DFC - Vulnerability Management Analyst
Full-time
cFocus Software Incorporated
cFocus Software seeks a Vulnerability Management Analyst to join our program supporting the United States International Defense Finance Agency (DFC). This position is remote. This position requires an Active Public Trust clearance.
Qualifications:
Qualifications:
- Active Public Trust clearance
- B.S. Computer Science, Information Technology, or a related field
- 5+ years of cybersecurity experience, including three or more years in vulnerability management, security compliance, POA&M management, or a closely related function.
- Hands-on experience analyzing authenticated scan results and validating vulnerabilities using Tenable Nessus, Qualys, Microsoft Defender, or comparable enterprise platforms.
- Demonstrated ability to assess vulnerability risk using CVSS, exploitability, CISA KEV status, asset criticality, exposure, mission impact, threat intelligence, and compensating controls.
- Experience creating and maintaining POA&M records, tracking remediation milestones, reconciling GRC and ticketing systems, validating closure evidence, and documenting false-positive determinations.
- Working knowledge of FISMA, the NIST Risk Management Framework, NIST SP 800-53 controls, NIST SP 800-40 vulnerability and patch-management principles, CISA KEV/BOD 22-01 requirements, and federal continuous-monitoring expectations.
- Ability to communicate technical risk clearly to federal cybersecurity leaders, System Owners, engineers, administrators, auditors, and nontechnical stakeholders.
- Strong analytical writing, data-quality, documentation, prioritization, and time-management skills in a deadline-driven environment.
- Active Security+, CySA+, CEH, GCVA, CISSP or other relevant security certifications preferred.
- Coordinate authenticated vulnerability scans with DFC stakeholders at frequencies aligned with policy, system criticality, exposure, threat conditions, and Government direction.
- Analyze output from Tenable, Qualys, Microsoft Defender, and other Government-approved vulnerability, endpoint, configuration, and posture-management platforms.
- Validate scanner findings against the operational environment and distinguish valid findings from false positives using documented rationale and supporting evidence.
- Assess and assign severity using CVSS, DFC policy, exploitability, known-exploitation status, asset criticality, external exposure, mission impact, and relevant threat intelligence.
- Recommend risk-informed remediation priorities, actions, timelines, evidence requirements, and closure criteria.
- Coordinate with engineering, operations, application, cloud, endpoint, and system administration teams to establish remediation ownership, dependencies, and target completion dates
- Provide rapid analysis and coordination for CISA Known Exploited Vulnerabilities (KEV), Binding Operational Directive 22-01 requirements, CISA Emergency Directives, vendor-declared zero-days, and vulnerabilities with active exploitation.
- Notify the ISSM within four hours of applicable CISA notification, vendor disclosure, Government notification, or Contractor identification.
- Verify exposure across applicable CSAM authorization boundaries and deliver a written impact assessment within one business day.
- Document affected systems, boundaries and assets; severity; exposure; exploitability; known exploitation; mission impact; remediation ownership; required timelines; recommended action; and residual-risk considerations.
- Track emergency remediation against CISA-, DFC-, or Government-directed deadlines and provide written confirmation of remediation status, compliance status, residual risk, and closure evidence.
- Use CSAM as the authoritative POA&M and compliance ledger and ServiceNow as the operational remediation ticketing record.
- Create complete POA&M items in CSAM within three business days after finding identification or Government direction, unless the Government establishes another deadline.
- Populate and maintain required fields, including identifier, weakness description, affected system and control, severity, source, responsible owner, required resources, scheduled completion date, milestones, status, residual risk, and closure evidence.
- Maintain bidirectional traceability so each applicable ServiceNow remediation ticket links to its CSAM POA&M item and each CSAM POA&M record references the appropriate ServiceNow ticket.
- Track remediation through closure, monitor milestone integrity and aging, and coordinate scheduled-completion-date changes only after federal authorization.
- Conduct monthly ServiceNow-to-CSAM reconciliation; identify stale or duplicate records, missing links or evidence, inconsistent status, inaccurate dates, and other data-quality issues; issue a written discrepancy log and track gaps to resolution.
- Prepare risk-acceptance or exception recommendation packages when remediation cannot be completed within applicable timelines or scheduled-completion-date constraints.
- Document the affected system and weakness, operational and mission impacts, exploitability, exposure, residual risk, compensating controls, remediation constraints, proposed duration and expiration, review interval, and conditions for continued acceptance.
- Route recommendation packages to the AODR through the COR and ISSM for federal decision and accurately record approved decisions in CSAM.
- Clearly preserve federal authority: do not accept risk for DFC, approve exceptions, extend POA&M dates without authorization, or make final closure decisions.
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the DFC - Vulnerability Management Analyst in Washington DC vacancy
$87.1k - $157.45k
...Description Leidos has a career opportunity for a Vulnerability Management Analyst to support the Air Force National Capital Region IT Services program. The AFNCR IT Services program provides support services for information systems for Headquarters Air Force (HAF), Air...SuggestedWork at office- ...Vulnerability Management Analyst Location - Joint Base Andrews, MD Clearance - Secret Certifications - CompTIA Security+ or equivalent About TIME Systems At TIME Systems, we are at the forefront of Technology, Innovation, Management, and Engineering solutions. Our commitment...SuggestedTemporary workLocal areaFlexible hours
- RiVidium is seeking a Vulnerability Management Analyst to support our planned MODES III team supporting Military Community and Family Policy (MC&FP). This role supports IT, Cybersecurity, and Data Operations - Core Operations and helps deliver mission-focused outcomes...SuggestedContract work
$87.1k - $157.45k
Leidos has a career opportunity for a Vulnerability Management Analyst to support the Air Force National Capital Region IT Services program. The AFNCR IT Services program provides support services for information systems for Headquarters Air Force (HAF), Air Force District...SuggestedWork at officeWorldwide- ...S. Government customer to provide cybersecurity vulnerability analysis support to reduce the prevalence and impact... ...(CIKR). The Cybersecurity Vulnerability Analyst utilizes cybersecurity best practices, risk management techniques, critical thinking, and strong analytical...Suggested
$80k - $128k
...Clearance: Secret Peraton is currently seeking a Risk and Vulnerability Analyst. Location: Chandler, AZ or Washington DC. The Risk and Vulnerability... ...years of experience in security operations, vulnerability management, or risk analysis. Hands‑on experience with industry...Contract workShift work- ...Salesforce case record creation Verify integrations between AI-generated summaries, call metadata, quality scores, and Verint quality management systems Validate CloudWatch alarms, anomaly detection configurations, operational monitoring dashboards, and alerting...Local area
$100k - $200k
...plans, test methodologies, and test cases to evaluate system compatibility and performance. Test Environment Deployment: Set up and manage virtual and physical test environments, including necessary tools and infrastructure, for testing systems and applications....- ...Qualifications 5+ years of directly relevant experience in cyber incident management or cybersecurity operations Knowledge of incident response and handling methodologies Having close familiarity with NIST 800-62 (latest revision), and FISMA standards as they pertain...
$100k - $125k
...Overview Nakupuna Consulting is looking to hire a Management Analyst to support a DoD client within the Department of the Navy (DON) in executing day-to-day administrative, analytical, and professional support requirements. The Management Analyst will support the client...Contract workWork at officeRemote work$78k - $82k
...Pay: $78,000.00 - $82,000.00 per year Job description: Management Analyst Constellation seeks a Management Analyst to join our Homeland Security team in Washington, DC. This role serves as a trusted advisor to senior federal leadership. This role will anticipate...Full timeFor contractorsWork at officeRemote workFlexible hours$85k
...that enhance efficiency and knowledge retention for NGB ExecSec and ARNG offices.This specialize... Show more Full-time DADMS Analyst / Management Analyst II.The DADMS Analyst / Management Analyst II manages software and hardware registration within the DoD Application...Full timeContract workTemporary workSummer workWork at officeRemote workWork from home- ...Job Description We are actively seeking an experienced Identity & Access Management (IAM) Analyst to join our Information Security team. In this role, you will be responsible for the design, implementation, administration, and continuous improvement of our identity...Temporary workCasual workWork at officeLocal areaFlexible hoursNight shift
- ...compelling opportunity for strategic partnerships in the GovCon space. Job Description BryceTech is currently looking for a Records Management Analyst. The person in this role will support our HHS ASPR client with a variety of needs including support to the Office of Records...For contractors
- Overview This position is in the Policy and Programs Division, Office of Counterintelligence, Domestic Operations Directorate, Bureau of Diplomatic Security (DS/CI/PPD). The Office of Counterintelligence works to detect, deter, and neutralize the efforts of foreign intelligence...Work at officeWorldwide
$69k - $105k
...Kearney & Company is seeking a Management Analyst to join our growing firm. Duties include but not limited to: Provide support to ensure conformance with work requirements associated with accounting, resource allocations, internal management controls, business process...Contract workFor contractorsWork at officeLocal areaFlexible hours- ...responsibility for assisting District residents who are covered by the Health Care Bill of Rights. The incumbent serves as a Management Analyst, responsible for assisting the administration with handling customer inquiries, analyzing, evaluating, and providing information...Work at officeLocal areaMonday to Friday
- ...vesting period Tuition / Certification / Training reimbursement Accident / Disability / Universal Life Insurance And much more The Management Analyst (Journeyman) provides programmatic, analytical, and administrative support to the U.S. Border Patrol (USBP) Program...Work at office
- ...Senior Database Management Analyst - Position Description Join a team that is shaping the future of Navy support. ICI Services is a 100% employee-owned company proudly celebrating 26 years of excellence—is seeking a Senior Database Management Analyst to Join our Team...Temporary workFor contractorsImmediate startFlexible hours
$76.7k - $128k
...Management Analyst II Overview AMERICAN SYSTEMS is an employee-owned federal government contractor supporting national priority programs through our strategic solutions in the areas of Information Technology, Test & Evaluation, Program Mission Support, Engineering & Analysis...For contractors- ...Trilogy Federal is seeking a Technology Business Management (TBM) Analyst to support the Department of Veterans Affairs (VA) Office of Information and Technology (OIT), IT Budget and Finance (ITBF) organization. This role supports TBM initiatives to advance IT cost transparency...Work at office
$116.35k - $210.33k
Description Leidos has an exciting opportunity for an Identity & Access Management (IAM) Analyst is responsible for administering user identities and access privileges across enterprise systems and applications. This role ensures that users receive appropriate access...Temporary workLocal areaImmediate start$56k - $94k
## Management AnalystApplylocations: US - MD, Bethesdatime type: Full timeposted on: Posted Yesterdayjob requisition id: 42236**Job Family:**Research Analyst**Travel Required:**None**Clearance Required:**Ability to Obtain Public Trust**What You Will Do:**We are seeking...Full timeTemporary workWork at officeFlexible hours- ...law enforcement community to exchange information on counterintelligence matters of mutual interest and concern. Oversees the management of contractors, ensuring compliance with contractual terms and conditions and identifying and rectifying problems to ensure satisfactory...Full timePart timeFor contractorsWork at officeRemote workWorldwide
- ...is a non-personal services contract to provide Administrative, Analyst and Advisor Services that shall support the Bureau of European... ...through the Departments conference room reservation platform. Manage files and records, preparing files, folders and other federal records...Contract workTemporary workFor contractorsWork at office
$89k - $125k
...click into an open position below and provide the requested information. We look forward to reviewing your submission! Position: Management Analyst Location: District of Columbia, Maryland, and Virginia - Hybrid, DC Job Id: 669 # of Openings: 2 Management Analyst Location:...Full timeContract workTemporary workWork experience placementWork at officeLocal areaRemote workFlexible hours- ...Position: Management Analyst Clearance Required: Secret Provides contract administration support, analyzes, and translates requirements into requisition; analyzes vendor invoices for accuracy and validates for compliance with contract terms and conditions. Initiates requests...Contract workTemporary workFor contractorsWork at office
- Essnova Solutions is seeking three Senior Management Analysts to support FEMA's National Training and Education Division and Training Partners Program. The analysts will provide research, analytical, technical, coordination, and deliverable-development support across FEMA...Contract workPart time
- ...We are actively seeking an experienced Identity & Access Management (IAM) Analyst to join our Information Security team. In this role, you will design, implement, administer, and continuously improve our identity governance and privileged access management programs. You...Visa sponsorshipWork visa
$60k - $85k
...Overview VTG is seeking a Management Analyst to support the Navy located at the Washington Navy Yard. The position is 100% onsite. What will you do? Collect, review, and analyze information in order to make recommendations to the Government. Define the nature and extent...For contractorsWork experience placement
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to DFC - Vulnerability Management Analyst. Be the first to apply!
Related searches
- vulnerability analyst Washington DC
- ethical hacker Washington DC
- penetration tester Washington DC
- business analyst healthcare Washington DC
- business analyst part time Washington DC
- fiserv business analyst Washington DC
- management analyst Washington DC
- oracle business analyst Washington DC
- business analyst law firm Washington DC
- senior business development analyst Washington DC

