Vulnerability Management Analyst
DANE LLC
Job Description
Job Description
Benefits:
- Life/STD/LTD
- FSA/DCA
- 401(k)
- Employee discounts
- Paid time off
- 401(k) matching
- Dental insurance
- Health insurance
- Tuition assistance
- Vision insurance
Job Type: Full Time
Education: Minimum of a Bachelor’s degree in computer science or Equivalent
Experience: Minimum 1 year of relevant experience
Clearance: Must hold an Active DoD Secret Clearance or higher Responsibilities
- Run authorized Tenable/Nessus scans using credentialed scan profiles and review exports to identify CVEs, plugin findings, KEV status, EOL/EOS software risks, and affected assets.
- Validate findings as true or false positives, track vulnerability age using first-seen/last-seen dates, and escalate unresolved findings to senior security staff or system owners.
- Support the full vulnerability lifecycle from intake and triage through ownership assignment, remediation tracking, retest/rescan validation, and closure evidence collection.
- Monitor KEV and Critical/High findings against federal remediation timelines (e.g., BOD 22-01) and flag aging, stale, or blocked findings for escalation.
- Build and maintain Power BI dashboards and Excel reports covering vulnerability posture, patch compliance, KEV status, finding aging, and ownership tracking using Power Query, slicers, and basic DAX measures.
- Produce recurring deliverables, including Critical/High aging reports, Tenable/iPost reconciliation summaries, EOL/EOS tracking, and executive snapshots; document KPI definitions and data sources.
- Reconcile vulnerability data across Tenable/Nessus, iPost, ServiceNow/CA ServiceDesk, Jira, SharePoint, POA&M trackers, and Excel exports to identify mismatches and coverage gaps.
- Coordinate with security, development, infrastructure, database, and cloud teams and ISSO stakeholders to drive remediation through closure.
- 1–3 years of experience in cybersecurity operations, vulnerability management, SOC, cyber GRC, IT operations, or application security support; working knowledge of CVE, CVSS, KEV, false positives, POA&M tracking, risk acceptance, and vulnerability aging.
- Hands-on Tenable/Nessus experience: executing credentialed scans, analyzing plugin output and CVE findings, validating true/false positives, and building dashboards, saved filters, and exports for KEV, Critical/High, EOL/EOS, and aging tracking.
- Intermediate Power BI (Power Query, data modeling, DAX, slicers) and strong Excel skills (pivot tables, VLOOKUP/XLOOKUP, conditional formatting, deduplication) for vulnerability reporting and KPI tracking.
- Experience with iPost, ServiceNow, CA ServiceDesk, Jira, or SharePoint for remediation tracking; ability to reconcile data across multiple tools, identify mismatches, and maintain accurate ownership and evidence records.
- Familiarity with EOL/EOS software tracking, patch compliance, remediation exceptions, risk acceptance documentation, and closure evidence collection.
- Strong attention to detail, comfort working with large and messy datasets, and clear communication skills for translating technical findings into plain-language updates for leadership and non-technical stakeholders.
- Experience supporting federal cybersecurity programs or regulated environments; familiarity with NIST SP 800-53, RMF, A&A, ATO, POA&M lifecycle management, CISA BOD 22-01, and FedRAMP vulnerability requirements.
- Exposure to DevSecOps and application security tooling: SAST, DAST, SCA, container image scanning, secrets scanning, or Software Bill of Materials (SBOM) analysis.
- Basic understanding of enterprise patching for Windows Server, Windows workstations, .NET Framework, Java JRE, SQL Server, and endpoint agents; familiarity with Splunk or other SIEM platforms.
- Experience developing SOPs, RACI matrices, or workflow documentation in a security or IT operations context.
- Relevant certifications such as CompTIA Security+, CySA+, CEH, or equivalent entry-to-mid-level cybersecurity credentials.
Flexible work from home options available.
Vacancy posted 15 days ago
Similar jobs that could be interesting for youBased on the Vulnerability Management Analyst in Chantilly, Loudoun County, VA vacancy
$131.8k - $290k
...building events where you get to engage with your co-workers and expand your career network. We are a fun, engaging environment with a management team focused on growing your career and making you a part of our future. We offer bonus compensation plans that demonstrate you...SuggestedContract workWork experience placementLocal areaFlexible hours- DescriptionSAIC is seeking a Principal Cyber Security Cloud Analyst, to serve as a member of a Vulnerability Assessment program. This position is located in... ...the presence of vulnerabilitiesAct as advisor to management and customers on technical research studies, to include...Suggested
$86.8k - $198k
Enterprise Cybersecurity Vulnerability Analyst, SeniorThe Opportunity:Support Booz Allen Hamilton's internal Enterprise Cybersecurity team by... ...SLA levels. Conduct analysis and serve as a vulnerability management resource supporting the company's client-facing and internal...SuggestedFull timeContract workPart timeWork at officeLocal areaRemote work$86.6k - $181.8k
Job Title: Event Management Practice Area AnalystJob Category: Information TechnologyTime Type: Full timeMinimum Clearance Required to... ...assisting in IT Infrastructure governance and operations. The analyst will work with key stakeholders to ensure proper implementation...SuggestedContract workWork experience placementImmediate startFlexible hours$150k - $195k
...for performing basic reconnaissance and vulnerability scanning in accordance with established... ...efforts; collaborating with management to develop security policies, training... ...CompTIA Pen Test+• CompTIA Cybersecurity Analyst (CySA+)• Certified Hacking Forensic Investigator...SuggestedWork experience placement$86.6k - $181.8k
Job Title: Service Configuration Management AnalystJob Category: Information TechnologyTime Type: Full timeMinimum Clearance Required to... ...Integration and Management) - Configuration Management Analyst to support the planning, design, and implementation of configuration...Contract workWork experience placementFlexible hours$200k
...Job Description Job Description Overview Senior Business Operations & Financial Management Analyst LOCATION: Chantilly, VA JOB STATUS: Full-time CLEARANCE: Active DoD Top Secret security clearance with SCI eligibility and Poly required. U.S. citizenship...Full timeWork at office- ...Position Title: Senior Business Operations & Financial Management Analyst Location: Chantilly, VA Clearance Requirement: Active Top Secret with SCI eligibility U.S. Citizenship required OMNI Consulting Solutions is seeking a Senior Business Operations &...Full timeWork at office
- ...not meet these requirements will not be considered. Responsibilities: Responsible for performing basic reconnaissance and vulnerability scanning in accordance with established testing methodologies Identifies common vulnerabilities that can be potentially...Work experience placement
- ...join our cybersecurity team. In this role, you will identify vulnerabilities and test the security of networks, applications, and systems... ...SIMILAR CAREER TITLES Ethical Hacker, Vulnerability Analyst, Security Consultant, Red Team Specialist, Cybersecurity Analyst...Temporary workFor contractorsImmediate startFlexible hours
$90k - $130k
...both active and passive capabilities to expose and exploit IA vulnerabilities. Review and evaluate information systems and recommend... ..., program design and implementation, configuration management, system maintenance, integration testing, Information system...Work experience placement$5,000 per month
...Responsible for performing basic reconnaissance and vulnerability scanning in accordance with established testing methodologies... ...advice, and leading remediation efforts; collaborating with management to develop security policies, training other cybersecurity professionals...Contract workTemporary workFor contractorsImmediate startFlexible hours- ...environment.Monitor and respond to customer requests received via the NSS central telephone number and the NSS Trouble Ticket Request Form.Manage all MID networks and dedicated network structures located within MID lab environments and facilities, including the generation of...Work at office
- ...system security plans, SOPs, audit logs, configuration scans, and vulnerability scansEvaluating the implementation and effectiveness of IT... ...Information Systems Auditor (CISA) or Certified Information Security Manager (CISM)Demonstrated knowledge and experience in IT risk and...Full timeFlexible hours
- Job Number: R0246787 Enterprise Cybersecurity Vulnerability Analyst, Senior The Opportunity Support Booz Allen Hamilton's internal Enterprise Cybersecurity team by utilizing enterprise-level vulnerability scanning and assessment tools to identify internally and externally...
$120k - $160k
...Architecture, SE milestones: SRR, PDR, CDR, etc.), and/or DAWIA/PMI Program Management will be especially well-prepared to excel. Job Description This position is for a Business Operations Analyst in Chantilly, VA supporting cutting-edge and innovative space programs....Full timeFor contractorsWork at office- ...Description Seeking a Digital Forensics Analyst, to serve as a member of an organizational cybersecurity program. This position requires an active TS/SCI with Polygraph. Key Responsibilities Conduct forensic acquisition and analysis on computer, mobile, IOT, digital media...Work experience placement
- Booz Allen Hamilton is seeking an Enterprise Cybersecurity Vulnerability Analyst, Senior to join its internal Enterprise Cybersecurity team. You will use enterprise-grade vulnerability scanning and assessment tools to identify vulnerabilities and misconfigurations across...
$100k - $113k
...Chantilly, VA to monitor and maintain systems security on operational systems such as malicious code eradication, configuration management, assessment and authorization of current and future systems, as well as to review and revise systems security documentation on proposed...Civilian ContractorWork experience placementWork at office$98.1k - $115k
...solutions to accomplish the requirements in addition to program management. The services obtained under this contract shall provide... ...Conducting regular security audits and assessments to identify vulnerabilities and risks.Monitoring network traffic for unusual activity...Contract workTemporary workFor contractorsWork at officeLocal areaRelocation$100k - $140k
...engineers, visitors, system administrators, security staff, program managers, and local vendors and inspectors. This position requires an... ...including audit log reviews, system compliance assessments, vulnerability scans, and account activity for privileged and general users....Full timeTemporary workFor contractorsWork at officeLocal areaRemote workFlexible hours$110k - $180k
...candidate will have demonstrated experience working the Risk Management Framework with Department of Defense (DOD) and Intelligence Community... ...are established and followed. The position will perform vulnerability/risk assessment and configuration management to support...Full timeContract workFor contractorsWork at officeImmediate start- Earned Value Management (EVM)/Integrated Performance Management (IPM) Analyst – SME Level – TS/SCI Clearance w/CI Poly Required Location Chantilly, VA Job Description Leffler Consulting is seeking a seasoned Earned Value Management (EVM)/Integrated Performance Management...For contractorsWork experience placementWork at office
- ...Health Information Management (HIM) Analyst Epic HIM / Solventum / Payor Platform Location: Chantilly, Virginia, United States Employment Type: Full-Time Job Summary: We are seeking a detail-oriented Health Information Management (HIM) Analyst with experience...Full time
- ...software engineering, AI solutions, cybersecurity, and IT program management. We thrive at the intersection of mission, technology, and... ...security groups and organizations Communicating vulnerability results and risk posture to senior executives Performing complex...Full timeWork experience placement
$85k - $125k
...Preferred qualifications include experience with access and account management principles, contingency planning, configuration management,... ...security plans, SOPs, audit logs, configuration scans, and vulnerability scans to support testing. We evaluate the design and...Full timeFlexible hours- DescriptionSAIC is seeking an Space Systems Analyst with technical expertise in government satellite systems to support the Mission... ...and architecturesExperience with DOD/IC acquisition and program management processesExperience with MATLAB or equivalent DSP development...For contractors
$86.8k - $198k
Missile Systems Analyst, SeniorThe Opportunity:Leverage experience with design and operations of foreign conventional missile systems... ...engagement operations, electronic warfare, datalinks, battle management, and operational employment conceptsMaster's degree in a STEM...Full timeContract workPart timeWork at officeLocal areaRemote work- ...perform duties as the alternate Information Systems Security Manager (ISSM). Cyber security paperwork (compliance) and Information... ...policies, controls and procedures and mitigate identified vulnerability and weaknesses Ability to work well in a team environment...InternshipWork at office
$120k - $160k
...SSPs, POA&Ms, and related authorization artifactsSystem Patch Management: Utilize patch deployment tools and hardening guidelines to... ...applicationsVulnerability Scanning & Remediation: Conduct regular vulnerability scans to detect vulnerabilities and developer & implement...Work experience placementWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vulnerability Management Analyst. Be the first to apply!
Related searches
- deloitte business technology analyst Chantilly, Loudoun County, VA
- business analyst law firm Chantilly, Loudoun County, VA
- knowledge management analyst Chantilly, Loudoun County, VA
- analytics business analyst Chantilly, Loudoun County, VA
- pega business analyst Chantilly, Loudoun County, VA
- business development analyst Chantilly, Loudoun County, VA
- business analyst Chantilly, Loudoun County, VA
- senior data management analyst Chantilly, Loudoun County, VA
- software asset management analyst Chantilly, Loudoun County, VA
- public sector business analyst Chantilly, Loudoun County, VA


