Vulnerability Analyst
$69.55k - $125.73kLeidos
Description
We are currently seeking a Vulnerability Analyst to join the Compartmented Enterprise Services Office (CESO) effort. This program is establishing a modern secure web service (SWS) operation as part of a state-of-the-art, highly automated platform capable of supporting a rapidly expanding customer population. Apply today to become part of the Leidos team assisting CESO as it migrates to a high security cloud environment, providing vulnerability management, risk assessment, and compliance services that protect the integrity of the platform throughout its lifecycle.
This position is based in Arlington, VA and is 100% on-site.
Requires a TS/SCI US Government Security Clearance to start.
Primary Responsibilities
Responsible for meeting both regulatory (Legal and Mandated Requirements) and non-regulatory (Real-World Threat Reduction) compliance demands across the CESO environment.
Assist in the management and maintenance of the IAVA (Information Assurance Vulnerability Alerts) program for CESO systems.
Manage and enforce information security policies, and train and educate end-users on proper security practices.
Conduct security and risk assessments using established frameworks (e.g., NIST, RMF, Common Criteria), mitigating risk via security controls and testing and evaluation to certify and accredit commercial security products used within the CESO platform.
Develop, update, organize, maintain, and track RMF documentation using information obtained from the customer.
Ensure privacy of data throughout its lifecycle; perform vulnerability management (scanning, assessment, reporting, and mitigation verification), business continuity, and disaster recovery activities.
Coordinate with infrastructure, storage, database, and application teams to align vulnerability management activities with CESO's operational and compliance requirements.
Maintain documentation, operational procedures, and compliance reports supporting CESO's secure cloud migration.
Responsible for a combination of duties to protect information and maintain security controls across the CESO system, site, or program in order to reduce risk.
Basic Qualifications
Bachelor's degree and 2+ years of related IT security experience; additional experience, education, or training may be considered in lieu of degree.
Active TS/SCI security clearance required
DoDD 8140 compliant certification, at minimum IAT Level II (e.g., Security+ CE), at start.
Experience with the Defense Information Systems Agency (DISA) security model, controls, and authorization processes for standard computing systems and cloud computing across the Department of Defense
Experience conducting activities associated with Information Assurance Vulnerability Alerts (IAVA) for example, Cybersecurity and Infrastructure Security Agency (CISA).
Experience with creating Information Assurance documentation such as Security Control Traceability Metrics (SCTM), Risk Assessment Report (RAR), Security Assessment Report (SAR) and maintaining POA&Ms (Plans of Action and Milestones).
Experience with ACAS and SEIM tools.
Experience with application and hardware security settings for vendor and/or DISA best business practices.
Candidate may be asked to obtain a CI Polygraph in the future.
Preferred Qualifications
Prior experience with DISA and DISA's support to mission partners.
TS/SCI with CI Polygraph preferred.
Experience with ACAS, SPLUNK, ACT (cybersecurity event), IAVA reporting, and eMASS.
Familiarity with vulnerability management across enterprise applications and infrastructure (e.g., Oracle, SQL Server, Exchange, virtualization platforms, Windows, Red Hat).
Understanding of disaster recovery and business continuity concepts as they apply to secure cloud migrations.
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.
Original Posting:
September 22, 2026
For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
Pay Range:
Pay Range $69,550.00 - $125,725.00
The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
About Leidos
Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit .
Pay and Benefits
Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at .
Securing Your Data
Beware of fake employment opportunities using Leidos’ name. Leidos will never ask you to provide payment-related information during any part of the employment application process (i.e., ask you for money), nor will Leidos ever advance money as part of the hiring process (i.e., send you a check or money order before doing any work). Further, Leidos will only communicate with you through emails that are generated by the Leidos.com automated system – never from free commercial services (e.g., Gmail, Yahoo, Hotmail) or via WhatsApp, Telegram, etc. If you received an email purporting to be from Leidos that asks for payment-related information or any other personal information (e.g., about you or your previous employer), and you are concerned about its legitimacy, please make us aware immediately by emailing us at View email address on click.appcast.io .
If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission ( .
Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.
REQNUMBER: R-00192830
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status. Leidos will consider qualified applicants with criminal histories for employment in accordance with relevant Laws. Leidos is an equal opportunity employer/disability/vet.
- DescriptionSAIC is seeking a highly skilled Senior Vulnerability Analyst with a strong technical background to join our team in support of a critical US government agency in the National Capital Region. This is an exciting opportunity to work with a team responsible for...Suggested2 days per week
$86.8k - $198k
Enterprise Cybersecurity Vulnerability Analyst, SeniorThe Opportunity:Support Booz Allen Hamilton's internal Enterprise Cybersecurity team by utilizing enterprise-level vulnerability scanning and assessment tools to identify internally and externally facing vulnerabilities...SuggestedFull timeContract workPart timeWork at officeLocal areaRemote work- Areté is looking for the person who makes sure vulnerabilities actually get closed - not just found. As our Vulnerability Management Analyst in Falls Church, VA, you will own the end-to-end remediation cycle - scanning, prioritization, patch qualification, deployment, and...SuggestedFull time
- A leading cybersecurity consultancy is seeking a Cybersecurity Vulnerability Analyst based in Arlington, VA. The role requires an active Top Secret Security Clearance and 5+ years of experience, focusing on vulnerability analysis for federal clients. Candidates must exhibit...Suggested
- ...Job Description Job Description Position Overview RiVidium Inc. seeking a highly skilled Senior Vulnerability Assessment Analyst to support enterprise cybersecurity and vulnerability management activities within a federal environment. The successful candidate...SuggestedContract work
- ...supporting a U.S. Government customer to provide cybersecurity vulnerability analysis support to reduce the prevalence and impact of... ...Infrastructure Key Resources (CIKR). The Cybersecurity Vulnerability Analyst utilizes cybersecurity best practices, risk management...
$104k - $166k
ResponsibilitiesPeraton is currently seeking a Senior Risk and Vulnerability Analyst.Location: Chandler, AZ or Washington DCRole and Responsibilities: The Senior Risk and Vulnerability Analyst supports a 24x7 Security Operations Center (SOC) by identifying, analyzing, and...Contract workShift work- ...missions worldwide.Job Description*** This position is contingent upon contract award ***Overview SOSi is seeking a Risk and Vulnerability Analyst II to support vulnerability assessment and risk analysis activities in alignment with our customer. This role is responsible...Contract workWork at officeWorldwideMonday to FridayWeekend workAfternoon shift
- NTT DATA seeks a Cybersecurity and Risk Analyst to join the VAPT team, identifying and mitigating cybersecurity risks across enterprise systems, networks, and applications. You will perform vulnerability assessments, risk evaluations, and threat simulations aligned with...
$130k - $190k
...systems and technologies for the Department of Homeland Security. Responsibilities may include:Conducting cybersecurity assessments, vulnerability assessments, and security control validation in support of federal acquisition-based test and evaluation activitiesPerforming...Full timeWork experience placementWork at officeLocal areaRemote workWorldwideFlexible hours$116.35k - $210.33k
...operational stakeholders.Help close the sensor-to-shooter loop by connecting intelligence, engineering analysis, and operational vulnerabilities.Primary ResponsibilitiesAll-Source Intelligence ReviewReview current intelligence assessments and reconcile available source...Full timeWork at office- ...activities, assessing security posture across enterprise environments, and supporting identification, validation, and reporting of vulnerabilities to improve cyber defense resilience.Responsibilities· Conduct penetration testing across enterprise systems, applications, and...Contract workWork at officeWorldwideMonday to FridayWeekend workAfternoon shift
$86k - $138k
...will: Support the Red Cell Team by performing and leading penetration tests to assess the security of customer systems.Identify vulnerabilities and develop recommended remediations to satisfy mandated NIST 800-53 security controls.Report and demonstrate findings to...Contract workFlexible hoursShift work$104k - $166k
...operations across diverse and high‑impact environments. This role supports critical national security missions by identifying vulnerabilities, emulating real‑world adversaries, and strengthening defensive cyber capabilities across enterprise, cloud, mobile, IoT, and High...Contract workCurrently hiringShift work$90k - $130k
...curated analytics tools, actively identifying and exploiting vulnerabilities to validate and strengthen the platform’s security posture against... ...Penetration Testing Engineer (CPTE)CompTIA CyberSecurity Analyst (CySA+)Federal IT Security Professional-Auditor (FITSP-A)GIAC...Full timeWork at office- Absolute Business Solutions Corp (ABSC) seeks a Vulnerability Management Analyst to strengthen Air Force networks in the AFNCR ITS2 program. On-site work in the National Capital Region with some remote tasks possible with client approval. You will support vulnerability...Remote work
- ...join our cybersecurity team. In this role, you will identify vulnerabilities and test the security of networks, applications, and systems... ...consulting services in information technology, cybersecurity, and analyst workforce development. At our company, you come first. We'...Temporary workFor contractorsImmediate startFlexible hours
- ...Mission Support systems, networks, and applications following approved Rules of Engagement and test plans. Identify and exploit vulnerabilities in network infrastructure, operating systems, web applications, and databases. Participate in red team and blue team...Temporary workFor contractorsLocal areaImmediate start
- ...ResponsibilitiesLead and perform advanced security assessments, including hands-on penetration testing of systems and applications.Identify vulnerabilities, assess risks, and deliver clear, actionable remediation recommendations.Develop and maintain assessment plans aligned withNIST...3 days per week
$124.54k - $180k
....ResponsibilitiesThe Senior Penetration Tester serves as Key Personnel responsible for leading advanced penetration testing and vulnerability assessment activities within a TS/SCI environment. This role ensures mission‑critical security assurance across enterprise systems...Currently hiring$104.8k - $192.2k
...technical expertise and specialized skills. The team stays highly relevant by researching and discovering the newest security vulnerabilities, attending and speaking at top security conferences around the world, and sharing knowledge on a variety of cybersecurity topics...For contractorsSummer holidayWork at officeLocal areaFlexible hours- Driven by Innovation and built on Trust, rockITdata is a unique SDVOSB services company that partners with leading commercial healthcare/life sciences organizations on cutting edge innovations - think AI, automation and data transformation. We then bring those commercially...Full time
- ...business systems. The successful candidate will partner closely with business stakeholders, developers, project managers, business analysts, vendors, and subject matter experts to validate system functionality, ensure data integrity, and support successful software...
- ...someone with a passion for cybersecurity, a deep understanding of application security, and the ability to identify and mitigate vulnerabilities. The successful candidate will play a critical role in ensuring the security of our applications and guiding our security...
$90k - $155k
...another tech company. We’re a community of innovators, engineers, analysts and business professionals working together with our... ...amazing new professionals to join our team. ABSC is seeking a Vulnerability Management Analyst to join our team supporting the Air Force...Contract workRemote workFlexible hours- Arete Associates in Falls Church, VA is seeking a Vulnerability Management Analyst to own the end-to-end remediation cycle from scanning to verification across desktops, servers, and networks. The role requires hands-on patching, risk-based prioritization, and coordination...
$146k - $234k
ResponsibilitiesJob Description:Peraton is seeking an Sr Information Systems Security Officer to support our Federal Strategic Cyber programs.Location: Washington, DC In this role, you will:Apply best practices for cybersecurity program standards, processes, procedures,...Contract workWork experience placementShift work$106.3k - $221.1k
...Penetration Tester will conduct comprehensive penetration tests on applications, networks, and systems. Identify and exploit security vulnerabilities to assess risk, developing detailed reports on findings, and providing recommendations for remediation. Collaborate with other...Live inWork at officeLocal area- ...Human Services (HHS) Office of Inspector General (OIG) Cyber Assessment Team. This position performs advanced penetration testing, vulnerability assessments, security research, exploitation activities, and technical consulting across federal systems, applications, cloud...Part timeWork at office
- ...our sustained growth driven by our people-first approach and unwavering dedication to excellence. This candidate will execute vulnerability identification, scanning, analysis, and coordination to reduce system attack. Maintain disciplined vulnerability workflows from...Work at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vulnerability Analyst. Be the first to apply!


