Vulnerability Management Analyst
Dane
Benefits:
Life/STD/LTD
FSA/DCA
401(k)
Employee discounts
Paid time off
401(k) matching
Dental insurance
Health insurance
Tuition assistance
Vision insurance
Description
Looking for a place that invests in you from day one? At DANE, we offer aggressive PTO, strong benefits, and ongoing learning opportunities, backed by a culture that values and supports our team.
We are seeking a Vulnerability Management Analyst (Tenable/Nessus & Metrics) to support vulnerability tracking, remediation coordination, and security metrics reporting in a federal technology environment. This is a junior-level role (1–3 years of experience) focused on execution and coordination, working hands-on with Tenable/Nessus, iPost, Power BI, Excel, and ticketing systems to ensure that vulnerability data is accurate, actionable, and reportable.
Details:
Location: Hybrid - Onsite, Arlington, VA,1 day/week and as needed Job Type: Full Time Education: Minimum of a Bachelor’s degree in computer science or Equivalent Experience: Minimum 1 year of relevant experience Clearance: Must hold an Active DoD Secret Clearance or higher
Responsibilities
Run authorized Tenable/Nessus scans using credentialed scan profiles and review exports to identify CVEs, plugin findings, KEV status, EOL/EOS software risks, and affected assets.
Validate findings as true or false positives, track vulnerability age using first-seen/last-seen dates, and escalate unresolved findings to senior security staff or system owners.
Support the full vulnerability lifecycle from intake and triage through ownership assignment, remediation tracking, retest/rescan validation, and closure evidence collection.
Monitor KEV and Critical/High findings against federal remediation timelines (e.g., BOD 22-01) and flag aging, stale, or blocked findings for escalation.
Build and maintain Power BI dashboards and Excel reports covering vulnerability posture, patch compliance, KEV status, finding aging, and ownership tracking using Power Query, slicers, and basic DAX measures.
Produce recurring deliverables, including Critical/High aging reports, Tenable/iPost reconciliation summaries, EOL/EOS tracking, and executive snapshots; document KPI definitions and data sources.
Reconcile vulnerability data across Tenable/Nessus, iPost, ServiceNow/CA ServiceDesk, Jira, SharePoint, POA&M trackers, and Excel exports to identify mismatches and coverage gaps.
Coordinate with security, development, infrastructure, database, and cloud teams and ISSO stakeholders to drive remediation through closure.
Requirements
1–3 years of experience in cybersecurity operations, vulnerability management, SOC, cyber GRC, IT operations, or application security support; working knowledge of CVE, CVSS, KEV, false positives, POA&M tracking, risk acceptance, and vulnerability aging.
Hands-on Tenable/Nessus experience: executing credentialed scans, analyzing plugin output and CVE findings, validating true/false positives, and building dashboards, saved filters, and exports for KEV, Critical/High, EOL/EOS, and aging tracking.
Intermediate Power BI (Power Query, data modeling, DAX, slicers) and strong Excel skills (pivot tables, VLOOKUP/XLOOKUP, conditional formatting, deduplication) for vulnerability reporting and KPI tracking.
Experience with iPost, ServiceNow, CA ServiceDesk, Jira, or SharePoint for remediation tracking; ability to reconcile data across multiple tools, identify mismatches, and maintain accurate ownership and evidence records.
Familiarity with EOL/EOS software tracking, patch compliance, remediation exceptions, risk acceptance documentation, and closure evidence collection.
Strong attention to detail, comfort working with large and messy datasets, and clear communication skills for translating technical findings into plain-language updates for leadership and non-technical stakeholders.
Preferred Qualifications
Experience supporting federal cybersecurity programs or regulated environments; familiarity with NIST SP 800-53, RMF, A&A, ATO, POA&M lifecycle management, CISA BOD 22-01, and FedRAMP vulnerability requirements.
Exposure to DevSecOps and application security tooling: SAST, DAST, SCA, container image scanning, secrets scanning, or Software Bill of Materials (SBOM) analysis.
Basic understanding of enterprise patching for Windows Server, Windows workstations, .NET Framework, Java JRE, SQL Server, and endpoint agents; familiarity with Splunk or other SIEM platforms.
Experience developing SOPs, RACI matrices, or workflow documentation in a security or IT operations context.
Relevant certifications such as CompTIA Security+, CySA+, CEH, or equivalent entry-to-mid-level cybersecurity credentials.
DANE LLC is an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Flexible work from home options available.
- Mission Technologies, a division of HII, is looking for a skilled professional in vulnerability management in Fairfax, Virginia. The successful candidate will support Department of Defense cybersecurity efforts, ensure accuracy in vulnerability assessments, and maintain...Suggested
- ...Overview Position Title: Senior Business Operations & Financial Management Analyst Location: Chantilly, VA Clearance Requirement: Active Top Secret with SCI eligibility U.S. Citizenship required OMNI Consulting Solutions is seeking a Senior Business Operations & Financial...SuggestedWork at office
- ...documentation is developed, maintained, reviewed, and updated on a continuous basis; Conduct required IS vulnerability scans according to risk assessment parameters Manage the risks to ISs and other FBI assets by coordinating appropriate correction or mitigation actions...SuggestedWork at office
$86.6k - $181.8k
The Information Technology Service Management (ITSM) Service Catalog/Request Fulfillment Process Analyst supports the design, deployment, and operations of IT Infrastructure based processes. The Process Analyst supports the deployment of process and procedures working with...SuggestedWork experience placementFlexible hours$100k - $130k
Employment Type Full-time Signal Hill Technologies is seeking a highly skilled Vulnerability Analyst to support our federal client's vulnerability management program. The position is contingent upon contract award and is anticipated as full-time/permanent. This role is...SuggestedPermanent employmentFull timeContract workWork at officeLocal area$45k - $65k
Blu Omega LLC seeks a Junior Vulnerability Analyst to support the NIH cybersecurity operations center. This remote role is responsible for assessing and mitigating cybersecurity vulnerabilities in critical healthcare and federal systems. Candidates should demonstrate a...Remote job- ...and customer-oriented Cyber Security Analyst to join our team in Chantilly, VA .... ...security reports. Advising management of security risks. Perform required... ...Qualifications: Knowledge of system vulnerability analysis and security testing. Strong...Internship
- ...Digital Forensic Analyst Employment Type: Full-Time, Mid-Level Department: Forensics CGS is seeking a Digital Forensic Analyst whose... ...updates and new options in the market Work closely with project management and other team members on completing complex projects in a...Full timeWork at officeRemote workFlexible hours
$176k - $282k
...Responsibilities The Digital Forensic Analyst will conduct research, evaluate system configuration data, and provide recommendations... ...team to implement changes to mitigate potential weaknesses/vulnerabilities. Additionally, the Digital Forensic Analyst will: Perform network...Contract workShift work- ...Description Seeking a Digital Forensics Analyst, to serve as a member of an organizational cybersecurity program. This position requires an active TS/SCI with Polygraph. Key Responsibilities Conduct forensic acquisition and analysis on computer, mobile, IOT, digital media...Work experience placement
- ...an experienced ICAM ISSO (Identity, Credential, and Access Management Information System Security Officer) to support critical cybersecurity... ...functioning as intended. Identify and document system vulnerabilities and risks, coordinating remediation efforts and tracking...Local areaFlexible hours
- ...account/access reviews for compliance with security policy. Monitor system security posture and support continuous monitoring and vulnerability scanning activities. Maintain and update system security documentation, including SSPs, POA&Ms, and configuration records....
$103.8k - $218.1k
...enterprise ITSM solution, enterprise service desk, endpoint management and security solution, as well as CONUS/OCONUS field support... ...protective and corrective measures when a security incident or vulnerability is discovered, with the approval of the ISSM or System Owner....Full timeContract workWork experience placementLocal areaFlexible hours$130k - $150k
...with detecting and preventing computer security compromises in a networked environment. Working knowledge of configuration management; system maintenance; and integration testing. Proficient in the use of tools used to prevent and/or negate malicious code....Civilian ContractorFor contractorsWork experience placementWork at office$110k - $180k
...candidate will have demonstrated experience working the Risk Management Framework with Department of Defense (DOD) and Intelligence Community... ...are established and followed. The position will perform vulnerability/risk assessment and configuration management to support...Contract workFor contractorsImmediate start- ...Degree in a related field or an advanced degree in Cybersecurity with 5+ years of experience in within information security or risk management supporting multi-domain SAP or SCI environments. Certifications: The ISSO shall possess an active technical certification...Temporary workWork at office
- ...Litigation Systems Analyst Employment Type: Full Time, Mid-level CGS is seeking a Systems Analyst to join our team supporting a wide-... ...Government staff and/or under the direction of the Contract IT Manager, Systems Manager, Senior Systems Analyst, or Lead Project Manager...Full timeContract workFor contractorsWork at officeFlexible hours
- ...cycle Assessment and Authorization (A&A) management through all 6 Steps of the RMF process... ...and recommend improvements to amend vulnerabilities, implement changes, and document upgrades... ...experience as an Information Assurance (IA) Analyst, ISSE, ISSO, or similar role in ATO...Full timeLocal areaFlexible hours
$100k - $140k
...engineers, visitors, system administrators, security staff, program managers, and local vendors and inspectors. This position requires an... ...including audit log reviews, system compliance assessments, vulnerability scans, and account activity for privileged and general users....Full timeTemporary workFor contractorsWork at officeLocal areaImmediate startRemote workFlexible hours- ...compliance with security policies, and managing risk through the implementation of robust... ...security assessments, monitor for vulnerabilities, and respond to potential threats. The... ...SIMILAR CAREER TITLES Cybersecurity Analyst, Information Security Specialist, Security...Temporary workFor contractorsImmediate startFlexible hours
$135k - $170k
...policy architecture across SPA's information systems. The team manages cyber policy, develops control implementations and system... ...supervision Desired Qualifications: ~ Experience performing Vulnerability Management activities and validating system compliance using...Work experience placementImmediate startFlexible hours$5,000 per month
...Security interface to government customer and Accrediting Authorities. Perform vulnerability/risk assessments to support authorization and accreditation. Prepare and review Risk Management Framework (RMF) documentation to include System Security Plans (SSPs),...Civilian ContractorContract workTemporary workFor contractorsWork at officeImmediate startFlexible hours$140k - $160k
...Security Officer (ISSO) to lead a collaborative team to develop, manage, and maintain information system security Assessment and... ...activities, consisting of periodic reviews of controls, audits, vulnerability scans, and penetration test reports. Develop and maintain POA&...Full timeFor contractorsFlexible hours- ...Senior Systems Analyst Employment Type: Full Time, Senior-level Department: Information Technology CGS is seeking a Senior Systems Analyst... ...for a large Federal agency. Responsibilities Develop, manage, and document a workflow process to identify, archive, and delete...Full timeContract workFor contractorsWork at officeFlexible hours
- ...Driving Customer Experience Excellence Pohanka Automotive Group is looking for a driven, people-first Service Business Development Manager (BDC Manager) to lead and elevate our customer engagement operations. In this role, you’ll coach and inspire a high-performing BDC...Local area
$190k - $210k
...Senior Business Development Manager Amentum is seeking a Senior Business Development (BD) professional in the Intelligence and Cyber Business Group to accelerate Amentum's growth within a classified Northern Virginia customer. Candidates for this key position must have...Hourly payContract workTemporary work- ...We are seeking a dedicated and experienced Business Development Manager to oversee the daily operations and drive growth at our Mental Health Practice. The Business Development Manager performs many leadership, organizational and decision‑making tasks in planning, guiding...For contractors
- ...Centurion is seeking a Senior Manager, Business Development to accelerate our Client's growth within the National Defense and Intelligence Communities; specifically, the National Geospatial-Intelligence Agency (NGA) and National Reconnaissance Office (NRO). The successful...Contract workTemporary workWork at office
$113.2k - $237.8k
Job Title: Cyber Security Analyst Job Category: Engineering Time Type: Full time Minimum Clearance Required to Start... ...career network. We are a fun, engaging environment with a management team focused on growing your career and making you a part of...Full timeContract workWork experience placementLocal areaImmediate startFlexible hours- ...capabilities across data science, data engineering, software engineering, AI solutions, cybersecurity, staff augmentation, and IT program management. We thrive at the intersection of mission, technology, and innovation. Passionate Integrity, Driven by Excellence At Ardent...Full time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vulnerability Management Analyst. Be the first to apply!
- business analyst law firm Chantilly, Loudoun County, VA
- analytics business analyst Chantilly, Loudoun County, VA
- business analyst Chantilly, Loudoun County, VA
- business strategy analyst Chantilly, Loudoun County, VA
- pega business analyst Chantilly, Loudoun County, VA
- deloitte business technology analyst Chantilly, Loudoun County, VA
- management analyst Chantilly, Loudoun County, VA
- senior data management analyst Chantilly, Loudoun County, VA
- senior business analyst contract Chantilly, Loudoun County, VA
- remote senior business analyst Chantilly, Loudoun County, VA



