VULNERABILITY MGMT ANALYST
Areté
Areté is looking for the person who makes sure vulnerabilities actually get closed — not just found. As our Vulnerability Management Analyst in Falls Church, VA, you will own the end-to-end remediation cycle — scanning, prioritization, patch qualification, deployment, and verification — across desktops, servers, network devices, and standalone systems on multiple sites and networks, working closely with Areté's Cyber Security staff. This is a hands‑on execution role, and you will be measured on whether vulnerabilities close on a recurring, risk-prioritized cadence. Equally important is doing so without breaking the business: qualifying patches before they are pushed, understanding which applications depend on pinned or vendor-locked component versions, coordinating maintenance windows with system owners, and having a tested rollback path when a patch goes wrong. The selected candidate must hold an active Top Secret clearance and be able to maintain it. This position is onsite at our Falls Church, VA facility. The candidate may be required to travel occasionally and provide some afterhours support. This is an exempt non-supervisory full-time position. Primary Responsibilities Conduct regular vulnerability assessments and serve as the technical expert with primary responsibility for vulnerability scanning and remediation of desktops, servers, network devices, and other systems across multiple sites, networks, and standalone environments. Analyze scan results from Rapid7 and Tenable Security Center (ACAS) and produce a risk-prioritized remediation plan that accounts for severity, exploitability, exposure, asset criticality, and known‑exploited‑vulnerability status — not raw CVSS alone. Execute continuous, recurring patching schedules against that prioritization, within maintenance windows authorized by the appropriate change control board. Qualify patches before deployment: test in a representative environment, identify dependencies on pinned or vendor-supported component versions, assess impact to line‑of‑business and server applications, and document a rollback plan. Identify vulnerabilities that cannot be resolved by patching alone — pinned application dependencies, end‑of‑life software, vendor‑locked systems — and develop compensating controls, mitigation strategies, or upgrade recommendations in coordination with system owners and Cyber Security. Coordinate with system owners and end users on upcoming patches and projected impacts, including reboots, service interruptions, and network‑wide effects. Verify remediation through rescanning and closure validation; track exceptions, deviations, and accepted risks through to resolution or formal acceptance. Automate recurring scanning, patching, reporting, and remediation workflows to reduce manual effort and improve consistency. Maintain vulnerability management processes and standard operating procedures, and maintain and report metrics for the function — remediation timeliness, aging, coverage, patch success and failure rates, and recurring problem areas. Prepare and present reports on vulnerability management activities to IT and senior management, communicating complex technical information to non‑technical stakeholders. Stay current on emerging threats, actively exploited vulnerabilities, and vendor advisories, and recommend proactive measures. Other duties, as assigned. Experiences And Background We Look For Active Top Secret clearance, with the ability to maintain it. Must have or be able to obtain a CompTIA Security+ CE certification within 120 days of employment, in accordance with DoDM 8140.03 and DFARS View phone number on click.appcast.io. Minimum of 3 years working as a System Administrator, Systems Engineer, Network Administrator, Vulnerability Analyst, or similar role. Proficient understanding of computer hardware, software, and operating systems — primarily Microsoft Windows Server and Red Hat Enterprise Linux — with strong system troubleshooting skills across both. Working knowledge of vulnerability scanning products such as Rapid7 (preferred), Tenable Security Center/Nessus (ACAS), or Qualys. Experience with patch management tools such as PDQ Deploy, SCCM/MECM, WSUS, YUM/DNF, or Red Hat Satellite — including testing and qualifying patches prior to deployment, coordinating change‑managed maintenance windows, and executing rollback when required. Working scripting ability in PowerShell, Bash, or Python sufficient to automate recurring scan parsing, patch orchestration, and reporting tasks. Strong interpersonal and written communication skills, with the ability to work autonomously, produce technical documentation, and negotiate remediation timelines with system owners who have competing priorities. Nice To Have TS/SCI access with polygraph. Advanced automation experience building patch orchestration or vulnerability reporting tooling. Experience patching and maintaining airgapped, standalone, or classified systems, including offline content management and update ingestion. Familiarity with DISA STIGs, SCAP Compliance Checker, and DoD or federal compliance frameworks (NIST 800-53, NIST 800-171, RMF). Experience with container and application dependency scanning, and with SBOM-based vulnerability identification. Experience managing vulnerabilities in third‑party and line‑of‑business applications where a vendor pins supported runtime or library versions. Industry certifications such as CySA+, Network+, CCNA, RHCSA, Microsoft AZ‑800/801 or MD‑102, GIAC GCED/GEVA, or vendor certifications in Rapid7 or Tenable/ACAS. Bachelor's Degree in an Information Technology related discipline. We have an impressive range of benefits, programs, and perks that we offer: Generous PTO and Leave Times Flextime Scheduling Bereavement Paid Time Off (PTO) Paid Parental Leave Financial Benefits Company-funded 5% contribution to your 401(k) retirement plan Company-funded 5% contribution to your Employee Stock Ownership Plan Continuing Education Assistance Health, Medical, And Wellness Benefits Medical Insurance Dental & Vision Insurance Life Insurance and Long-Term Disability (LTD) Vision Reimbursement #J-18808-Ljbffr Areté
- ...Job Description Job Description Areté is looking for the person who makes sure vulnerabilities actually get closed — not just found. As our Vulnerability Management Analyst in Falls Church, VA, you will own the end-to-end remediation cycle — scanning, prioritization...SuggestedFull time
- ...through innovative solutions and an engaging culture. Description of Task to be Performed: AnaVation is seeking a Cyber Vulnerability Analyst to join our team and support our mission critical customer in Reston, VA or Colorado Springs, CO. In this role you will...SuggestedFull timeTemporary workImmediate start
- A leading cybersecurity consultancy is seeking a Cybersecurity Vulnerability Analyst based in Arlington, VA. The role requires an active Top Secret Security Clearance and 5+ years of experience, focusing on vulnerability analysis for federal clients. Candidates must exhibit...Suggested
- ...supporting a U.S. Government customer to provide cybersecurity vulnerability analysis support to reduce the prevalence and impact of... ...Infrastructure Key Resources (CIKR). The Cybersecurity Vulnerability Analyst utilizes cybersecurity best practices, risk management...Suggested
- NTT DATA seeks a Cybersecurity and Risk Analyst to join the VAPT team, identifying and mitigating cybersecurity risks across enterprise systems, networks, and applications. You will perform vulnerability assessments, risk evaluations, and threat simulations aligned with...Suggested
- Njvc LLC is looking for a Cybersecurity Analyst (Vulnerability Management & Continuous Monitoring) in Oakton, VA. This role supports DoD cybersecurity operations, focusing on vulnerability management and compliance activities. Candidates must have 5+ years of experience...
- ...requirements, and internal policy standards • Assist in governance activities, risk assessments, and reporting processes • Maintain vulnerability management standard, procedures, and guidelines • Identify vulnerabilities requiring risk escalation and exception review •...Full timeTemporary workRelocation
$90k - $155k
...another tech company. We’re a community of innovators, engineers, analysts and business professionals working together with our... ...amazing new professionals to join our team. ABSC is seeking a Vulnerability Management Analyst to join our team supporting the Air Force...Contract workRemote workFlexible hours- Company Description KRG Technologies Inc. Job Description Job Title: Network and security Admin Location: Herndon, Virginia Duration: CONTRACT(6-12months) Job Description: ~ Minimum 5 years of hands-on skills on one or more of the following...Full timeContract workWork at office
- ...Information Technology (TSA IT) Task Order (TO) by performing security attacks against all types of IT assets, and exploiting vulnerabilities found to determine if further reach within the engagement scope can be obtained. Provide final reports and presentations of the...Full timeFor contractors
- Areté seeks a Vulnerability Management Analyst to own the end-to-end remediation cycle across desktops, servers, and network devices at our Falls Church, VA facility. You will scan, prioritize, qualify patches, deploy, and verify closures while coordinating with Cyber...
- ...Rate: Open to W2 ONLY (no c2c) Great opportunity with top-tier financial institution! We are currently seeking a Software Test Analyst/QA Analyst with 2–5 years of professional, hands-on QA/testing experience, in banking or financial services, with demonstrated experience...Contract workTemporary workLocal area3 days per week
- ...Cyber Network Defense Analyst (CNDA) Our partner provides remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution using host-based, network-based and cloud-based cybersecurity analysis...Immediate startRemote work
- ...The Computer Network Defense Analyst uses information collected from a variety of sources to monitor network activity and analyze it for evidence of suspicious behavior. Monitoring and analysis are performed to identify and report events that occur, or might occur, within...Local areaImmediate startFlexible hours
- ...Cyber Network Forensic Analyst III, TS/SCI Raytheon Technologies provides remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution using host-based, network-based and cloud-based cybersecurity...Immediate startRemote work
$500 per month
Become a Professional Game Tester We're looking for passionate gamers to join our elite team of mobile game testers. Get paid to play and test the latest games before they launch. $500+ Avg Monthly Pay 5-10 Hours/Week 100% Remote Position Requirements: ...Extra incomeRemote work10 hours per week$86.8k - $198k
Enterprise Cybersecurity Vulnerability Analyst, SeniorThe Opportunity:Support Booz Allen Hamilton's internal Enterprise Cybersecurity team by utilizing enterprise-level vulnerability scanning and assessment tools to identify internally and externally facing vulnerabilities...Full timeContract workPart timeWork at officeLocal areaRemote work$106.5k - $197.5k
L3Harris is dedicated to recruiting and developing high-performing talent who are passionate about what they do. Our employees are unified in a shared dedication to our customers' mission and quest for professional growth. L3Harris provides an inclusive, engaging environment...For contractorsLocal areaMonday to FridayFlexible hours- ...Tysons corner, United States | Posted on 06/12/2026 The Digital Forensics Analyst is responsible for collecting, preserving, analyzing, and documenting digital evidence associated with cybersecurity incidents, investigations, legal proceedings, and insider threat cases...
- ...Digital Forensic Analyst Employment Type: Full-Time, Mid-Level CGS is seeking a Digital Forensic Analyst whose primary focus will be on the preservation & collection of mobile device and cloud-stored data. This candidate should be fluent in a broad range of forensic...Full timeWork at officeRemote workFlexible hours
- ...JOB DESCRIPTION Iron EagleX is seeking a SME Cyber Network Analyst to join our fast-paced technical team. In this role, you will... ...pathways to identify relationships, dependencies, vulnerabilities, and potential operational access paths. ~ Perform packet...Contract work
- Nightwing Group is seeking a Cyber Network Forensic Analyst IV in Arlington, VA to support onsite incident response for a U.S. Government customer. You will assist the government lead, coordinate teams, and drive investigations to assess breach severity and craft remediation...
- Raytheon Technologies is seeking a Cyber Network Forensic Analyst III to contribute to advanced cybersecurity operations. This role involves monitoring network activity to identify and analyze cyber threats, ensuring the protection of information systems. As part of a specialized...Remote job
$122k - $253k
## Cyber Network Forensic Analyst IVApplylocations: Arlington, VAtime type: Full timeposted on: Posted Todayjob requisition id: JR10... ...include cyber space operations, cyber defense and resiliency, vulnerability research, ubiquitous technical surveillance, data intelligence...Contract workImmediate start- System Security EngineerThis position plays a hands-on role securing systems that support critical Defense and Intelligence missions. This position is focused on applying risk management frameworks, engineering security controls, and maintaining system authorizations for...
$100k - $116k
...meaningful results. This is a contingent position based upon customer approval. SkyePoint Decisions is seeking a Mid-Level Digital Forensic Analyst to support the Diplomatic Security Cyber Mission (DSCM) program providing leading cyber and technology security experience to...Contract workInterim roleLocal areaRemote work- ...assessment, treatment, acceptance, and reporting, including vulnerabilities, threat intelligence, identity and access risk, cloud and infrastructure... ...and indirect leadership of security professionals, managers, analysts, advisors, vendors, and cross-functional contributors.Defines...Work at officeRemote workRelocationVisa sponsorshipRelocation package
$86k - $138k
Peraton is seeking a Mid-Level Digital Forensic Analyst in Arlington, VA. This role involves recovering and analyzing digital evidence to support investigations, utilizing industry-standard tools like Cellebrite and Magnet Axiom. A Bachelor's degree with 5 years of experience...- ...position conducts penetration tests, adversary emulation exercises, vulnerability exploitation, security validation, and red team assessments... ...with Security Engineers, Security Architects, ISSOs, SOC Analysts, Threat Hunters, Incident Responders, System Owners, and...Full timeWork at officeRemote work
- ...documenting and operating programs. Maintains communication with users concerning program problems. May work with Business Systems Analysts to obtain project specifications and discuss. designs. Emphasis on knowledge of UI testing and test automation tools (must be...Full time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to VULNERABILITY MGMT ANALYST. Be the first to apply!




