Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Vulnerability Management Analyst

DANE LLC

Job Description

Job Description

Benefits:

  • Life/STD/LTD
  • FSA/DCA
  • 401(k)
  • Employee discounts
  • Paid time off
  • 401(k) matching
  • Dental insurance
  • Health insurance
  • Tuition assistance
  • Vision insurance
Description

Looking for a place that invests in you from day one? At DANE, we offer aggressive PTO, strong benefits, and ongoing learning opportunities, backed by a culture that values and supports our team.

We are seeking a Vulnerability Management Analyst (Tenable/Nessus & Metrics ) to support vulnerability tracking, remediation coordination, and security metrics reporting in a federal technology environment. This is a junior-level role (1–3 years of experience) focused on execution and coordination, working hands-on with Tenable/Nessus, iPost, Power BI, Excel, and ticketing systems to ensure that vulnerability data is accurate, actionable, and reportable.

Details:

Location: Hybrid - Onsite, Arlington, VA,1 day/week and as needed
Job Type: Full Time
Education: Minimum of a Bachelor’s degree in computer science or Equivalent
Experience: Minimum 1 year of relevant experience
Clearance: Must hold an Active DoD Secret Clearance or higher

Responsibilities

  • Run authorized Tenable/Nessus scans using credentialed scan profiles and review exports to identify CVEs, plugin findings, KEV status, EOL/EOS software risks, and affected assets.
  • Validate findings as true or false positives, track vulnerability age using first-seen/last-seen dates, and escalate unresolved findings to senior security staff or system owners.
  • Support the full vulnerability lifecycle from intake and triage through ownership assignment, remediation tracking, retest/rescan validation, and closure evidence collection.
  • Monitor KEV and Critical/High findings against federal remediation timelines (e.g., BOD 22-01) and flag aging, stale, or blocked findings for escalation.
  • Build and maintain Power BI dashboards and Excel reports covering vulnerability posture, patch compliance, KEV status, finding aging, and ownership tracking using Power Query, slicers, and basic DAX measures.
  • Produce recurring deliverables, including Critical/High aging reports, Tenable/iPost reconciliation summaries, EOL/EOS tracking, and executive snapshots; document KPI definitions and data sources.
  • Reconcile vulnerability data across Tenable/Nessus, iPost, ServiceNow/CA ServiceDesk, Jira, SharePoint, POA&M trackers, and Excel exports to identify mismatches and coverage gaps.
  • Coordinate with security, development, infrastructure, database, and cloud teams and ISSO stakeholders to drive remediation through closure.
Requirements

  • 1–3 years of experience in cybersecurity operations, vulnerability management, SOC, cyber GRC, IT operations, or application security support; working knowledge of CVE, CVSS, KEV, false positives, POA&M tracking, risk acceptance, and vulnerability aging.
  • Hands-on Tenable/Nessus experience: executing credentialed scans, analyzing plugin output and CVE findings, validating true/false positives, and building dashboards, saved filters, and exports for KEV, Critical/High, EOL/EOS, and aging tracking.
  • Intermediate Power BI (Power Query, data modeling, DAX, slicers) and strong Excel skills (pivot tables, VLOOKUP/XLOOKUP, conditional formatting, deduplication) for vulnerability reporting and KPI tracking.
  • Experience with iPost, ServiceNow, CA ServiceDesk, Jira, or SharePoint for remediation tracking; ability to reconcile data across multiple tools, identify mismatches, and maintain accurate ownership and evidence records.
  • Familiarity with EOL/EOS software tracking, patch compliance, remediation exceptions, risk acceptance documentation, and closure evidence collection.
  • Strong attention to detail, comfort working with large and messy datasets, and clear communication skills for translating technical findings into plain-language updates for leadership and non-technical stakeholders.
Preferred Qualifications

  • Experience supporting federal cybersecurity programs or regulated environments; familiarity with NIST SP 800-53, RMF, A&A, ATO, POA&M lifecycle management, CISA BOD 22-01, and FedRAMP vulnerability requirements.
  • Exposure to DevSecOps and application security tooling: SAST, DAST, SCA, container image scanning, secrets scanning, or Software Bill of Materials (SBOM) analysis.
  • Basic understanding of enterprise patching for Windows Server, Windows workstations, .NET Framework, Java JRE, SQL Server, and endpoint agents; familiarity with Splunk or other SIEM platforms.
  • Experience developing SOPs, RACI matrices, or workflow documentation in a security or IT operations context.
  • Relevant certifications such as CompTIA Security+, CySA+, CEH, or equivalent entry-to-mid-level cybersecurity credentials.
DANE LLC is an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Flexible work from home options available.

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Vulnerability Management Analyst in Chantilly, Loudoun County, VA vacancy
  •  ...benefits, and ongoing learning opportunities, backed by a culture that values and supports our team. We are seeking a Vulnerability Management Analyst (Tenable/Nessus & Metrics ) to support vulnerability tracking, remediation coordination, and security metrics... 
    Suggested
    Full time
    Work from home
    Flexible hours
    1 day per week

    DANE LLC

    Chantilly, Loudoun County, VA
    22 days ago
  •  ...deployments as per protocols, perform post-deployment testing, and manage version control to track changes • Co-ordinate maintenance...  ..., risk assessments, and reporting processes • Maintain vulnerability management standard, procedures, and guidelines • Identify vulnerabilities... 
    Suggested
    Full time
    Temporary work
    Relocation

    Infosys

    Reston, VA
    5 days ago
  • $62k - $141k

     ...Active Directory attack path enumerationExperience with C2 frameworks, including Cobalt Strike, Mythic, or HavocKnowledge of network vulnerability assessments, web application security testing, network penetration testing, or red teamingHS diploma or GEDNice If You Have:... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Chantilly, Loudoun County, VA
    1 day ago
  • $200k

    OverviewSenior Business Operations & Financial Management Analyst LOCATION: Chantilly, VAJOB STATUS: Full-timeCLEARANCE: Active DoD Top Secret security clearance with SCI eligibility and Poly required.U.S. citizenship required.SALARY RANGE: Estimated $200,000+ USD Annually... 
    Suggested
    Work at office

    Astrion Group

    Chantilly, Loudoun County, VA
    3 days ago
  • DescriptionSAIC is seeking a Principal Cyber Security Cloud Analyst, to serve as a member of a Vulnerability Assessment program. This position is located in...  ...the presence of vulnerabilitiesAct as advisor to management and customers on technical research studies, to include... 
    Suggested

    Science Applications International Corporation

    Chantilly, Loudoun County, VA
    4 days ago
  • $86.6k - $181.8k

    Job Title: Event Management Practice Area AnalystJob Category: Information TechnologyTime Type: Full timeMinimum Clearance Required to...  ...assisting in IT Infrastructure governance and operations. The analyst will work with key stakeholders to ensure proper implementation... 
    Contract work
    Work experience placement
    Immediate start
    Flexible hours

    CACI International

    Chantilly, Loudoun County, VA
    4 days ago
  • $86.8k - $198k

    Enterprise Cybersecurity Vulnerability Analyst, SeniorThe Opportunity:Support Booz Allen Hamilton's internal Enterprise Cybersecurity team by...  ...SLA levels. Conduct analysis and serve as a vulnerability management resource supporting the company's client-facing and internal... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    3 days ago
  • $150k - $195k

     ...for performing basic reconnaissance and vulnerability scanning in accordance with established...  ...efforts; collaborating with management to develop security policies, training...  ...CompTIA Pen Test+• CompTIA Cybersecurity Analyst (CySA+)• Certified Hacking Forensic Investigator... 
    Work experience placement

    VTG

    Chantilly, Loudoun County, VA
    8 hours ago
  • $86.6k - $181.8k

    Job Title: Service Configuration Management AnalystJob Category: Information TechnologyTime Type: Full timeMinimum Clearance Required to...  ...Integration and Management) - Configuration Management Analyst to support the planning, design, and implementation of configuration... 
    Contract work
    Work experience placement
    Flexible hours

    CACI International

    Chantilly, Loudoun County, VA
    2 days ago
  •  ...Position Title: Senior Business Operations & Financial Management Analyst Location: Chantilly, VA Clearance Requirement: Active Top Secret with SCI eligibility U.S. Citizenship required OMNI Consulting Solutions is seeking a Senior Business Operations &... 
    Full time
    Work at office

    OMNI Consulting Solutions

    Chantilly, Loudoun County, VA
    a month ago
  • $124k - $168k

     ...Responsibilities: Responsible for performing basic reconnaissance and vulnerability scanning in accordance with established testing methodologies...  ..., and leading remediation efforts Collaborating with management to develop security policies, training other cybersecurity... 
    Work experience placement

    Cyber Defense Technologies

    Chantilly, Loudoun County, VA
    2 days ago
  •  ...perform duties as the alternate Information Systems Security Manager (ISSM). Cyber security paperwork (compliance) and Information...  ...policies, controls and procedures and mitigate identified vulnerability and weaknesses Ability to work well in a team environment and... 
    Internship
    Work at office

    MANTECH

    Chantilly, Loudoun County, VA
    1 day ago
  •  ...system security plans, SOPs, audit logs, configuration scans, and vulnerability scansEvaluating the implementation and effectiveness of IT...  ...Information Systems Auditor (CISA) or Certified Information Security Manager (CISM)Demonstrated knowledge and experience in IT risk and... 
    Full time
    Flexible hours

    Guidehouse

    Chantilly, Loudoun County, VA
    2 days ago
  • Earned Value Management (EVM)/Integrated Performance Management (IPM) Analyst – SME Level – TS/SCI Clearance w/CI Poly Required Location Chantilly, VA Job Description Leffler Consulting is seeking a seasoned Earned Value Management (EVM)/Integrated Performance Management... 
    For contractors
    Work experience placement
    Work at office

    Leffler Consulting, LLC

    Chantilly, Loudoun County, VA
    more than 2 months ago
  • $100k - $113k

     ...Chantilly, VA to monitor and maintain systems security on operational systems such as malicious code eradication, configuration management, assessment and authorization of current and future systems, as well as to review and revise systems security documentation on proposed... 
    Civilian Contractor
    Work experience placement
    Work at office

    VTG

    Chantilly, Loudoun County, VA
    2 days ago
  • $98.1k - $115k

     ...solutions to accomplish the requirements in addition to program management. The services obtained under this contract shall provide...  ...Conducting regular security audits and assessments to identify vulnerabilities and risks.Monitoring network traffic for unusual activity... 
    Contract work
    Temporary work
    For contractors
    Work at office
    Local area
    Relocation

    AT&T

    Chantilly, Loudoun County, VA
    6 days ago
  • $100k - $140k

     ...engineers, visitors, system administrators, security staff, program managers, and local vendors and inspectors. This position requires an...  ...including audit log reviews, system compliance assessments, vulnerability scans, and account activity for privileged and general users.... 
    Full time
    Temporary work
    For contractors
    Work at office
    Local area
    Remote work
    Flexible hours

    Rincon Research

    Chantilly, Loudoun County, VA
    3 days ago
  • $110k - $180k

     ...candidate will have demonstrated experience working the Risk Management Framework with Department of Defense (DOD) and Intelligence Community...  ...are established and followed. The position will perform vulnerability/risk assessment and configuration management to support... 
    Full time
    Contract work
    For contractors
    Work at office
    Immediate start

    Jacobs

    Chantilly, Loudoun County, VA
    3 days ago
  • $103.8k - $218.1k

     ...Bridge develops and supports Identity, Credential and Access Management (ICAM) capabilities for the enterprise and stand-alone deployment...  ..., standards, and methodologies. Familiarity with the use of vulnerability scanning and assessment tools (e.g., ACAS/Nessus) necessary... 
    Contract work
    For contractors
    Work experience placement
    Work at office
    Local area
    Flexible hours

    CACI International

    Chantilly, Loudoun County, VA
    8 hours ago
  •  ...part of an overall Sponsor effort to migrate portions or all of payroll systems to a new-shared service provider. Priorities will be managed by the designated Government Technical Manager (GTM). Work Requirements: Software Quality Assurance with Application Testing: 1.... 
    For contractors

    Science Applications International Corporation

    Chantilly, Loudoun County, VA
    4 days ago
  • OverviewThe Software Test Engineer / Quality Assurance Engineer develops and implements quality control methodologies to ensure compliance with quality assurance standards, guidelines, and procedures within a large computer-based organization. This position is responsible...

    VTG

    Chantilly, Loudoun County, VA
    4 days ago
  •  ...verification methods for system, subsystem, and component level requirementsInvestigate problems referred by customer supportPlan, manage, and track project test effortsEvaluate and develop detailed test plans, procedures, and reportsOversee and perform testing in a DevOps... 

    VTG

    Chantilly, Loudoun County, VA
    2 days ago
  • OverviewVTG is seeking a detail-oriented QA Automation Engineer to design, develop, and maintain automated test frameworks and scripts. This role will play a critical part in ensuring software quality by integrating automated testing into the development lifecycle and improving...

    VTG

    Chantilly, Loudoun County, VA
    8 hours ago
  •  ...software engineering, AI solutions, cybersecurity, and IT program management. We thrive at the intersection of mission, technology, and...  ...security groups and organizations Communicating vulnerability results and risk posture to senior executives Performing complex... 
    Full time
    Work experience placement

    Ardent Principles, Inc.

    Chantilly, Loudoun County, VA
    22 days ago
  •  ...administering SolarWinds alongside deep knowledge of Microsoft Windows Systems, HP SANs, and VMware products Advanced experience managing VPNs, GRE tunnels, routing protocols (BGP E/I, OSPF), VLANs, VRFs, and configuring KGs Strong familiarity with Cisco ACI, data... 
    Work at office

    MANTECH

    Chantilly, Loudoun County, VA
    1 day ago
  • $86.8k - $198k

    Missile Systems Analyst, SeniorThe Opportunity:Leverage experience with design and operations of foreign conventional missile systems...  ...engagement operations, electronic warfare, datalinks, battle management, and operational employment conceptsMaster's degree in a STEM... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Chantilly, Loudoun County, VA
    1 day ago
  • DescriptionSAIC is seeking an Space Systems Analyst with technical expertise in government satellite systems to support the Mission...  ...and architecturesExperience with DOD/IC acquisition and program management processesExperience with MATLAB or equivalent DSP development... 
    For contractors

    Science Applications International Corporation

    Chantilly, Loudoun County, VA
    4 days ago
  • $140k - $160k

     ...Security Officer (ISSO) to lead a collaborative team to develop, manage, and maintain information system security Assessment and...  ...activities, consisting of periodical reviews of controls, audits, vulnerability scans, and penetration test reports. POA&M development to... 
    Full time
    For contractors
    Flexible hours

    Dark Wolf Solutions

    Chantilly, Loudoun County, VA
    3 days ago
  •  ...System Security Officer (ISSO). The ISSO will be responsible for managing the authorizations and risks related to the processing,...  ...the execution, analysis, and remediation activities for the vulnerability management program (scanning, assessment, reporting, and mitigation... 

    Falcon IT & Staffing Solutions

    Chantilly, Loudoun County, VA
    2 days ago
  • Overview Amyx is seeking to hire an Acquisition Consultant/Management Analyst to join our Defense Health Ageny contract in San Antonio,Tx. Responsibilities Provide medical administration services in a wide range of organizational, business, and financial operations... 
    Full time
    Contract work
    For contractors
    Flexible hours

    Amyx

    Reston, VA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Vulnerability Management Analyst. Be the first to apply!