Vulnerability Management Analyst
Dane
Benefits:
Life/STD/LTD
FSA/DCA
401(k)
Employee discounts
Paid time off
401(k) matching
Dental insurance
Health insurance
Tuition assistance
Vision insurance
Description
Looking for a place that invests in you from day one? At DANE, we offer aggressive PTO, strong benefits, and ongoing learning opportunities, backed by a culture that values and supports our team.
We are seeking a Vulnerability Management Analyst (Tenable/Nessus & Metrics) to support vulnerability tracking, remediation coordination, and security metrics reporting in a federal technology environment. This is a junior-level role (1–3 years of experience) focused on execution and coordination, working hands-on with Tenable/Nessus, iPost, Power BI, Excel, and ticketing systems to ensure that vulnerability data is accurate, actionable, and reportable.
Details:
Location: Hybrid - Onsite, Arlington, VA,1 day/week and as needed Job Type: Full Time Education: Minimum of a Bachelor’s degree in computer science or Equivalent Experience: Minimum 1 year of relevant experience Clearance: Must hold an Active DoD Secret Clearance or higher
Responsibilities
Run authorized Tenable/Nessus scans using credentialed scan profiles and review exports to identify CVEs, plugin findings, KEV status, EOL/EOS software risks, and affected assets.
Validate findings as true or false positives, track vulnerability age using first-seen/last-seen dates, and escalate unresolved findings to senior security staff or system owners.
Support the full vulnerability lifecycle from intake and triage through ownership assignment, remediation tracking, retest/rescan validation, and closure evidence collection.
Monitor KEV and Critical/High findings against federal remediation timelines (e.g., BOD 22-01) and flag aging, stale, or blocked findings for escalation.
Build and maintain Power BI dashboards and Excel reports covering vulnerability posture, patch compliance, KEV status, finding aging, and ownership tracking using Power Query, slicers, and basic DAX measures.
Produce recurring deliverables, including Critical/High aging reports, Tenable/iPost reconciliation summaries, EOL/EOS tracking, and executive snapshots; document KPI definitions and data sources.
Reconcile vulnerability data across Tenable/Nessus, iPost, ServiceNow/CA ServiceDesk, Jira, SharePoint, POA&M trackers, and Excel exports to identify mismatches and coverage gaps.
Coordinate with security, development, infrastructure, database, and cloud teams and ISSO stakeholders to drive remediation through closure.
Requirements
1–3 years of experience in cybersecurity operations, vulnerability management, SOC, cyber GRC, IT operations, or application security support; working knowledge of CVE, CVSS, KEV, false positives, POA&M tracking, risk acceptance, and vulnerability aging.
Hands-on Tenable/Nessus experience: executing credentialed scans, analyzing plugin output and CVE findings, validating true/false positives, and building dashboards, saved filters, and exports for KEV, Critical/High, EOL/EOS, and aging tracking.
Intermediate Power BI (Power Query, data modeling, DAX, slicers) and strong Excel skills (pivot tables, VLOOKUP/XLOOKUP, conditional formatting, deduplication) for vulnerability reporting and KPI tracking.
Experience with iPost, ServiceNow, CA ServiceDesk, Jira, or SharePoint for remediation tracking; ability to reconcile data across multiple tools, identify mismatches, and maintain accurate ownership and evidence records.
Familiarity with EOL/EOS software tracking, patch compliance, remediation exceptions, risk acceptance documentation, and closure evidence collection.
Strong attention to detail, comfort working with large and messy datasets, and clear communication skills for translating technical findings into plain-language updates for leadership and non-technical stakeholders.
Preferred Qualifications
Experience supporting federal cybersecurity programs or regulated environments; familiarity with NIST SP 800-53, RMF, A&A, ATO, POA&M lifecycle management, CISA BOD 22-01, and FedRAMP vulnerability requirements.
Exposure to DevSecOps and application security tooling: SAST, DAST, SCA, container image scanning, secrets scanning, or Software Bill of Materials (SBOM) analysis.
Basic understanding of enterprise patching for Windows Server, Windows workstations, .NET Framework, Java JRE, SQL Server, and endpoint agents; familiarity with Splunk or other SIEM platforms.
Experience developing SOPs, RACI matrices, or workflow documentation in a security or IT operations context.
Relevant certifications such as CompTIA Security+, CySA+, CEH, or equivalent entry-to-mid-level cybersecurity credentials.
DANE LLC is an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Flexible work from home options available.
$103.54k - $147.92k
...Mission Technologies is currently seeking a Junior Vulernability Management Analyst to work out of Fairfax, VA i in support of the DoD/DoW... ...: I want to and can do that! • Supports enterprise vulnerability management operations for Department of Defense mission systems...SuggestedFull timeContract workFor contractorsWork at officeLocal areaWorldwide$60k - $73k
...Vulnerability Management Analyst Are you looking for limitless career opportunities with a company that values growth, innovation, and teamwork? At Ntiva, we're more than a Managed Services Provider, we're a community dedicated to helping each other, our clients, and...SuggestedContract workTemporary workRemote workMonday to Friday- ...Junior Vulnerability Management Analyst Everforth ECS is seeking a Junior Vulnerability Management Analyst to work in the National Capital Region covering the Pentagon, Falls Church, and Fairfax. The War Data Platform (WDP) is a key initiative within the U.S. Department...SuggestedFor contractorsInternship
- Mission Technologies, a division of HII, is looking for a skilled professional in vulnerability management in Fairfax, Virginia. The successful candidate will support Department of Defense cybersecurity efforts, ensure accuracy in vulnerability assessments, and maintain...Suggested
$103.54k - $147.92k
...Required Travel: 0-10%. Responsibilities Supports enterprise vulnerability management operations for Department of Defense mission systems across... ...and compensating controls under guidance of senior analysts. Maintains detailed records supporting Risk Management Framework...SuggestedFull timeFor contractorsWork at officeLocal area- ...Position Title: Senior Business Operations & Financial Management Analyst Location: Chantilly, VA Clearance Requirement: Active Top Secret with SCI eligibility U.S. Citizenship required OMNI Consulting Solutions is seeking a Senior Business Operations & Financial...Work at office
- ...Overview Senior Business Operations & Financial Management Analyst LOCATION: Chantilly, VA JOB STATUS: Full-time CLEARANCE: Active DoD Top Secret security clearance with SCI eligibility and Poly required. U.S. citizenship required. Astrion has...Full timeWork at office
- ...Overview At all levels, our Earned Value Management Analysts will utilize and enhance their skills in EVM by supporting programs related to the development and acquisition of space vehicles for various legacy programs of the DOD and Intelligence communities. The support...For contractorsWork at office
- ...Position Title: IT Management Tool Analyst Position Type: Full-time, On-Site Location: Chantilly, VA Clearance: Active TS/SCI CI Poly Overview Seeking a discerning technology professional who possesses both the technical acumen...Full time
- ...join our cybersecurity team. In this role, you will identify vulnerabilities and test the security of networks, applications, and systems... ...SIMILAR CAREER TITLES Ethical Hacker, Vulnerability Analyst, Security Consultant, Red Team Specialist, Cybersecurity Analyst...Temporary workFor contractorsImmediate startFlexible hours
- ...and clearly translate highly technical information to senior management in a way that supports mission goals. Help define the... ...Provide risk-appropriate and pragmatic recommendations to correct vulnerabilities found. Configure and safely utilize attacker tools,...Work experience placement
- ...cybersecurity firm in Chantilly, VA, seeks a highly skilled Penetration Tester to join their team. The role involves identifying vulnerabilities and testing the security of networks, applications, and systems through simulated real-world attacks. Ideal candidates are...
- ...Responsibilities: Responsible for performing basic reconnaissance and vulnerability scanning in accordance with established testing methodologies... ..., and leading remediation efforts Collaborating with management to develop security policies, training other cybersecurity...Work experience placement
- ...cloud specific concepts such as networking, identity and access management, console applications, and functions. A strong Penetration... ...at identifying and exploiting misconfigurations and/or vulnerabilities in cloud infrastructure. Our mission is to help our client protect...
- ...Service Performance Management Analyst, TS/SCI with Polygraph Security Clearance Required, Chantilly, VA Ready to hire a Service Performance Management Analyst. Qualified candidates must have an active TS/SCI with Polygraph Security Clearance. Military (Air Force...
$89.2k - $194.78k
...critical voice, video and collaboration services for the full spectrum of operations. AT&T has an opening for a Change Management Analyst to support the program’s configuration control board, customer’s technical post implementation review, and root cause analysis...Temporary workWork at officeLocal areaRelocation- ...Familiarity with detecting and preventing computer security compromises in a networked environment. Working knowledge of configuration management; system maintenance; and integration testing. Proficient in the use of tools used to prevent and/or negate malicious code....Civilian ContractorWork at office
- ...information Technology, Information Assurance, Information Management (IT/IA/IM) • Manage the day-to-day system security including... ...security compliance • Review Nessus security scans, communicate vulnerabilities to technical stakeholders, and perform remediation •...Work experience placement
- ...compliance with security policies, and managing risk through the implementation of robust... ...security assessments, monitor for vulnerabilities, and respond to potential threats. The... ...SIMILAR CAREER TITLES Cybersecurity Analyst, Information Security Specialist, Security...Temporary workFor contractorsImmediate startFlexible hours
- ...Degree in a related field or an advanced degree in Cybersecurity with 5+ years of experience in within information security or risk management supporting multi-domain SAP or SCI environments. Certifications: The ISSO shall possess an active technical certification...Temporary workWork at office
- ...Administrators and other IS security personnel. Conduct required IS vulnerability scans according to risk assessment parameters. Develop Plan... ...(POAMs) in response to reported security vulnerabilities Manage the risks to ISs and other NRO assets by coordinating...Work at officeLocal area
- ...implementing and overseeing security policies, managing risk assessments, and ensuring... ...closely with other IT teams to identify vulnerabilities, develop security protocols, and monitor... ..., Cybersecurity Officer, Security Analyst, Information Assurance Officer, Security...Temporary workFor contractorsImmediate startFlexible hours
- ...configurations, enclave policy, or local policy. This is achieved through passive evaluations (compliance audits) and active evaluations (vulnerability assessments). Establishes strict program control processes to ensure mitigation of risks and supports for obtaining...For contractorsWork experience placementLocal area
$165k - $195k
...Required Top Secret/SCI Overview AMERICAN SYSTEMS is seeking a Senior Information System Security Officer (ISSO ) to manage RMF execution, authorization, and continuous monitoring for hybrid onpremises and cloud systems supporting classified government...Full timeRemote work$140k - $160k
...Security Officer (ISSO) to lead a collaborative team to develop, manage, and maintain information system security Assessment and... ...activities, consisting of periodical reviews of controls, audits, vulnerability scans, and penetration test reports. POA&M development to...Full timeFor contractorsFlexible hours- ...configurations, enclave policy, or local policy. This is achieved through passive evaluations (compliance audits) and active evaluations (vulnerability assessments). Establishes strict program control processes to ensure mitigation of risks and supports for obtaining...For contractorsWork experience placementLocal area
- ...Associates Degree and 12 years of work experience or equivalent Desired Qualifications: Expertise with configuration management; system maintenance; and integration testing. Ability to troubleshoot technical configurations and make recommendations on...For contractorsWork experience placement
- ...cybersecurity, AI governance, data protection, and enterprise risk management - accountable for ensuring the confidentiality, integrity, and... ...maturity Direct and mentor the Information Security Analyst and develop organizational security capability QUALIFICATIONS...Remote workHome officeFlexible hours
- ...cycle Assessment and Authorization (A&A) management through all 6 Steps of the RMF process... ...and recommend improvements to amend vulnerabilities, implement changes, and document upgrades... ...experience as an Information Assurance (IA) Analyst, ISSE, ISSO, or similar role in ATO...Full timeLocal areaRemote workFlexible hours
- ...policy architecture across SPA's information systems. The team manages cyber policy, develops control implementations and system... ...supervision Desired Qualifications: ~ Experience performing Vulnerability Management activities and validating system compliance using...Work experience placementImmediate start
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vulnerability Management Analyst. Be the first to apply!
- senior business analyst contract Chantilly, Loudoun County, VA
- business analyst law firm Chantilly, Loudoun County, VA
- records management analyst Chantilly, Loudoun County, VA
- business analyst healthcare Chantilly, Loudoun County, VA
- deloitte business technology analyst Chantilly, Loudoun County, VA
- pega business analyst Chantilly, Loudoun County, VA
- business strategy analyst Chantilly, Loudoun County, VA
- software asset management analyst Chantilly, Loudoun County, VA
- business analyst part time remote Chantilly, Loudoun County, VA
- business analyst Chantilly, Loudoun County, VA

