Vulnerability Management Analyst
DANE LLC
Job Description
Job Description
Benefits:
- Life/STD/LTD
- FSA/DCA
- 401(k)
- Employee discounts
- Paid time off
- 401(k) matching
- Dental insurance
- Health insurance
- Tuition assistance
- Vision insurance
Job Type: Full Time
Education: Minimum of a Bachelor’s degree in computer science or Equivalent
Experience: Minimum 1 year of relevant experience
Clearance: Must hold an Active DoD Secret Clearance or higher Responsibilities
- Run authorized Tenable/Nessus scans using credentialed scan profiles and review exports to identify CVEs, plugin findings, KEV status, EOL/EOS software risks, and affected assets.
- Validate findings as true or false positives, track vulnerability age using first-seen/last-seen dates, and escalate unresolved findings to senior security staff or system owners.
- Support the full vulnerability lifecycle from intake and triage through ownership assignment, remediation tracking, retest/rescan validation, and closure evidence collection.
- Monitor KEV and Critical/High findings against federal remediation timelines (e.g., BOD 22-01) and flag aging, stale, or blocked findings for escalation.
- Build and maintain Power BI dashboards and Excel reports covering vulnerability posture, patch compliance, KEV status, finding aging, and ownership tracking using Power Query, slicers, and basic DAX measures.
- Produce recurring deliverables, including Critical/High aging reports, Tenable/iPost reconciliation summaries, EOL/EOS tracking, and executive snapshots; document KPI definitions and data sources.
- Reconcile vulnerability data across Tenable/Nessus, iPost, ServiceNow/CA ServiceDesk, Jira, SharePoint, POA&M trackers, and Excel exports to identify mismatches and coverage gaps.
- Coordinate with security, development, infrastructure, database, and cloud teams and ISSO stakeholders to drive remediation through closure.
- 1–3 years of experience in cybersecurity operations, vulnerability management, SOC, cyber GRC, IT operations, or application security support; working knowledge of CVE, CVSS, KEV, false positives, POA&M tracking, risk acceptance, and vulnerability aging.
- Hands-on Tenable/Nessus experience: executing credentialed scans, analyzing plugin output and CVE findings, validating true/false positives, and building dashboards, saved filters, and exports for KEV, Critical/High, EOL/EOS, and aging tracking.
- Intermediate Power BI (Power Query, data modeling, DAX, slicers) and strong Excel skills (pivot tables, VLOOKUP/XLOOKUP, conditional formatting, deduplication) for vulnerability reporting and KPI tracking.
- Experience with iPost, ServiceNow, CA ServiceDesk, Jira, or SharePoint for remediation tracking; ability to reconcile data across multiple tools, identify mismatches, and maintain accurate ownership and evidence records.
- Familiarity with EOL/EOS software tracking, patch compliance, remediation exceptions, risk acceptance documentation, and closure evidence collection.
- Strong attention to detail, comfort working with large and messy datasets, and clear communication skills for translating technical findings into plain-language updates for leadership and non-technical stakeholders.
- Experience supporting federal cybersecurity programs or regulated environments; familiarity with NIST SP 800-53, RMF, A&A, ATO, POA&M lifecycle management, CISA BOD 22-01, and FedRAMP vulnerability requirements.
- Exposure to DevSecOps and application security tooling: SAST, DAST, SCA, container image scanning, secrets scanning, or Software Bill of Materials (SBOM) analysis.
- Basic understanding of enterprise patching for Windows Server, Windows workstations, .NET Framework, Java JRE, SQL Server, and endpoint agents; familiarity with Splunk or other SIEM platforms.
- Experience developing SOPs, RACI matrices, or workflow documentation in a security or IT operations context.
- Relevant certifications such as CompTIA Security+, CySA+, CEH, or equivalent entry-to-mid-level cybersecurity credentials.
Flexible work from home options available.
Vacancy posted 15 days ago
Similar jobs that could be interesting for youBased on the Vulnerability Management Analyst in Chantilly, Loudoun County, VA vacancy
- ...benefits, and ongoing learning opportunities, backed by a culture that values and supports our team. We are seeking a Vulnerability Management Analyst (Tenable/Nessus & Metrics) to support vulnerability tracking, remediation coordination, and security metrics reporting...SuggestedFull timeWork from homeFlexible hours1 day per week
- Mission Technologies, a division of HII, is looking for a skilled professional in vulnerability management in Fairfax, Virginia. The successful candidate will support Department of Defense cybersecurity efforts, ensure accuracy in vulnerability assessments, and maintain...Suggested
- ...Overview Position Title: Senior Business Operations & Financial Management Analyst Location: Chantilly, VA Clearance Requirement: Active Top Secret with SCI eligibility U.S. Citizenship required OMNI Consulting Solutions is seeking a Senior Business Operations & Financial...SuggestedWork at office
$124k - $168k
...Responsibilities: Responsible for performing basic reconnaissance and vulnerability scanning in accordance with established testing methodologies... ..., and leading remediation efforts Collaborating with management to develop security policies, training other cybersecurity...SuggestedWork experience placement$110k - $215k
...exceptional performance! Core One is seeking Senior Cyber Security Analyst to support our IC program. This position requires a TS/SCI w/... ...cybersecurity policies, and regulations. Knowledge of risk management standards, CNSSP 1253, FIPS 140-2, 199, 200, and NIST SP 800-3...SuggestedFull timeContract work$89.2k - $194.78k
...AT&T is seeking a Change Management Analyst to join their National Security Team in Chantilly, Virginia. This role requires a minimum of 5 days office presence and focuses on supporting configuration control, customer engagement, and managing change tickets. The ideal...Work at office$100k - $130k
Employment Type Full-time Signal Hill Technologies is seeking a highly skilled Vulnerability Analyst to support our federal client's vulnerability management program. The position is contingent upon contract award and is anticipated as full-time/permanent. This role is...Permanent employmentFull timeContract workWork at officeLocal area- ...with CVE Experience with Vulnerabilty Management Top 2 Soft Skills Great written and verbal... ..." Job Description Analyzing the vulnerability reports and advising the business on the... ...the tools and experience needed by the analyst will be: Tenable Qualys Experience with...Contract work
- ...Digital Forensic Analyst Employment Type: Full-Time, Mid-Level Department: Forensics CGS is seeking a Digital Forensic Analyst whose... ...updates and new options in the market Work closely with project management and other team members on completing complex projects in a...Full timeWork at officeRemote workFlexible hours
- Description Seeking a Digital Forensics Analyst, to serve as a member of an organizational cybersecurity program. This position requires an active TS/SCI with Polygraph. Key Responsibilities Conduct forensic acquisition and analysis on computer, mobile, IOT, digital media...Work experience placement
- ...an experienced ICAM ISSO (Identity, Credential, and Access Management Information System Security Officer) to support critical cybersecurity... ...functioning as intended. Identify and document system vulnerabilities and risks, coordinating remediation efforts and tracking...Local areaFlexible hours
- ...account/access reviews for compliance with security policy. Monitor system security posture and support continuous monitoring and vulnerability scanning activities. Maintain and update system security documentation, including SSPs, POA&Ms, and configuration records....
- ...System Security Officer (ISSO). The ISSO will be responsible for managing the authorizations and risks related to the processing,... ...the execution, analysis, and remediation activities for the vulnerability management program (scanning, assessment, reporting, and mitigation...
- ...Litigation Systems Analyst Employment Type: Full Time, Mid-level CGS is seeking a Systems Analyst to join our team supporting a... ...Government staff and/or under the direction of the Contract IT Manager, Systems Manager, Senior Systems Analyst, or Lead Project Manager...Full timeContract workFor contractorsWork at officeRemote workFlexible hours
$113.2k - $237.8k
Job Title: Cyber Security Analyst Job Category: Engineering Time Type: Full time Minimum Clearance Required to Start: TS/SCI... ...career network. We are a fun, engaging environment with a management team focused on growing your career and making you a part of our...Full timeContract workWork experience placementLocal areaImmediate startFlexible hours- ...background in quality control practices, energy efficiency improvements, and safety assurance. Familiarity with computerized maintenance management systems (CMMS) or diagnostic software. Experience conducting vehicle inspections in compliance with DOT or local regulatory...Local areaNight shift
- ...implement, integrate, and sustain Comply-to-Connect (C2C) deployment support to migrate, deploy, improve, and maintain C2C services Manage and maintain appliances, applications, servers, and supporting infrastructure in both classified and unclassified environments...Work at office
$225k - $260k
...sales team, responsible for identifying and acquiring new business Mission and Enterprise Information Technology opportunities while managing and growing existing accounts. Role requires a strategic sales approach, strong client relationship management skills, and a...Hourly payContract workTemporary workLocal area$100k
...and monthly bonuses; Our top performers make well over a 6-figure income. To ensure your success, you will have a dedicated sales manager & support team, continued results-driven training, WHAT THE COMPENSATION PACKAGE OFFERS: UNCAPPED EARNING POTENTIAL AGGRESSIVE...Local area- ...effective relationships with peers and communicate at all levels within the organization. ~ Ability to provide Tier 3 support and manage complex and escalated tickets in production environment Additional Information All your information will be kept...Full timeContract workWork at office
- ...Centurion is seeking a Senior Manager, Business Development to accelerate our Client's growth within the National Defense and Intelligence Communities; specifically, the National Geospatial-Intelligence Agency (NGA) and National Reconnaissance Office (NRO). The successful...Contract workTemporary workWork at office
- ...thrusters, and complete propulsion subsystems. Develop and implement sales plans, systems, policies, initiatives, and procedures to manage the sales pipeline and close deals. Collaborate with the Communications & Marketing team in creating propulsion product collateral,...Permanent employmentFor contractorsLocal areaWeekend work
- Position Description & Qualifications As the Director of Business Development , you will lead a high-stakes, end-to-end campaign pursuits designed to continually build capabilities addressing eligibility, identifying & mitigating improper payments, fraud mitigation, auditing...Full timeContract workPart timeLocal areaRemote workFlexible hours
- ...Driving Customer Experience Excellence Pohanka Automotive Group is looking for a driven, people-first Service Business Development Manager (BDC Manager) to lead and elevate our customer engagement operations. In this role, you’ll coach and inspire a high-performing BDC...Local area
- ...partners to formulate successful teaming partnerships. Collaborate with the Lead Account Partner, solution leaders, and capture managers to develop bid strategies, proposal processes, technical solutions, and written proposals for RFI/RFQ/RFP/White Papers. Develop...Worldwide
- Centurion is seeking a Senior Manager, Business Development in Chantilly, Virginia, to enhance growth within the National Defense and Intelligence sectors, focusing on the National Geospatial-Intelligence Agency (NGA) and National Reconnaissance Office (NRO). The ideal...Work at office
- Serco is seeking a Director of Business Development to lead end-to-end campaign pursuits in the Benefits Integrity - BPO arena. You will drive customer engagement, shape right-to-win strategies, and rally cross-functional teams to win large government contracts. This full...Full timeRemote work
- ...Government Services company , is seeking a Strategic Business Analyst with a Secret Security clearance to support ATS and our government... ...of military strategy, enterprise architecture, and program management, requiring the ability to translate complex operational...Work at officeLocal areaFlexible hours
$116.35k - $210.33k
Leidos is seeking an experienced Technical Project Manager (PM) to lead and track the development and implementation of complex, strategic initiatives across multiple service teams. This role requires strong project management skills and the technical acumen to understand...Full timeFor contractors$85k - $95k
Business Analyst HighPoint's professionals focus on helping government agencies and companies implement their most critically strategic... ...reporting and analysis strategy; maintaining a strong focus on managing recurring and ad‑hoc reporting processes from design, data...Local area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vulnerability Management Analyst. Be the first to apply!
Related searches
- business analyst healthcare Chantilly, Loudoun County, VA
- fiserv business analyst Chantilly, Loudoun County, VA
- management analyst Chantilly, Loudoun County, VA
- business analyst law firm Chantilly, Loudoun County, VA
- senior business development analyst Chantilly, Loudoun County, VA
- pega business analyst Chantilly, Loudoun County, VA
- business analyst part time remote Chantilly, Loudoun County, VA
- senior business analyst Chantilly, Loudoun County, VA
- agile business analyst Chantilly, Loudoun County, VA
- software asset management analyst Chantilly, Loudoun County, VA



