Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Tier 1 - Vulnerability Assessment Analyst

$69.55k - $125.73k

Leidos

Department of Homeland Security (DHS), Customs and Border Protection (CBP) Security Operations Center (SOC) is a US Government program responsible to prevent, identify, contain and eradicate cyber threats to CBP networks through monitoring, intrusion detection and protective security services to CBP information systems including local area networks/wide area networks (LAN/WAN), commercial Internet connection, public facing websites, wireless, mobile/cellular, cloud, security devices, servers and workstations. The CBP SOC is responsible for the overall security of CBP Enterprise-wide information systems, and collects, investigates, and reports any suspected and confirmed security violations.

The DHS CBP SOC Program has a critical need for a

Tier 1 Vulnerability Assessor

to join our VAT program This position will provide Vulnerability Assessment support to the United States Department of Homeland Security, focused on performing vulnerability scans of enterprise IT assets utilizing the approved scanning infrastructure. Additional responsibilities include performing research and analyzing current threats and vulnerabilities that may affect the enterprise, writing security advisories, and participating as team member performing focused adversarial assessments. Primary responsibilities include: Perform research on current threats and vulnerabilities and analyze security posture of the enterprise. - Author security advisories Manage enterprise vulnerability compliance, CISA Binding Operational Directives, CISA Emergency Directives, ISVM. Present vulnerability scan information to leadership, auditors, system engineers, etc. Basic Qualifications: All Department of Homeland Security CBP SOC employees are required to favorably pass a 5-year (BI) Background Investigation. Bachelors’ degree in Computer Science, Engineering, Information Technology, Cyber Security, or related field and 2+ years of related experience. Additional years of experience and cyber certifications may be considered in lieu of degree. Familiar with the management, operational, and technical aspects of IT Security in a complex enterprise environment. Familiarity with CVE’s, Current vulnerabilities, Technology Standards and Controls. Experience with in-depth analysis of vulnerabilities and troubleshooting scan issues. Strong familiarity with STIGs and STIG compliance scanning. Should have at least one of the following certifications: SANS GIAC: GCED, GCIA, GCFA, GPEN, GWAPT, GCFE, GREM, GXPN, GMON or GCIH ISC2 CCFP, CCSP, CISSP CERT CSIH EC Council: CHFI, LPT, ECSA, Offensive Security: OSCP, OSCE, OSWP and OSEE EnCase: EnCE Dod 8570: IAT L3, CNDSP Analyst or IR Carnegie Mellon: CCSIH" Preferred Qualifications: Experience in cyber government, and/or federal law enforcement. Experience in Vulnerability scanning and analysis. Experience in financial, CSP and FISMA audits. Experience with Database (DBPro), Web application (WebInspect), OS (Tenable) scanning and Splunk queries If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares. Original Posting:

September 21, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above. Pay Range:

Pay Range $69,550.00 - $125,725.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
Vacancy posted 3 hours ago
Similar jobs that could be interesting for youBased on the Tier 1 - Vulnerability Assessment Analyst in Ashburn, VA vacancy
  • DescriptionSAIC is seeking a Principal Cyber Security Cloud Analyst, to serve as a member of a Vulnerability Assessment program. This position is located in Chantilly, VA and requires an active TS/SCI with Polygraph.The hired individual will perform the following key roles... 
    Suggested

    Science Applications International Corporation

    Chantilly, Loudoun County, VA
    22 hours ago
  • $120.8k - $265.8k

     ...Management Framework (RMF) activities (Steps 1-6), assisting Information System...  ...Security Documentation: Develop and maintain Assessment & Authorization (A&A) documentation,...  ...security weaknesses, deficiencies, and/or vulnerabilities in the design - evaluating designs for... 
    Suggested
    Contract work
    Work experience placement
    Local area
    Immediate start
    Flexible hours

    CACI International

    Sterling, VA
    1 day ago
  • $122k - $253k

     ...operations, cyber defense and resiliency, vulnerability research, ubiquitous technical...  ...Nightwing is seeking an Cyber Network Forensic Analyst to support this critical customer...  ...analyses anomalous network activity - Assesses network topology and device configurations... 
    Suggested
    Contract work
    Immediate start

    Nightwing

    Sterling, VA
    3 hours ago
  •  ...operations, cyber defense and resiliency, vulnerability research, ubiquitous technical...  ...Demonstrated on-the-job experience conducting assessments of existing IT architecture for compliance...  ...frameworkCertifications (not required but encouraged):1. Certified Information Systems Security... 
    Suggested
    Full time

    Nightwing

    Sterling, VA
    2 days ago
  • $140k - $190k

     ...than the title suggests. What Success Looks Like Objective 1: Close security findings at their cause rather than at the ticket...  ...an answer that is current rather than an answer from the last assessment. What is recorded as implemented matches what is running.... 
    Suggested
    Temporary work
    Immediate start
    Remote work
    Relocation package
    Day shift

    Agile Defense

    Reston, VA
    25 days ago
  •  ...supporting federal agencies with IT controls assessments and program evaluations. This is an...  ...SOPs, audit logs, configuration scans, and vulnerability scansEvaluating the implementation and...  ...please contact Guidehouse Recruiting at 1-(***) ***-**** or via email at... 
    Full time
    Flexible hours

    Guidehouse

    Chantilly, Loudoun County, VA
    3 days ago
  • $107.9k - $195.05k

     ...Management and Application Security Logging and Vulnerability Management :Ensure continuous monitoring...  ...security issues.Conduct security assessments using Microfocus WebInspect and other...  ...week.Preferred QualificationsMaster’s with 1-2 years of prior experience in... 
    Full time
    Work at office
    Local area

    Leidos

    Ashburn, VA
    1 day ago
  •  ...activities associated with event collection tier solutions. Normalize and correlate such...  ...work must be done in the US.  This is a 1-2 days per week onsite role in Herndon, VA...  ...reviewing applications, analyzing resumes, or assessing responses and identifying potential... 
    Contract work
    Temporary work
    2 days per week
    1 day per week

    UltraViolet Cyber

    Herndon, VA
    28 days ago
  •  ...knowledge Liaise with business analysts to develop feasible,...  ...releases Review Cybersecurity Assessments and Static Code Analysis to define...  ...Understanding of software security vulnerabilities and mitigation strategies...  ...an on-site requirement of 1-2 days a week in Ashburn, VA... 
    2 days per week
    1 day per week

    Jobtailor

    Ashburn, VA
    3 days ago
  • $94.4k - $198.3k

     ...171, DHS 4300A, CBP Handbook 1400-05D Assess entire system lifecycle requirements and...  ...environment Enhance - Implement Cybersecurity vulnerability/A&A hardening testing Optimize -...  ...~3-year check for felony convictions ~1-year check for illegal drug use ~1-year... 
    Full time
    Contract work
    Work experience placement
    Local area
    Flexible hours

    CACI

    Ashburn, VA
    6 days ago
  •  ...portfolio.Core ResponsibilitiesManage the Assessment and Authorization (A&A) lifecycle for...  ...document continuous monitoring (ConMon) and vulnerability management across assigned classified...  ...Secret clearance (with current SSBI or Tier 5 investigation).Minimum of 3 years of experience... 
    For contractors

    Metron

    Reston, VA
    2 days ago
  • $82.3k - $220k

     ...controlling changes to the system, and assessing the security impact of those changes.Job...  ...ISSM for review.• Mentors and coaches ISSO 1.• Performs other duties as assigned....  ...NIST SP 800-53, JSIG, DAAG, ICD 503), IR, Vulnerability Management, SCAP, STIG, and Security-... 
    Full time
    Local area

    Draper Laboratory

    Reston, VA
    2 days ago
  • $100k - $140k

     ...security controls including audit log reviews, system compliance assessments, vulnerability scans, and account activity for privileged and general users...  ...assistanceWhat required background will make you successful?1-3 years of ISSO and/or System Administration... 
    Full time
    Temporary work
    For contractors
    Work at office
    Local area
    Remote work
    Flexible hours

    Rincon Research

    Chantilly, Loudoun County, VA
    4 days ago
  • $98.1k - $115k

     ...information systems security, security control assessments, information assurance engineering, and...  ...audits and assessments to identify vulnerabilities and risks.Monitoring network traffic for...  ...) (#polygraph)Required Qualifications:1. Hands on Experience with the RMF Process... 
    Contract work
    Temporary work
    For contractors
    Work at office
    Local area
    Relocation

    AT&T

    Chantilly, Loudoun County, VA
    2 days ago
  • $103.8k - $218.1k

     ...boundaries, hardware and software lists, risk assessment reports, POA&Ms, data flows, and other...  .... Familiarity with the use of vulnerability scanning and assessment tools (e.g., ACAS...  ...been designated as requiring IAM Level 1 CWIP certification and requires one of... 
    Contract work
    For contractors
    Work experience placement
    Work at office
    Local area
    Flexible hours

    CACI International

    Chantilly, Loudoun County, VA
    1 day ago
  •  ...their ship specification sections and first tier references iso interpretation of technical...  ...and engineering submittals, providing assessments of issues/recommendations (with inputs from...  ...the HR Service Desk at (***) ***-****, option 1. Please note, due to EEOC/OFCCP... 
    Full time
    Contract work
    Part time
    Local area
    Immediate start
    Flexible hours

    Serco

    Sterling, VA
    1 day ago
  • $135k - $185k

     ...Maintain system authorization packages and manage POA&Ms.Conduct vulnerability scanning and review Nessus findings.Support RMF activities...  ..., such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification... 
    Full time
    Contract work
    Local area
    Night shift

    Computer World Services (CWS)Corporation

    Ashburn, VA
    22 hours ago
  • $99k - $225k

     ...) or Information System Security Analyst (ISSA)Experience conducting tools assessments and configuration analysis against...  ..., or Master’s degree and 1+ years of experience supporting...  ...capabilities topologies, CONOPS, and vulnerability scans to assess riskExperience with... 
    Full time
    Contract work
    Part time
    For subcontractor
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Reston, VA
    4 days ago
  •  ...decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating...  ...and support the documentation, validation, assessment, and accreditation processes necessary to...  ...projects and activities ~ Master's degree and 1+ years of experience supporting IT... 
    Remote work
    Flexible hours

    GuidePoint Security

    Reston, VA
    22 hours ago
  • $150k - $195k

     ...for performing basic reconnaissance and vulnerability scanning in accordance with established testing...  ...experience as described in Table A.5.5.1.Do you have what it takes?Requirements:...  ...CompTIA Pen Test+• CompTIA Cybersecurity Analyst (CySA+)• Certified Hacking Forensic... 
    Work experience placement

    VTG

    Chantilly, Loudoun County, VA
    1 day ago
  • $86.8k - $198k

     ...TesterThe Opportunity:Conduct testing and analysis to identify vulnerabilities and potential threat vectors in systems and networks,...  ...fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Herndon, VA
    3 days ago
  • $140.25k - $233.45k

     ...directives are enforced to support assessment, authorization and continued...  ...environments, threats, vulnerabilities and internal interfaces to define...  ...: ~ Successfully completed Tier 5 Investigation (T5),...  ...program award Shift: Shift 1 (United States of America) Stay... 
    Permanent employment
    Full time
    Relocation
    Visa sponsorship
    Work visa
    Flexible hours
    Shift work

    Boeing

    Herndon, VA
    1 day ago
  • $160.2k - $195.8k

     ...requirements are integrated throughout the system lifecycle Develop and maintain security documentation and compliance artifacts Assess system risks and recommend mitigation strategies Provide cybersecurity guidance to engineers and non-technical partners... 
    Temporary work
    Local area
    Relocation package
    Flexible hours

    KBR

    Sterling, VA
    3 days ago
  •  ...operations, cyber defense and resiliency, vulnerability research, ubiquitous technical...  ...analysis and remediation.Assist in risk assessments and develop effective mitigation countermeasures...  ...CloudWatchDesired Certifications:DoD 8570.1 IAT Level IICSSLP (Certified Secure... 
    Full time
    Local area

    Nightwing

    Sterling, VA
    2 days ago
  •  ...(ICD) 503 and associated NIST publications. Preparation of Assessment and Authorization (A&A) documents and procedures. Interface...  ...~ Familiarization with NIST Special Publication 800-37 Revision 1, Guide for Applying the Risk Management Framework to Federal Information... 
    Contract work
    Temporary work
    Worldwide
    Flexible hours

    Excelity

    Reston, VA
    3 days ago
  •  ...you're passionate about offensive cybersecurity, identifying vulnerabilities before adversaries do, and protecting national security...  ...As a Penetration Tester, you will perform technical security assessments against customer systems in support of certification, accreditation... 

    WarCollar Industries

    Herndon, VA
    22 hours ago
  • $5,000 per month

     ...Responsibilities Responsible for performing basic reconnaissance and vulnerability scanning in accordance with established testing methodologies...  ...and staying abreast of emerging threats Pen Tester, Level 1 (Junior) Functional Description: Responsible for performing... 
    Contract work
    Temporary work
    For contractors
    Immediate start
    Flexible hours

    LV8D Solutions

    Chantilly, Loudoun County, VA
    4 days ago
  •  ...Corporation is seeking a Senior Social Network Analyst to support The Defense Intelligence Agency...  ...START: TBDPERIOD OF PERFORMANCE: 1 Base Year + 4 Option YearsLOCATION: DIA Facilities...  ...social network analysis techniques.· Assesses opportunities to disrupt or degrade networks... 
    Local area

    Celestar

    Reston, VA
    22 hours ago
  • $112k - $179k

     ...understanding of NIST SP 800-53 controls, STIG implementation, vulnerability analysis, and the ability to produce assessable, audit-ready security documentation.The ideal...  ...RMF & Security LifecycleLead and support RMF Steps 1-6 for assigned systems.Manage, validate, and... 
    Contract work
    Shift work

    Peraton Corporation

    Herndon, VA
    22 hours ago
  • $108k - $170k

     ...expertise to support information systems security, security control assessments, information assurance engineering, and security control...  ...partners;l. Ability to effectively provide ISSO guidance to Level 1 and Level 2 ISSOs.Required Clearance:TS/SCI/ with Poly (#tssci)... 
    Contract work
    Temporary work
    For contractors
    Work at office
    Local area
    Relocation

    AT&T

    Chantilly, Loudoun County, VA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Tier 1 - Vulnerability Assessment Analyst. Be the first to apply!