (TO) by performing security attacks against all types of IT assets, and exploiting vulnerabilities found to determine if further reach within the engagement scope can be obtained. Provide final reports and presentations of the... 
    Full time
    For contractors

    gTANGIBLE Corporation

    Arlington, VA
    more than 2 months ago
  • $140k - $190k

    Job Description Job Description About Agile Defense At Agile Defense we know that action defines the outcome and new challenges require new solutions. That’s why we always look to the future and embrace change with an unmovable spirit and the courage to build for...
    Temporary work
    Immediate start
    Remote work
    Relocation package
    Day shift

    Agile Defense

    Reston, VA
    5 days ago
  •  ...documentation to include SSP, Contingency, Incident & Configuration Mgmt planning and execution·Experience working on multiple complex...  ...network scanning software (Nessus, Security Center, Tenable Vulnerability Management, nmap, Wiz, burp)·Experience with Endpoint... 
    Temporary work
    For contractors
    Work at office
    Local area

    Argo Cyber Systems

    Arlington, VA
    8 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to VULNERABILITY MGMT ANALYST. Be the first to apply!