Vulnerability Analyst
$100k - $130kSignal Hill Technologies
Employment Type Full-time Signal Hill Technologies is seeking a highly skilled Vulnerability Analyst to support our federal client's vulnerability management program. The position is contingent upon contract award and is anticipated as full-time/permanent. This role is responsible for identifying, assessing, and reporting on vulnerabilities across enterprise systems, networks, and applications, and for driving remediation efforts in coordination with system owners and cyber defenders. This position is on-site in Fairfax, VA. About Signal Hill Technologies Founded and led by veteran cyber operators, Signal Hill Technologies delivers advanced cybersecurity solutions to DoD, Intelligence Community, financial services, and critical infrastructure clients, with many years of experience defending both US Government and commercial clients against sophisticated, well‑funded, motivated adversaries. We are relentless about real results and operationally proven expertise. Our mission is to provide the best technical solutions and hands‑on support to address each customer's unique cyber risks. Position Responsibilities Perform technical and non‑technical risk and vulnerability assessments across the local computing environment, network and infrastructure, enclave boundary, supporting infrastructure, and applications. Conduct recurring and ad‑hoc vulnerability scans using Tenable Nessus (Nessus Professional, Tenable.sc, and/or Tenable.io), and analyze results to identify, prioritize, and track findings through remediation. Prepare audit and assessment reports identifying technical and procedural findings, with clear, actionable remediation and mitigation recommendations for system owners and leadership. Serve as the primary point of contact for system owners, walking them through scan results and advising on remediation priorities. Analyze the organization's cyber defense policies and configurations and evaluate compliance with applicable regulations, directives, and enclave/local policy. Maintain and operate a deployable cyber defense audit toolkit (scanning software/hardware) in support of assessment missions. Maintain current knowledge of applicable cyber defense policies, regulations, and compliance frameworks relevant to vulnerability assessment and auditing (e.g., NIST RMF, DISA STIGs). Measure the effectiveness of defense‑in‑depth architecture against known and emerging vulnerabilities. Track vulnerability trends and metrics over time, and brief technical and non‑technical stakeholders (including leadership) on posture, risk, and compliance status. Coordinate with system/application owners, ISSOs/ISSMs, and engineering teams to validate findings and support timely remediation. Support the development and refinement of vulnerability management processes, scanning schedules, and reporting standards. Minimum Qualifications Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or a related technical field. Public Trust eligible (U.S. citizenship or green card required and ability to pass a background investigation). 2+ years of experience conducting network, system, or application vulnerability assessments. Strong collaborative and interpersonal skills, with a customer‑service mindset, and the ability to clearly communicate technical findings and actionable guidance in a diplomatic and approachable manner. Hands‑on, in‑depth experience with Tenable products including Tenable Nessus Professional. Working knowledge of network security architecture (topology, protocols, defense‑in‑depth) and traffic flows across TCP/IP and OSI layers. Experience with operating system hardening standards, such as CIS or DISA STIGS. Ability to analyze scan output, correlate findings, and produce clear written reports for both technical and executive audiences. Proficiency with Microsoft Office Suite and SharePoint for documentation and collaboration. Preferred Qualifications Direct experience supporting a federal civilian agency vulnerability management program. Experience working with legacy operating systems and Linux. Experience developing or delivering vulnerability management training or documentation for technical staff. Certifications: e.g. Security+ CE, CySA+, GSEC or equivalent. Knowledge of the MITRE ATT&CK framework. Compensation: $100k-$130k depending on experience. Company health plan. 401(k) plan with employer match. Paid holidays and paid time off. Signal Hill Technologies is an equal opportunity employer. We do not discriminate based on race, color, religion, sex, national origin, age, disability, protected veteran status, or any other characteristic protected by applicable law. #J-18808-Ljbffr Signal Hill Technologies
- ...work with all levels of the "business" Top 5 Technical Skills Tenable Qualys MS Office Experience with CVE Experience with Vulnerability Management Top 2 Soft Skills Great written and verbal communication skills Ability to work with all levels of the "business"...SuggestedContract work
- Job Description We are seeking a Penetration Tester to join our team! You will implement security measures for the protection of computer networks and information. Responsibilities Implement and monitor daily security alerts Report and respond to any security breaches ...SuggestedApprenticeship
$131.3k - $237.35k
...for a cyber security professional to conduct penetration testing and ethical hacking, to target, assess, and exploit risk and vulnerabilities of information systems. This candidate is expected to have hands on penetration testing experience. In addition to technical skills...Suggested- Mission Technologies, a division of HII, is looking for a skilled professional in vulnerability management in Fairfax, Virginia. The successful candidate will support Department of Defense cybersecurity efforts, ensure accuracy in vulnerability assessments, and maintain...Suggested
- ...Koniag IT Systems, LLC, a Koniag Government Services company, is seeking a Cyber Vulnerability Analyst (Encryptor Specialist) with a TS/SCI security clearance to support KPS and our government customer in Falls, Church, VA. We offer competitive compensation and an extraordinary...SuggestedWork at officeLocal areaRemote workFlexible hours
- Company Description KRG Technologies Inc. Job Description Job Title: Network and security Admin Location: Herndon, Virginia Duration: CONTRACT(6-12months) Job Description: ~ Minimum 5 years of hands-on skills on one or more of the following...Full timeContract workWork at office
- ...supporting a U.S. Government customer to provide cybersecurity vulnerability analysis support to reduce the prevalence and impact of... ...Infrastructure Key Resources (CIKR). The Cybersecurity Vulnerability Analyst utilizes cybersecurity best practices, risk management...
$106.5k - $197.5k
L3Harris is dedicated to recruiting and developing high-performing talent who are passionate about what they do. Our employees are unified in a shared dedication to our customers’ mission and quest for professional growth. L3Harris provides an inclusive, engaging environment...For contractorsLocal areaMonday to FridayFlexible hours$80k - $120k
...Digital Forensic Analyst Employment Type: Full-Time, Mid-Level Department: Forensics CGS is seeking a Digital Forensic Analyst whose primary focus will be on the preservation and collection of mobile device and cloud-stored data. This candidate should be fluent in a broad...Full timeWork at officeRemote workFlexible hours$100k - $145k
...innovative, creative, and energetic group of team members supporting a government client. Steampunk is looking for a Digital Forensics Analyst to support one of our federal customers. The Digital Forensics Analyst will support a dynamic team that provides engineering...$117.52k - $197.6k
...systems are built, assessed, and operated in compliance with DoD and NIST requirements. From managing RMF and ATO packages to driving vulnerability remediation and system hardening, this role is central to maintaining secure, mission‑ready systems throughout their lifecycle....RelocationRelocation package- ...benefits, and ongoing learning opportunities, backed by a culture that values and supports our team. We are seeking a Vulnerability Management Analyst (Tenable/Nessus & Metrics) to support vulnerability tracking, remediation coordination, and security metrics reporting...Full timeWork from homeFlexible hours1 day per week
- ...posture of integrated hardware and software environments. You will support DoD information assurance activities, RMF execution, vulnerability management, and continuous monitoring in an Agile Scrum environment. Responsibilities * Oversee Information Assurance...
- ...perspectives, and sharing the wins. That's why we have our eyes on you. What’s the role? Tevora is seeking an Information Security Analyst to join the SOC Compliance team.This role on the SOC Compliance team is looking for a passionate individual who has a solid balance...Internship
- ...standards. You will work closely with other IT teams to identify vulnerabilities, develop security protocols, and monitor systems for... ...Information Security Officer, Cybersecurity Officer, Security Analyst, Information Assurance Officer, Security Architect, Security...Temporary workFor contractorsImmediate startFlexible hours
- Senior Cybersecurity Engineer The Senior Cybersecurity Engineer serves as a subject matter expert in ensuring system security compliance and risk management throughout the program life cycle. This role involves driving Authorization to Operate (ATO) efforts, implementing...Full timeInterim roleFlexible hours
$80k - $115k
...tests Perform system self-assessments as part of an Ongoing Authorization program Monitor and respond to Information Security Vulnerability Management (ISVM)/Patch Management Provide audit support for assigned systems (Financial, A-123, FISMA, internal, DHS, etc.),...Local areaFlexible hours- At Excelity, we're passionate about delivering innovative technology solutions that help businesses thrive. Whether you're looking to streamline your operations, improve efficiency, or enhance customer engagement, our team of experienced professionals is here to help. ...Contract workTemporary workWorldwideFlexible hours
- ...standards. You will work closely with other IT teams to identify vulnerabilities, develop security protocols, and monitor systems for... ...consulting services in information technology, cybersecurity, and analyst workforce development. At our company, you come first. We'...Temporary workFor contractorsImmediate startFlexible hours
- Tysons corner, United States | Posted on 06/12/2026 The Digital Forensics Analyst is responsible for collecting, preserving, analyzing, and documenting digital evidence associated with cybersecurity incidents, investigations, legal proceedings, and insider threat cases...
- ...ownership of outcomes. What You'll Bring You bring experience supporting classified networks and possess a strong understanding of RMF, vulnerability management, security architecture, system hardening, and incident response. You enjoy working across disciplines and partnering...
- ...ICD 503, FedRAMP, FISMA, and agency-specific policies. Prepare for and support audits, inspections, and assessments. Conduct vulnerability scanning, compliance checks, risk assessments, and remediation tracking using tools such as Nessus or Tenable.sc. Create and...
$99k - $225k
...years of experience as an ISSO or Information System Security Analyst (ISSA) ~ Experience conducting tools assessments and configuration... ...and reviewing tool or capabilities topologies, CONOPS, and vulnerability scans to assess risk Experience with cyber-related tools...For subcontractor$62k - $141k
...Experience executing the analysis, design, and implementation of enterprise cybersecurity solutions Experience maintaining vulnerability scanning tool compliance and patch management, including ensuring IT staff pushes patches to all systems, maintaining compliance...Full timeContract workPart timeWork at officeLocal areaRemote work- ...process on program systems/networks. Performs or reviews technical security assessments of computing environments to identify vulnerabilities, non-compliance with IA standards and regulations, and recommends mitigation strategies. Validates and verifies system...
- ...functional teams to oversee system security assessments, monitor for vulnerabilities, and respond to potential threats. The ideal candidate is... .... *** SIMILAR CAREER TITLES Cybersecurity Analyst, Information Security Specialist, Security Compliance Officer...Temporary workFor contractorsImmediate startFlexible hours
$129.81k - $172.5k
...Certified Information Systems Security Professional (CISSP). ~ Experience in documenting security incidents and performing security vulnerability assessments. ~ Experience working with Agile teams and SAFe to perform testing and uncovering system and network...Temporary workWork experience placementWork at officeImmediate startWork from homeWorldwideFlexible hours- ...potential security weaknesses and recommend improvements to amend vulnerabilities, implement changes, and document upgrades. Maintain... ...of five (5) years experience as an Information Assurance (IA) Analyst, ISSE, ISSO, or similar role in ATO package development, including...Full timeLocal areaRemote workFlexible hours
- Information Systems Security Officer (ISSO) Mantis Security is a leading specialty firm of high caliber talent who specialize in Cyber Operations, Cyber Defense, Information Assurance, Software Development, DevSecOps, Security Engineering, and Cloud Engineering. We ...Immediate start
$210k - $235k
...security experience with methods and tools used to improve the security posture of critical systems such as identifying risks, vulnerabilities, anomalies, patching, auditing, automation, security hardening, best practices, and evaluating system changes. In addition, the...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vulnerability Analyst. Be the first to apply!


