Vulnerability Management Analyst
Dane
Benefits:
Life/STD/LTD
FSA/DCA
401(k)
Employee discounts
Paid time off
401(k) matching
Dental insurance
Health insurance
Tuition assistance
Vision insurance
Description
Looking for a place that invests in you from day one? At DANE, we offer aggressive PTO, strong benefits, and ongoing learning opportunities, backed by a culture that values and supports our team.
We are seeking a Vulnerability Management Analyst (Tenable/Nessus & Metrics) to support vulnerability tracking, remediation coordination, and security metrics reporting in a federal technology environment. This is a junior-level role (1–3 years of experience) focused on execution and coordination, working hands-on with Tenable/Nessus, iPost, Power BI, Excel, and ticketing systems to ensure that vulnerability data is accurate, actionable, and reportable.
Details:
Location: Hybrid - Onsite, Arlington, VA,1 day/week and as needed Job Type: Full Time Education: Minimum of a Bachelor’s degree in computer science or Equivalent Experience: Minimum 1 year of relevant experience Clearance: Must hold an Active DoD Secret Clearance or higher
Responsibilities
Run authorized Tenable/Nessus scans using credentialed scan profiles and review exports to identify CVEs, plugin findings, KEV status, EOL/EOS software risks, and affected assets.
Validate findings as true or false positives, track vulnerability age using first-seen/last-seen dates, and escalate unresolved findings to senior security staff or system owners.
Support the full vulnerability lifecycle from intake and triage through ownership assignment, remediation tracking, retest/rescan validation, and closure evidence collection.
Monitor KEV and Critical/High findings against federal remediation timelines (e.g., BOD 22-01) and flag aging, stale, or blocked findings for escalation.
Build and maintain Power BI dashboards and Excel reports covering vulnerability posture, patch compliance, KEV status, finding aging, and ownership tracking using Power Query, slicers, and basic DAX measures.
Produce recurring deliverables, including Critical/High aging reports, Tenable/iPost reconciliation summaries, EOL/EOS tracking, and executive snapshots; document KPI definitions and data sources.
Reconcile vulnerability data across Tenable/Nessus, iPost, ServiceNow/CA ServiceDesk, Jira, SharePoint, POA&M trackers, and Excel exports to identify mismatches and coverage gaps.
Coordinate with security, development, infrastructure, database, and cloud teams and ISSO stakeholders to drive remediation through closure.
Requirements
1–3 years of experience in cybersecurity operations, vulnerability management, SOC, cyber GRC, IT operations, or application security support; working knowledge of CVE, CVSS, KEV, false positives, POA&M tracking, risk acceptance, and vulnerability aging.
Hands-on Tenable/Nessus experience: executing credentialed scans, analyzing plugin output and CVE findings, validating true/false positives, and building dashboards, saved filters, and exports for KEV, Critical/High, EOL/EOS, and aging tracking.
Intermediate Power BI (Power Query, data modeling, DAX, slicers) and strong Excel skills (pivot tables, VLOOKUP/XLOOKUP, conditional formatting, deduplication) for vulnerability reporting and KPI tracking.
Experience with iPost, ServiceNow, CA ServiceDesk, Jira, or SharePoint for remediation tracking; ability to reconcile data across multiple tools, identify mismatches, and maintain accurate ownership and evidence records.
Familiarity with EOL/EOS software tracking, patch compliance, remediation exceptions, risk acceptance documentation, and closure evidence collection.
Strong attention to detail, comfort working with large and messy datasets, and clear communication skills for translating technical findings into plain-language updates for leadership and non-technical stakeholders.
Preferred Qualifications
Experience supporting federal cybersecurity programs or regulated environments; familiarity with NIST SP 800-53, RMF, A&A, ATO, POA&M lifecycle management, CISA BOD 22-01, and FedRAMP vulnerability requirements.
Exposure to DevSecOps and application security tooling: SAST, DAST, SCA, container image scanning, secrets scanning, or Software Bill of Materials (SBOM) analysis.
Basic understanding of enterprise patching for Windows Server, Windows workstations, .NET Framework, Java JRE, SQL Server, and endpoint agents; familiarity with Splunk or other SIEM platforms.
Experience developing SOPs, RACI matrices, or workflow documentation in a security or IT operations context.
Relevant certifications such as CompTIA Security+, CySA+, CEH, or equivalent entry-to-mid-level cybersecurity credentials.
DANE LLC is an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Flexible work from home options available.
- ...Vulnerability Management Analyst ID 2025-3164 Job Locations US Category Information Technology Type Regular Full-Time Overview DecisionPoint seeks a Vulnerability Management Analyst to support enterprise cybersecurity...SuggestedFull timeContract workFor contractorsLocal areaRemote work
$200k
...Job Description Job Description Overview Senior Business Operations & Financial Management Analyst LOCATION: Chantilly, VA JOB STATUS: Full-time CLEARANCE: Active DoD Top Secret security clearance with SCI eligibility and Poly required. U.S. citizenship...SuggestedFull timeWork at office- ...Position Title: Senior Business Operations & Financial Management Analyst Location: Chantilly, VA Clearance Requirement: Active Top Secret with SCI eligibility U.S. Citizenship required OMNI Consulting Solutions is seeking a Senior Business Operations &...SuggestedFull timeWork at office
$150k - $195k
...for performing basic reconnaissance and vulnerability scanning in accordance with established... ...efforts; collaborating with management to develop security policies, training... ...CompTIA Pen Test+ * CompTIA Cybersecurity Analyst (CySA+) * Certified Hacking Forensic...SuggestedWork experience placement- ...not meet these requirements will not be considered. Responsibilities: Responsible for performing basic reconnaissance and vulnerability scanning in accordance with established testing methodologies Identifies common vulnerabilities that can be potentially...SuggestedWork experience placement
$90k - $130k
...both active and passive capabilities to expose and exploit IA vulnerabilities. Review and evaluate information systems and recommend... ..., program design and implementation, configuration management, system maintenance, integration testing, Information system...Work experience placement- ...perform duties as the alternate Information Systems Security Manager (ISSM). Cyber security paperwork (compliance) and Information... ...policies, controls and procedures and mitigate identified vulnerability and weaknesses Ability to work well in a team environment and...InternshipWork at office
- ...Health Information Management (HIM) Analyst Epic HIM / Solventum / Payor Platform Location: Chantilly, Virginia, United States Employment Type: Full-Time Job Summary: We are seeking a detail-oriented Health Information Management (HIM) Analyst with experience...Full time
- Earned Value Management (EVM)/Integrated Performance Management (IPM) Analyst – SME Level – TS/SCI Clearance w/CI Poly Required Location Chantilly, VA Job Description Leffler Consulting is seeking a seasoned Earned Value Management (EVM)/Integrated Performance Management...For contractorsWork experience placementWork at office
- ...software engineering, AI solutions, cybersecurity, and IT program management. We thrive at the intersection of mission, technology, and... ...security groups and organizations Communicating vulnerability results and risk posture to senior executives Performing complex...Full timeWork experience placement
- ...administering SolarWinds alongside deep knowledge of Microsoft Windows Systems, HP SANs, and VMware products Advanced experience managing VPNs, GRE tunnels, routing protocols (BGP E/I, OSPF), VLANs, VRFs, and configuring KGs Strong familiarity with Cisco ACI, data...Work at office
$79.6k - $172.4k
Business Program and Project Management Analyst TS/SCI with Poly REQUIRED Position Description CGI Federal is seeking candidates for Business Program and Project Management Analyst positions supporting a USG agency in Northern Virginia. Successful candidates will...Work at officeLocal areaShift work$79.6k - $172.4k
Business Program & Project Management Analyst TS/SCI with Poly REQUIRED Position Description CGI Federal is seeking candidates for Business Program & Project Management Analyst positions supporting a USG agency in Northern Virginia. Successful candidates will assist...Local area$100k - $140k
...ability to remain in a stationary position 50% of the time. You may need to move about the office to access file cabinets, office machinery, or communicate with colleagues, management, and clients, which may involve delivering presentations. last updated 36 week of 2026...Full timeWork at office$27.63 per hour
...Computer Systems Analyst Join our dynamic team as a Computer Systems Analyst and play a crucial role in supporting our fast-paced... ...growth. Responsibilities: Ability to prioritize tasks and manage time effectively in a fast-paced environment. Provide timely...Hourly payMinimum wageContract workWork experience placementWork at officeRemote workFlexible hours- ...Systems Analyst LOCATION Chantilly, VA 20151 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.... ...Engineering, Data Science, Cybersecurity, Operations Research, Management Information Systems, etc. ALTERNATE EXPERIENCE General...Temporary workFor contractorsImmediate startFlexible hours
$113.2k - $237.8k
...Job Title: Cyber Security Analyst Job Category: Engineering Time Type: Full time Minimum Clearance Required to Start: TS/SCI... ...career network. We are a fun, engaging environment with a management team focused on growing your career and making you a part of our...Full timeContract workWork experience placementLocal areaImmediate startFlexible hours$113.2k - $237.8k
...Job Title: Cyber Threat Analyst Job Category: Engineering Time Type: Full time... ...methodologies, intelligence analysis, and vulnerability assessments. If chosen, YOU will have... ...are a fun, engaging environment with a management team focused on growing your career and...Full timeContract workWork experience placementLocal areaImmediate startFlexible hours- ...Driving Customer Experience Excellence Pohanka Automotive Group is looking for a driven, people-first Service Business Development Manager (BDC Manager) to lead and elevate our customer engagement operations. In this role, you’ll coach and inspire a high-performing...Local area
- ...effective relationships with peers and communicate at all levels within the organization. ~ Ability to provide Tier 3 support and manage complex and escalated tickets in production environment Additional Information All your information will be kept...Full timeContract workWork at office
$190k - $210k
...As a Capture Manager at Amentum, you will drive strategy, planning, and execution for high-value business opportunities in the Intelligence Community (IC). Leveraging your deep customer knowledge, competitive insights, and capture acumen, you will own the end-to-end capture...Hourly payContract workLocal area- ...network architectures Demonstrated experience using network management tools Demonstrated experience leveraging adversarial... ...groups and organizations Demonstrated experience communicating vulnerability results and risk posture to senior executives Demonstrated...Full timeTemporary workFlexible hours
$5,000 per month
...Security interface to government customer and Accrediting Authorities. Perform vulnerability/risk assessments to support authorization and accreditation. Prepare and review Risk Management Framework (RMF) documentation to include System Security Plans (SSPs),...Civilian ContractorContract workTemporary workFor contractorsWork at officeImmediate startFlexible hours$100k - $140k
...engineers, visitors, system administrators, security staff, program managers, and local vendors and inspectors. This position requires an... ...including audit log reviews, system compliance assessments, vulnerability scans, and account activity for privileged and general users....Full timeTemporary workFor contractorsWork at officeLocal areaImmediate startRemote workFlexible hours$140k - $160k
...with MS TFS. Experience with ZAP security testing. Good organizational skills. Good leadership skills. Good project management skills. Good negotiation skills. Good people management skills. Good time management skills. Good problem-solving ability...Full time- ...participate in Agile/Scrum ceremonies (Sprint planning, stand-ups, retrospectives). Work closely with developers, DevOps, and product managers. Contribute to test strategy, QA processes, and quality improvements. Maintain documentation for testing processes and...Flexible hours
$140k - $190k
...certifications required: Active Certified Information Systems Security Professional (CISSP) Active Certified Information Security Manager (CISM) Other relevant certifications (e.g., CCSP, CEH) may be considered. Bachelor’s degree in computer science, Engineering,...Temporary workImmediate startRemote workRelocation packageDay shift$50 - $85 per hour
...must be delivery and efficiency focused, with the ability to manage all aspects of a consulting project to include requirements analysis... ..., Nessus, Netcat, Burp Suite, etc. Conduct and document vulnerability scans and penetration testing on web-based applications and their...Contract workPart timeFor contractorsWork experience placementImmediate startRemote work- ...cloud and containerized environments Experience with automated vulnerability scanning and exploitation platforms Knowledge of security... ...and capabilities to help prevent fraud, detect threats, and manage digital risk and access. In addition to mitigating attack risks...
- Friedman Williams seeks a Marketing & Business Development Coordinator to support a dynamic marketing team in Chantilly, VA. This role offers exposure to events, client outreach, and business development in a fast-paced firm environment. You will work closely with marketing...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vulnerability Management Analyst. Be the first to apply!
- deloitte business technology analyst Chantilly, Loudoun County, VA
- business analyst law firm Chantilly, Loudoun County, VA
- knowledge management analyst Chantilly, Loudoun County, VA
- analytics business analyst Chantilly, Loudoun County, VA
- pega business analyst Chantilly, Loudoun County, VA
- business development analyst Chantilly, Loudoun County, VA
- business analyst Chantilly, Loudoun County, VA
- senior data management analyst Chantilly, Loudoun County, VA
- software asset management analyst Chantilly, Loudoun County, VA
- public sector business analyst Chantilly, Loudoun County, VA




