Vulnerability Management Analyst
Foxhole Technology Inc
Work Arrangement: Hybrid, Clearance: Secret Foxhole Technology provides robust cybersecurity and IT support capabilities for federal civilian and defense agencies. A recognized leader in navigating technology and security challenges, Foxhole delivers mission-focused innovations to answer evolving and complex needs. Our talented employee-owners provide agile, scalable services and solutions that solve operational gaps, operate critical systems, and protect and secure the enterprise – across the organization and around the world . Foxhole Technology is seeking Vulnerability Management, Tenable/Nessus & Metrics Analyst to support vulnerability management, security metrics, remediation tracking, and dashboard reporting in a federal-civilian technology environment, in a hybrid capacity in Rosslyn, VA. This role is designed for an analyst with approximately 1-3 years of relevant experience who can work hands-on with Tenable/Nessus data, Excel, Power BI, iPost exports, ticketing records, and remediation evidence. The analyst will help identify affected systems, validate findings, track remediation ownership, monitor KEVs and Critical/High vulnerabilities, reconcile data across sources, and support leadership reporting. The role should be positioned as an execution and coordination role. The analyst will not be expected to own enterprise security operations, perform all production patch deployments, or act as the ISSO. The analyst will support the Federal Security apparatus and product/application teams by making vulnerability data accurate, actionable, and reportable. Job Description Tenable/Nessus Vulnerability Analysis, Ad Hoc Scanning, and Native Dashboards Perform and Review Tenable/Nessus scan exports and dashboards to identify affected assets, plugins, CVEs, severity, first-seen dates, last-seen dates, plugin output, vulnerability age, and remediation guidance. Run approved ad hoc Tenable/Nessus scans when requested by Security, product teams, ISSO, or leadership, using approved scan templates, credentialed scan profiles, scan windows, and target lists. Create and maintain Tenable/Nessus native dashboards, saved views, reports, filters, asset groups/tags where permitted, and recurring exports for KEVs, Critical/High findings, stale findings, aging, ownership, and validation status. Monitor scan jobs, confirm scan completion, export results, identify scan failures or credential issues, and elevate scan coverage or authentication problems to senior security staff or platform administrators. Help validate whether findings are true positives, duplicates, stale/residual artifacts, configuration issues, missing patches, unsupported software, or application dependencies. Use Tenable/Nessus evidence to support ownership assignment, remediation planning, retest validation, and closure evidence. Reconcile Tenable/Nessus data against iPost, ServiceNow/CA ServiceDesk, Jira, POA&M trackers, Excel files, SharePoint trackers, and remediation evidence. Escalate unclear Tenable/Nessus findings to senior security staff, system owners, application teams, SO/Windows Services, infrastructure, database teams, or ISSO stakeholders for ownership decisions. Operate within approved rules of engagement. The role may run authorized ad hoc scans and build Tenable reports, but is not expected to be the enterprise Tenable platform administrator or final approver for scan policy changes Minimum Requirements 1-3 years of experience in cybersecurity operations, vulnerability management, security operations, cyber GRC, IT operations, application support, or related technical/security work. Hands-on exposure to Tenable/Nessus vulnerability data, including plugins, CVEs, severity, affected assets, plugin output, first-seen/last-seen dates, and remediation guidance. Ability to run authorized ad hoc Tenable/Nessus scans using approved scan templates, target lists, credentials, scan windows, and documented rules of engagement. Ability to create or maintain Tenable/Nessus dashboards, saved filters, reports, and exports for vulnerability review and remediation tracking. Ability to work with vulnerability exports from Tenable/Nessus and organize findings in Excel, Power BI, SharePoint, Jira, ServiceNow/CA ServiceDesk, or similar tools. Working understanding of vulnerability management concepts such as severity, KEV, CVE, false positive, remediation evidence, rescan validation, aging, ownership, dependencies, risk acceptance, and due dates. Intermediate Power BI or reporting experience, including data imports, transformations, tables, charts, filters, slicers, and dashboard maintenance. Strong Excel skills, including filtering, lookups, pivots, conditional formatting, data cleanup, and comparison across exports. Ability to communicate clearly with technical teams and non-technical stakeholders about finding status, blockers, evidence, and next steps. Strong attention to detail and willingness to reconcile messy data across multiple sources. Familiarity with iPost, Tenable/Nessus, ServiceNow, Jira, ServiceDesk, SharePoint, Power BI, Splunk, or similar reporting/security tools. Exposure to application development, product teams, DevSecOps, SAST, SCA, DAST, container scanning, secrets scanning, or SBOM tooling. Experience tracking EOL/EOS software, patch compliance, POA&M aging, remediation exceptions, risk acceptance, or closure evidence. Requirements of position: Think analytically, effective verbal and written communication skills, make decisions, observe/remember details, interpret data, concentrate on tasks, adjust to change, handle stress/emotions. Regular attendance, maintain work schedule, attend meetings, meet deadlines, keyboard/type, handle confidential information, use math/calculations, stay organized, operate office equipment, may direct others. May be exposed to dust/dirt, humidity, and noise Foxhole Technology is an Equal Opportunity Employer and makes hiring decisions without regard to race, color, religion, sex (including pregnancy, childbirth and sexual orientation), national origin, age, disability, genetic information, military/veteran status, or any other protected class. #J-18808-Ljbffr Foxhole Technology
- cFocus Software seeks a Vulnerability Management Analyst to join our program supporting the United States International Defense Finance Agency (DFC). This position is remote. This position requires an Active Public Trust clearance. Qualifications: ~ Active Public...SuggestedFull timeFor contractorsRemote work
- Foxhole Technology is seeking a Vulnerability Management, Tenable/Nessus & Metrics Analyst to support vulnerability management, security metrics, remediation tracking, and dashboard reporting in a federal civilian technology environment. The role is hybrid in Rosslyn,...Suggested
$90k - $155k
...tech company. We’re a community of innovators, engineers, analysts and business professionals working together with our customers... ...new professionals to join our team. ABSC is seeking a Vulnerability Management Analyst to join our team supporting the Air Force National...SuggestedContract workRemote workFlexible hours- Absolute Business Solutions Corp (ABSC) is recruiting a Vulnerability Management Analyst to strengthen cybersecurity for the AFNCR ITS2 program, supporting the Pentagon, JB Andrews, and JBAB. The role emphasizes vulnerability detection, remediation, and compliance across...SuggestedRemote job
- ...contribute to transformative projects across banking, wealth management, and insurance sectors. If you're passionate about AI and eager... ..., risk assessments, and reporting processes• Maintain vulnerability management standard, procedures, and guidelines• Identify vulnerabilities...SuggestedFull timeTemporary workRelocation
$115k - $131k
...Job Description Job Description Copper River Cyber Solutions is seeking a highly motivated The Vulnerability Management Analyst to support the NIH cybersecurity program by identifying, analyzing, tracking, and reporting security vulnerabilities across enterprise...Contract workLocal areaFlexible hours- Job Title: Mid-Level Vulnerability Management Analyst Location: Bethesda, Maryland Type: Direct Hire / Perm Work Model: 99% remote with occasional onsite for meetings Security Clearance: Public Trust Position Summary The Mid-Level Vulnerability Management Analyst performs...Permanent employmentLocal areaRemote work
$87.1k - $157.45k
Leidos has a career opportunity for a Vulnerability Management Analyst to support the Air Force National Capital Region IT Services program. The AFNCR IT Services program provides support services for information systems for Headquarters Air Force (HAF), Air Force District...Work at officeWorldwide$104k - $166k
Responsibilities The Vulnerability Management Analyst will support the Federal Aviation Administration (FAA) under the BNATCS contract, providing specialized cybersecurity and risk management services to help protect National Airspace System (NAS) systems, enterprise infrastructure...Contract workLocal areaRemote workShift work- System One in Bethesda, MD is seeking a Mid-Level Vulnerability Management Analyst to perform vulnerability scanning, analysis, reporting, and remediation tracking across NIH/OD-managed systems. You will coordinate with stakeholders, monitor CVE sources, and develop remediation...Remote job
- SkyePoint Decisions is seeking a Vulnerability Management Analyst to identify, analyze, track, and report security vulnerabilities across enterprise systems, applications, databases, cloud environments, and network infrastructure. The Analyst collaborates with system owners...Remote job
$86.8k - $198k
Enterprise Cybersecurity Vulnerability Analyst, SeniorThe Opportunity:Support Booz Allen Hamilton's internal Enterprise Cybersecurity team by... ...SLA levels. Conduct analysis and serve as a vulnerability management resource supporting the company's client-facing and internal...Full timeContract workPart timeWork at officeLocal areaRemote work- DescriptionSAIC is seeking a highly skilled Senior Vulnerability Analyst with a strong technical background to join our team in support of a... ...to work with a team responsible for Patch and Vulnerability Management, contributing to the security and integrity of vital...2 days per week
- A leading cybersecurity consultancy is seeking a Cybersecurity Vulnerability Analyst based in Arlington, VA. The role requires an active Top Secret Security Clearance and 5+ years of experience, focusing on vulnerability analysis for federal clients. Candidates must exhibit...
- Cybersecurity Vulnerability Analyst (Incident Manager III) Description Supporting our prime contractor and their U.S. Government customer to provide cybersecurity vulnerability analysis support to reduce the prevalence and impact of vulnerabilities and exploitable conditions...For contractors
- ...S. Government customer to provide cybersecurity vulnerability analysis support to reduce the prevalence and impact... ...(CIKR). The Cybersecurity Vulnerability Analyst utilizes cybersecurity best practices, risk management techniques, critical thinking, and strong analytical...
$104k - $166k
ResponsibilitiesPeraton is currently seeking a Senior Risk and Vulnerability Analyst.Location: Chandler, AZ or Washington DCRole and... ...years of experience in security operations, vulnerability management, or risk analysis. 6 years of experience with a Masters Degree...Contract workShift work- ...upon contract award ***Overview SOSi is seeking a Risk and Vulnerability Analyst II to support vulnerability assessment and risk analysis activities... ...to support tool operations, testing, and vulnerability management activitiesQualifications· Experience:Three (3) to five (5)...Contract workWork at officeWorldwideMonday to FridayWeekend workAfternoon shift
- ...Phoenix Cyber is looking for Vulnerability Analysts to join our client delivery team. This is a remote position. Provide technical leadership and oversight to vulnerability threat management activities and initiatives Develop and implement strategies to manage and...Full timeRemote work
- NTT DATA seeks a Cybersecurity and Risk Analyst to join the VAPT team, identifying and mitigating cybersecurity risks across enterprise systems, networks, and applications. You will perform vulnerability assessments, risk evaluations, and threat simulations aligned with...
- ...mitigation plans Oversee analysis and reporting of security vulnerabilities across systems Perform vulnerability scans, analyze results,... ...papers Requirements 8+ years of experience in vulnerability management and analysis Experience with enterprise vulnerability scanning...
- ...Job Description Job Description One Federal Solution is seeking an experienced Operations Management Analyst to support a Government Client by providing analytical, operational, and program management support for mission-critical initiatives. The successful candidate...
- ...operations, cyber defense and resiliency, vulnerability research, ubiquitous technical... ...Nightwing is seeking a Cyber Incident Manager to support this critical customer mission... ...Compromise (IOCs), escalating to specialized analysts Required Skills U.S. Citizenship...Contract workImmediate startShift workNight shiftWeekend work
$144.2k - $164.6k
Cyber Security Log Management Analyst Capital One is looking for a Cyber Security Analyst to join our Log Management team. This team is responsible for enabling comprehensive cyber monitoring. We ensure standard log events are generated across Capital One so our threat...Full timePart timeH1bLocal area- Mayvin is seeking an experienced Operations Management Analys to support the Department of Homeland Security Federal Protective Service. This is a mission critical position that will support the Government through data analysis and operational and program management support...
$104.8k - $192.2k
...The team works together in planning, pursuing, delivering and managing engagements to assess, improve, build, and in some cases... ...relevant by researching and discovering the newest security vulnerabilities, attending and speaking at top security conferences around the...For contractorsSummer holidayWork at officeLocal areaFlexible hours- ...risks, policies, and mitigation plans. The role includes leading vulnerability analysis across multiple systems and guiding remediation... ...expert presentations. Required are 8+ years in vulnerability management, experience with Tenable.sc/Nessus/ACAS, and knowledge of NIST...
- ...$127,898 Per year (FV J)Dates: Open 08/06/2026 to 08/17/2026Schedule: Full-timeWork type: PermanentRelocation: FalsePosition ID: AWA-AJI-26-5775TY-99743Document ID: 879426900Grade: FV JJob category: Management And Program Analysis (0343)Hiring path: fed-internal-search
- SummaryAll Native Group is seeking a Management and Program Analyst II position to provide skilled — and largely independent — administrative analytical and evaluative work to program operations and, management and organizational efficiency and productivity for the assigned...Full timeContract workFor contractorsWork at officeImmediate startOverseasMonday to FridayWeekend workAfternoon shift
- ...subject matter expert in a specialized area. Formulates LOB/SO management policies and systems. Participates and provides direction to... ...intensity that they often require input and assistance from other analysts and subject-matter specialists in field appropriate to the...Full timePart timeFor contractors
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vulnerability Management Analyst. Be the first to apply!
- penetration tester Arlington, VA
- vulnerability analyst Arlington, VA
- ethical hacker Arlington, VA
- public sector business analyst Arlington, VA
- knowledge management analyst Arlington, VA
- business analyst healthcare Arlington, VA
- business strategy analyst Arlington, VA
- servicenow business analyst Arlington, VA
- business analyst law firm Arlington, VA
- configuration management analyst Arlington, VA

