Vulnerability Management Analyst
Dane
Benefits:
Life/STD/LTD
FSA/DCA
401(k)
Employee discounts
Paid time off
401(k) matching
Dental insurance
Health insurance
Tuition assistance
Vision insurance
Description
Looking for a place that invests in you from day one? At DANE, we offer aggressive PTO, strong benefits, and ongoing learning opportunities, backed by a culture that values and supports our team.
We are seeking a Vulnerability Management Analyst (Tenable/Nessus & Metrics) to support vulnerability tracking, remediation coordination, and security metrics reporting in a federal technology environment. This is a junior-level role (1–3 years of experience) focused on execution and coordination, working hands-on with Tenable/Nessus, iPost, Power BI, Excel, and ticketing systems to ensure that vulnerability data is accurate, actionable, and reportable.
Details:
Location: Hybrid - Onsite, Arlington, VA,1 day/week and as needed Job Type: Full Time Education: Minimum of a Bachelor’s degree in computer science or Equivalent Experience: Minimum 1 year of relevant experience Clearance: Must hold an Active DoD Secret Clearance or higher
Responsibilities
Run authorized Tenable/Nessus scans using credentialed scan profiles and review exports to identify CVEs, plugin findings, KEV status, EOL/EOS software risks, and affected assets.
Validate findings as true or false positives, track vulnerability age using first-seen/last-seen dates, and escalate unresolved findings to senior security staff or system owners.
Support the full vulnerability lifecycle from intake and triage through ownership assignment, remediation tracking, retest/rescan validation, and closure evidence collection.
Monitor KEV and Critical/High findings against federal remediation timelines (e.g., BOD 22-01) and flag aging, stale, or blocked findings for escalation.
Build and maintain Power BI dashboards and Excel reports covering vulnerability posture, patch compliance, KEV status, finding aging, and ownership tracking using Power Query, slicers, and basic DAX measures.
Produce recurring deliverables, including Critical/High aging reports, Tenable/iPost reconciliation summaries, EOL/EOS tracking, and executive snapshots; document KPI definitions and data sources.
Reconcile vulnerability data across Tenable/Nessus, iPost, ServiceNow/CA ServiceDesk, Jira, SharePoint, POA&M trackers, and Excel exports to identify mismatches and coverage gaps.
Coordinate with security, development, infrastructure, database, and cloud teams and ISSO stakeholders to drive remediation through closure.
Requirements
1–3 years of experience in cybersecurity operations, vulnerability management, SOC, cyber GRC, IT operations, or application security support; working knowledge of CVE, CVSS, KEV, false positives, POA&M tracking, risk acceptance, and vulnerability aging.
Hands-on Tenable/Nessus experience: executing credentialed scans, analyzing plugin output and CVE findings, validating true/false positives, and building dashboards, saved filters, and exports for KEV, Critical/High, EOL/EOS, and aging tracking.
Intermediate Power BI (Power Query, data modeling, DAX, slicers) and strong Excel skills (pivot tables, VLOOKUP/XLOOKUP, conditional formatting, deduplication) for vulnerability reporting and KPI tracking.
Experience with iPost, ServiceNow, CA ServiceDesk, Jira, or SharePoint for remediation tracking; ability to reconcile data across multiple tools, identify mismatches, and maintain accurate ownership and evidence records.
Familiarity with EOL/EOS software tracking, patch compliance, remediation exceptions, risk acceptance documentation, and closure evidence collection.
Strong attention to detail, comfort working with large and messy datasets, and clear communication skills for translating technical findings into plain-language updates for leadership and non-technical stakeholders.
Preferred Qualifications
Experience supporting federal cybersecurity programs or regulated environments; familiarity with NIST SP 800-53, RMF, A&A, ATO, POA&M lifecycle management, CISA BOD 22-01, and FedRAMP vulnerability requirements.
Exposure to DevSecOps and application security tooling: SAST, DAST, SCA, container image scanning, secrets scanning, or Software Bill of Materials (SBOM) analysis.
Basic understanding of enterprise patching for Windows Server, Windows workstations, .NET Framework, Java JRE, SQL Server, and endpoint agents; familiarity with Splunk or other SIEM platforms.
Experience developing SOPs, RACI matrices, or workflow documentation in a security or IT operations context.
Relevant certifications such as CompTIA Security+, CySA+, CEH, or equivalent entry-to-mid-level cybersecurity credentials.
DANE LLC is an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Flexible work from home options available.
- ...benefits, and ongoing learning opportunities, backed by a culture that values and supports our team. We are seeking a Vulnerability Management Analyst (Tenable/Nessus & Metrics ) to support vulnerability tracking, remediation coordination, and security metrics...SuggestedFull timeWork from homeFlexible hours1 day per week
- DescriptionSAIC is seeking a Principal Cyber Security Cloud Analyst, to serve as a member of a Vulnerability Assessment program. This position is located in... ...the presence of vulnerabilitiesAct as advisor to management and customers on technical research studies, to include...Suggested
$86.8k - $198k
Enterprise Cybersecurity Vulnerability Analyst, SeniorThe Opportunity:Support Booz Allen Hamilton's internal Enterprise Cybersecurity team by... ...SLA levels. Conduct analysis and serve as a vulnerability management resource supporting the company's client-facing and internal...SuggestedFull timeContract workPart timeWork at officeLocal areaRemote work$86.6k - $181.8k
Job Title: Event Management Practice Area AnalystJob Category: Information TechnologyTime Type: Full timeMinimum Clearance Required to... ...assisting in IT Infrastructure governance and operations. The analyst will work with key stakeholders to ensure proper implementation...SuggestedContract workWork experience placementImmediate startFlexible hours$150k - $195k
...for performing basic reconnaissance and vulnerability scanning in accordance with established... ...efforts; collaborating with management to develop security policies, training... ...CompTIA Pen Test+• CompTIA Cybersecurity Analyst (CySA+)• Certified Hacking Forensic Investigator...SuggestedWork experience placement$86.6k - $181.8k
Job Title: Service Configuration Management AnalystJob Category: Information TechnologyTime Type: Full timeMinimum Clearance Required to... ...Integration and Management) - Configuration Management Analyst to support the planning, design, and implementation of configuration...Contract workWork experience placementFlexible hours- ...Position Title: Senior Business Operations & Financial Management Analyst Location: Chantilly, VA Clearance Requirement: Active Top Secret with SCI eligibility U.S. Citizenship required OMNI Consulting Solutions is seeking a Senior Business Operations &...Full timeWork at office
$200k
...Job Description Job Description Overview Senior Business Operations & Financial Management Analyst LOCATION: Chantilly, VA JOB STATUS: Full-time CLEARANCE: Active DoD Top Secret security clearance with SCI eligibility and Poly required. U.S. citizenship...Full timeWork at office- ...system security plans, SOPs, audit logs, configuration scans, and vulnerability scansEvaluating the implementation and effectiveness of IT... ...Information Systems Auditor (CISA) or Certified Information Security Manager (CISM)Demonstrated knowledge and experience in IT risk and...Full timeFlexible hours
$78.7k - $165.2k
...Opportunity:CACI is seeking an Enterprise Hardware Business Operations Analyst to support our Department of the Air Force (DAF) customer on... ...to support Air Force hardware ordering and delivery workflows. Manage staffing readiness, including planning, timing, onboarding, and...Contract workWork experience placementFlexible hours$100k - $140k
...engineers, visitors, system administrators, security staff, program managers, and local vendors and inspectors. This position requires an... ...including audit log reviews, system compliance assessments, vulnerability scans, and account activity for privileged and general users....Full timeTemporary workFor contractorsWork at officeLocal areaRemote workFlexible hours$110k - $180k
...candidate will have demonstrated experience working the Risk Management Framework with Department of Defense (DOD) and Intelligence Community... ...are established and followed. The position will perform vulnerability/risk assessment and configuration management to support...Full timeContract workFor contractorsWork at officeImmediate start$142k - $149k
...Chantilly, VA to monitor and maintain systems security on operational systems such as malicious code eradication, configuration management, assessment and authorization of current and future systems, as well as to review and revise systems security documentation on proposed...Civilian ContractorFor contractorsWork experience placementWork at office- Senior Integrated (EVM and Schedule) Performance Management Analyst – TS/SCI Clearance w/CI Poly Required Location Chantilly, VA Job Description Leffler Consulting is seeking a Senior Integrated Performance Management (IPM) Analyst to join our team in Chantilly providing...For contractorsWork at office
- ...part of an overall Sponsor effort to migrate portions or all of payroll systems to a new-shared service provider. Priorities will be managed by the designated Government Technical Manager (GTM). Work Requirements: Software Quality Assurance with Application Testing: 1....For contractors
$116.35k - $210.33k
...candidate will work on a team comprised of developers, database administrators, systems engineers, security engineers, as well as program managers and a scrum master. The ideal candidate will be familiar with agile principles, specifically scrum. The candidate will be joining...Full time$98.1k - $146k
...operations.AT&T is looking for a Cybersecurity Analyst to conduct continuous monitoring and... ...:Support in establishing and managing a 7 am to 7 PM M-F Network Operations and... ...monitor for security alerts and coordinate vulnerability assessments and artifact collection...Temporary workWork at officeLocal areaRelocationNight shift- OverviewVTG is seeking a detail-oriented QA Automation Engineer to design, develop, and maintain automated test frameworks and scripts. This role will play a critical part in ensuring software quality by integrating automated testing into the development lifecycle and improving...
- Overview Amyx is seeking to hire an Acquisition Consultant/Management Analyst to join our Defense Health Ageny contract in San Antonio,Tx. Responsibilities Provide medical administration services in a wide range of organizational, business, and financial operations...Full timeContract workFor contractorsFlexible hours
- ...practice and play a significant role in the company's long-term growth. What You'll Do Federal Market Development Build and manage a targeted portfolio of government prime contractors, systems integrators, and federal program teams. Develop relationships...Full timeContract workFor contractorsFor subcontractorImmediate start
$103.8k - $218.1k
Job Title: Senior Business Analyst - CMDB Authoritative SourcesJob Category: Information TechnologyTime Type: Full timeMinimum Clearance... ...sources that should be included within the Configuration Management Database (CMDB). The expectation is that these requirements largely...Contract workWork experience placementLocal areaFlexible hours- Digital Forensic Analyst Employment Type: Full-Time, Mid-Level Department: Forensics CGS is seeking a Digital Forensic Analyst whose... ...updates and new options in the market Work closely with project management and other team members on completing complex projects in a...Full timeWork at officeRemote workFlexible hours
- ...AnalystLocation: Chantilly, VA Job Summary: The Senior Business Analyst will support the customer’s Artificial Intelligence (AI)... ...testing.Conduct vendor risk assessments and document findings.Manage project plans and documentation for product sourcing and acquisition...
$160.2k - $195.8k
...Title: Network Analyst Belong. Connect. Grow. with KBR! KBR’s National Security Solutions team provides high-end engineering and... ...line of engineering, logistics, operations, science, program management, mission IT and cybersecurity solutions. Collaborative Environment...Temporary workLocal areaWorldwideRelocation packageFlexible hours- Description Seeking a Digital Forensics Analyst, to serve as a member of an organizational cybersecurity program. This position requires an active TS/SCI with Polygraph. Key Responsibilities Conduct forensic acquisition and analysis on computer, mobile, IOT, digital media...Work experience placement
$100k - $140k
...ability to remain in a stationary position 50% of the time. You may need to move about the office to access file cabinets, office machinery, or communicate with colleagues, management, and clients, which may involve delivering presentations. last updated 36 week of 2026...Full timeWork at office- ...candidate will be responsible for providing Joint Intelligence Community Government project leads with the planning, organizing and management of cyber security implementation on systems related to satellite ground processing capabilities.SPECIFIC TASKING/PROJECT SUPPORT:...Work at officeNight shift
$79.6k - $172.4k
Business Program & Project Management Analyst TS/SCI with Poly REQUIRED Position Description CGI Federal is seeking candidates for Business Program & Project Management Analyst positions supporting a USG agency in Northern Virginia. Successful candidates will assist...Local area- ...DESCRIPTION: Performs Cyber Systems Architecture, Cyber Technology Research Development, Cyber Data Administration, Cyber Knowledge Management, Cyber Network Services, Cyber Systems Administration, Cyber Systems Analysis, and Cybersecurity Defense Infrastructure Support...
- ...complete satellites to meet mission requirements Lead and/or participate in proposal activities, including generation of technical, management, cost, schedule, and proposal content for new business Develop strong relationships across all levels of the business to ensure...Permanent employmentFor contractorsLocal areaWeekend work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vulnerability Management Analyst. Be the first to apply!
- remote senior business analyst Chantilly, Loudoun County, VA
- senior business analyst contract Chantilly, Loudoun County, VA
- senior business analyst Chantilly, Loudoun County, VA
- records management analyst Chantilly, Loudoun County, VA
- public sector business analyst Chantilly, Loudoun County, VA
- business analyst contract Chantilly, Loudoun County, VA
- fiserv business analyst Chantilly, Loudoun County, VA
- business development analyst Chantilly, Loudoun County, VA
- business analyst law firm Chantilly, Loudoun County, VA
- business analyst part time remote Chantilly, Loudoun County, VA




