Tier 1 - Vulnerability Assessment Analyst
$69.55k - $125.73kLeidos
Department of Homeland Security (DHS), Customs and Border Protection (CBP) Security Operations Center (SOC) is a US Government program responsible to prevent, identify, contain and eradicate cyber threats to CBP networks through monitoring, intrusion detection and protective security services to CBP information systems including local area networks/wide area networks (LAN/WAN), commercial Internet connection, public facing websites, wireless, mobile/cellular, cloud, security devices, servers and workstations. The CBP SOC is responsible for the overall security of CBP Enterprise-wide information systems, and collects, investigates, and reports any suspected and confirmed security violations. The DHS CBP SOC Program has a critical need for a Tier 1 Vulnerability Assessor to join our VAT program
This position will provide Vulnerability Assessment support to the United States Department of Homeland Security, focused on performing vulnerability scans of enterprise IT assets utilizing the approved scanning infrastructure. Additional responsibilities include performing research and analyzing current threats and vulnerabilities that may affect the enterprise, writing security advisories, and participating as team member performing focused adversarial assessments.
Primary responsibilities include:
Perform research on current threats and vulnerabilities and analyze security posture of the enterprise. - Author security advisories
Manage enterprise vulnerability compliance, CISA Binding Operational Directives, CISA Emergency Directives, ISVM.
Present vulnerability scan information to leadership, auditors, system engineers, etc.
Basic Qualifications:
All Department of Homeland Security CBP SOC employees are required to favorably pass a 5-year (BI) Background Investigation.
Bachelors’ degree in Computer Science, Engineering, Information Technology, Cyber Security, or related field and 2+ years of related experience. Additional years of experience and cyber certifications may be considered in lieu of degree.
Familiar with the management, operational, and technical aspects of IT Security in a complex enterprise environment.
Familiarity with CVE’s, Current vulnerabilities, Technology Standards and Controls. Experience with in-depth analysis of vulnerabilities and troubleshooting scan issues. Strong familiarity with STIGs and STIG compliance scanning. Should have at least one of the following certifications:
SANS GIAC: GCED, GCIA, GCFA, GPEN, GWAPT, GCFE, GREM, GXPN, GMON or GCIH ISC2 CCFP, CCSP, CISSP CERT CSIH EC Council: CHFI, LPT, ECSA, Offensive Security: OSCP, OSCE, OSWP and OSEE EnCase: EnCE Dod 8570: IAT L3, CNDSP Analyst or IR Carnegie Mellon: CCSIH"
Preferred Qualifications:
Experience in cyber government, and/or federal law enforcement. Experience in Vulnerability scanning and analysis. Experience in financial, CSP and FISMA audits.
Experience with Database (DBPro), Web application (WebInspect), OS (Tenable) scanning and Splunk queries
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.
Original Posting: September 21, 2026 For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
Pay Range: Pay Range $69,550.00 - $125,725.00 The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
Vacancy posted 3 hours ago
Similar jobs that could be interesting for youBased on the Tier 1 - Vulnerability Assessment Analyst in Ashburn, VA vacancy
- DescriptionSAIC is seeking a Principal Cyber Security Cloud Analyst, to serve as a member of a Vulnerability Assessment program. This position is located in Chantilly, VA and requires an active TS/SCI with Polygraph.The hired individual will perform the following key roles...Suggested
$120.8k - $265.8k
...Management Framework (RMF) activities (Steps 1-6), assisting Information System... ...Security Documentation: Develop and maintain Assessment & Authorization (A&A) documentation,... ...security weaknesses, deficiencies, and/or vulnerabilities in the design - evaluating designs for...SuggestedContract workWork experience placementLocal areaImmediate startFlexible hours$122k - $253k
...operations, cyber defense and resiliency, vulnerability research, ubiquitous technical... ...Nightwing is seeking an Cyber Network Forensic Analyst to support this critical customer... ...analyses anomalous network activity - Assesses network topology and device configurations...SuggestedContract workImmediate start- ...operations, cyber defense and resiliency, vulnerability research, ubiquitous technical... ...Demonstrated on-the-job experience conducting assessments of existing IT architecture for compliance... ...frameworkCertifications (not required but encouraged):1. Certified Information Systems Security...SuggestedFull time
$140k - $190k
...than the title suggests. What Success Looks Like Objective 1: Close security findings at their cause rather than at the ticket... ...an answer that is current rather than an answer from the last assessment. What is recorded as implemented matches what is running....SuggestedTemporary workImmediate startRemote workRelocation packageDay shift- ...supporting federal agencies with IT controls assessments and program evaluations. This is an... ...SOPs, audit logs, configuration scans, and vulnerability scansEvaluating the implementation and... ...please contact Guidehouse Recruiting at 1-(***) ***-**** or via email at...Full timeFlexible hours
$107.9k - $195.05k
...Management and Application Security Logging and Vulnerability Management :Ensure continuous monitoring... ...security issues.Conduct security assessments using Microfocus WebInspect and other... ...week.Preferred QualificationsMaster’s with 1-2 years of prior experience in...Full timeWork at officeLocal area- ...activities associated with event collection tier solutions. Normalize and correlate such... ...work must be done in the US. This is a 1-2 days per week onsite role in Herndon, VA... ...reviewing applications, analyzing resumes, or assessing responses and identifying potential...Contract workTemporary work2 days per week1 day per week
- ...knowledge Liaise with business analysts to develop feasible,... ...releases Review Cybersecurity Assessments and Static Code Analysis to define... ...Understanding of software security vulnerabilities and mitigation strategies... ...an on-site requirement of 1-2 days a week in Ashburn, VA...2 days per week1 day per week
$94.4k - $198.3k
...171, DHS 4300A, CBP Handbook 1400-05D Assess entire system lifecycle requirements and... ...environment Enhance - Implement Cybersecurity vulnerability/A&A hardening testing Optimize -... ...~3-year check for felony convictions ~1-year check for illegal drug use ~1-year...Full timeContract workWork experience placementLocal areaFlexible hours- ...portfolio.Core ResponsibilitiesManage the Assessment and Authorization (A&A) lifecycle for... ...document continuous monitoring (ConMon) and vulnerability management across assigned classified... ...Secret clearance (with current SSBI or Tier 5 investigation).Minimum of 3 years of experience...For contractors
$82.3k - $220k
...controlling changes to the system, and assessing the security impact of those changes.Job... ...ISSM for review.• Mentors and coaches ISSO 1.• Performs other duties as assigned.... ...NIST SP 800-53, JSIG, DAAG, ICD 503), IR, Vulnerability Management, SCAP, STIG, and Security-...Full timeLocal area$100k - $140k
...security controls including audit log reviews, system compliance assessments, vulnerability scans, and account activity for privileged and general users... ...assistanceWhat required background will make you successful?1-3 years of ISSO and/or System Administration...Full timeTemporary workFor contractorsWork at officeLocal areaRemote workFlexible hours$98.1k - $115k
...information systems security, security control assessments, information assurance engineering, and... ...audits and assessments to identify vulnerabilities and risks.Monitoring network traffic for... ...) (#polygraph)Required Qualifications:1. Hands on Experience with the RMF Process...Contract workTemporary workFor contractorsWork at officeLocal areaRelocation$103.8k - $218.1k
...boundaries, hardware and software lists, risk assessment reports, POA&Ms, data flows, and other... .... Familiarity with the use of vulnerability scanning and assessment tools (e.g., ACAS... ...been designated as requiring IAM Level 1 CWIP certification and requires one of...Contract workFor contractorsWork experience placementWork at officeLocal areaFlexible hours- ...their ship specification sections and first tier references iso interpretation of technical... ...and engineering submittals, providing assessments of issues/recommendations (with inputs from... ...the HR Service Desk at (***) ***-****, option 1. Please note, due to EEOC/OFCCP...Full timeContract workPart timeLocal areaImmediate startFlexible hours
$135k - $185k
...Maintain system authorization packages and manage POA&Ms.Conduct vulnerability scanning and review Nessus findings.Support RMF activities... ..., such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification...Full timeContract workLocal areaNight shift$99k - $225k
...) or Information System Security Analyst (ISSA)Experience conducting tools assessments and configuration analysis against... ..., or Master’s degree and 1+ years of experience supporting... ...capabilities topologies, CONOPS, and vulnerability scans to assess riskExperience with...Full timeContract workPart timeFor subcontractorWork at officeLocal areaRemote work- ...decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating... ...and support the documentation, validation, assessment, and accreditation processes necessary to... ...projects and activities ~ Master's degree and 1+ years of experience supporting IT...Remote workFlexible hours
$150k - $195k
...for performing basic reconnaissance and vulnerability scanning in accordance with established testing... ...experience as described in Table A.5.5.1.Do you have what it takes?Requirements:... ...CompTIA Pen Test+• CompTIA Cybersecurity Analyst (CySA+)• Certified Hacking Forensic...Work experience placement$86.8k - $198k
...TesterThe Opportunity:Conduct testing and analysis to identify vulnerabilities and potential threat vectors in systems and networks,... ...fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity...Full timeContract workPart timeWork at officeLocal areaRemote work$140.25k - $233.45k
...directives are enforced to support assessment, authorization and continued... ...environments, threats, vulnerabilities and internal interfaces to define... ...: ~ Successfully completed Tier 5 Investigation (T5),... ...program award Shift: Shift 1 (United States of America) Stay...Permanent employmentFull timeRelocationVisa sponsorshipWork visaFlexible hoursShift work$160.2k - $195.8k
...requirements are integrated throughout the system lifecycle Develop and maintain security documentation and compliance artifacts Assess system risks and recommend mitigation strategies Provide cybersecurity guidance to engineers and non-technical partners...Temporary workLocal areaRelocation packageFlexible hours- ...operations, cyber defense and resiliency, vulnerability research, ubiquitous technical... ...analysis and remediation.Assist in risk assessments and develop effective mitigation countermeasures... ...CloudWatchDesired Certifications:DoD 8570.1 IAT Level IICSSLP (Certified Secure...Full timeLocal area
- ...(ICD) 503 and associated NIST publications. Preparation of Assessment and Authorization (A&A) documents and procedures. Interface... ...~ Familiarization with NIST Special Publication 800-37 Revision 1, Guide for Applying the Risk Management Framework to Federal Information...Contract workTemporary workWorldwideFlexible hours
- ...you're passionate about offensive cybersecurity, identifying vulnerabilities before adversaries do, and protecting national security... ...As a Penetration Tester, you will perform technical security assessments against customer systems in support of certification, accreditation...
$5,000 per month
...Responsibilities Responsible for performing basic reconnaissance and vulnerability scanning in accordance with established testing methodologies... ...and staying abreast of emerging threats Pen Tester, Level 1 (Junior) Functional Description: Responsible for performing...Contract workTemporary workFor contractorsImmediate startFlexible hours- ...Corporation is seeking a Senior Social Network Analyst to support The Defense Intelligence Agency... ...START: TBDPERIOD OF PERFORMANCE: 1 Base Year + 4 Option YearsLOCATION: DIA Facilities... ...social network analysis techniques.· Assesses opportunities to disrupt or degrade networks...Local area
$112k - $179k
...understanding of NIST SP 800-53 controls, STIG implementation, vulnerability analysis, and the ability to produce assessable, audit-ready security documentation.The ideal... ...RMF & Security LifecycleLead and support RMF Steps 1-6 for assigned systems.Manage, validate, and...Contract workShift work$108k - $170k
...expertise to support information systems security, security control assessments, information assurance engineering, and security control... ...partners;l. Ability to effectively provide ISSO guidance to Level 1 and Level 2 ISSOs.Required Clearance:TS/SCI/ with Poly (#tssci)...Contract workTemporary workFor contractorsWork at officeLocal areaRelocation
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Tier 1 - Vulnerability Assessment Analyst. Be the first to apply!


