Vulnerability Management Analyst
$87.1k - $157.45kLeidos
Description
Leidos has a career opportunity for a Vulnerability Management Analyst to support the Air Force National Capital Region IT Services program.
The AFNCR IT Services program provides support services for information systems for Headquarters Air Force (HAF), Air Force District of Washington (AFDW), Office of the Secretary of Defense (OSD), Joint Chiefs of Staff, and other Air Force activities within the AFNCR, missions to include the Pentagon, Joint Base Andrews (JBA), Joint Base Anacostia-Bolling (JBAB), and other locations, leased spaces, and alternate sites. The major support areas required are IT Operations and Maintenance; Plans, Projects, and Engineering (PP&E); and National Military Command Center (NMCC). The senior leaders and national defense missions that are supported require that the AFNCR operations never fail, resulting in a fast-paced, challenging, but also rewarding environment.
If this sounds like the kind of environment where you can thrive, keep reading!
Leidos Defense Group provides a diverse portfolio of systems, solutions, and services covering land, sea, air, space, and cyberspace for customers worldwide. Solutions for Defense include enterprise and mission IT, large-scale intelligence systems, command and control, geospatial and data analytics, cybersecurity, logistics, training, and intelligence analysis and operations support. Our team is solving the world’s toughest security challenges for customers with “can’t fail” missions. To explore and learn more, click here!
Are you ready to make an impact? Begin your journey of a flourishing and meaningful career, share your resume with us today!
POSITION SUMMARY:
Leidos is seeking a Vulnerability Management Analyst to join our Cybersecurity Operations team supporting the AFNCR IT Services (AFNCRIT) program. This T1-level position is ideal for an entry-level cybersecurity professional interested in learning vulnerability management processes. The role will assist with running vulnerability scans using ACAS, reviewing STIG findings, and supporting remediation coordination across Air Force enterprise systems under the guidance of senior team members.
PRIMARY RESPONSIBILITIES:
Assist with scheduling and running vulnerability scans using Tenable SecurityCenter/Nessus (ACAS) in classified and unclassified environments under senior staff guidance.
Review scan results to help identify potential CAT I/II/III findings, false positives, and basic configuration issues.
Support tracking of remediation actions, Plans of Action and Milestones (POA&Ms), and exceptions in accordance with RMF guidance.
Follow established procedures to validate DISA STIG checklists and work with team members to ensure secure system configurations.
Help prepare basic vulnerability reports, compliance summaries, and metrics to support leadership briefings and inspection readiness (e.g., CCRI/CORA).
Assist in maintaining asset groupings, scan zones, and credentialed scanning configurations as directed by senior analysts.
Coordinate with Queue Managers, ISSOs, and Engineering teams to support the remediation of high-priority vulnerabilities.
Maintain data accuracy within ACAS, including proper tagging and grouping for consistent reporting.
BASIC QUALIFICATIONS:
Active DoD Secret clearance required.
CompTIA Security+ CE or higher DoD 8570 IAT Level II certification must meet 8140 ISSM role qualification
Bachelor's Degree and 4-8 years of cybersecurity or system administration experience, with at least 1 year of direct ACAS or Tenable experience. Additional education and years of experience may be considered in lieu of a degree.
Working knowledge of DISA STIGs, vulnerability risk levels, and POA&M remediation strategies.
Familiarity with NIST SP 800-53, RMF compliance, and Air Force cybersecurity policy (AFMAN 17-130).
Strong attention to detail, documentation skills, and the ability to interpret technical vulnerability data.
PREFERRED QUALIFICATIONS:
Experience supporting USAF, DISA, or other DoD mission systems.
Familiarity with eMASS, SCAP Compliance Checker (SCC), or HBSS.
Prior involvement in CCRI/CORA preparation or vulnerability remediation campaigns.
Ability to communicate risk-based recommendations to both technical and non-technical stakeholders.
Understanding of automation tools/scripts (e.g., PowerShell, Nessus APIs) to support scan or report optimization.
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.
Original Posting:
July 13, 2026For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
Pay Range:
Pay Range $87,100.00 - $157,450.00The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
About Leidos
Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit .
Pay and Benefits
Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at .
Securing Your Data
Beware of fake employment opportunities using Leidos’ name. Leidos will never ask you to provide payment-related information during any part of the employment application process (i.e., ask you for money), nor will Leidos ever advance money as part of the hiring process (i.e., send you a check or money order before doing any work). Further, Leidos will only communicate with you through emails that are generated by the Leidos.com automated system – never from free commercial services (e.g., Gmail, Yahoo, Hotmail) or via WhatsApp, Telegram, etc. If you received an email purporting to be from Leidos that asks for payment-related information or any other personal information (e.g., about you or your previous employer), and you are concerned about its legitimacy, please make us aware immediately by emailing us at .
If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the .
Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.
$87.1k - $157.45k
...Description Leidos has a career opportunity for a Vulnerability Management Analyst to support the Air Force National Capital Region IT Services program. The AFNCR IT Services program provides support services for information systems for Headquarters Air Force (HAF), Air...SuggestedWork at office- ...RiVidium is seeking a Vulnerability Management Analyst to support our planned MODES III team supporting Military Community and Family Policy (MC&FP). This role supports IT, Cybersecurity, and Data Operations - Core Operations and helps deliver mission-focused outcomes...SuggestedContract work
- RiVidium is seeking a Vulnerability Management Analyst to support our MODES III team for MC&FP policy. The role spans IT, Cybersecurity, and Data Operations, delivering mission-focused outcomes for service members and families. You will analyze vulnerabilities, coordinate...Suggested
- Infrastructure Vulnerability Management Analyst Contract Alphalogic is a global technology solutions company headquartered in the Washington, DC metropolitan area. Alphalogic offers a wide range of technology and consulting services including predictive analytics, data...SuggestedContract work
- Rividium Inc is seeking a Vulnerability Management Analyst to join their team supporting Military Community and Family Policy. This role involves analyzing vulnerabilities and coordinating corrective actions while maintaining rigorous remediation processes to support IT...Suggested
- Alphalogic, Inc. is seeking an Infrastructure Vulnerability Management Analyst in Washington, DC. The role involves reviewing vulnerability scans, managing security profiles, and performing security analysis using tools like IBM AppScan and Guardium Database Scanner. Ideal...
- Security Vulnerability Management Analyst Full-time Qmulos is recruiting cybersecurity technologists who want to challenge themselves by working with brilliant people to solve some of today’s most important technology problems. As an emerging cybersecurity software company...Full time
- Qmulos, located in Washington D.C., is seeking a Security Vulnerability Management Analyst to provide strategic cybersecurity advisory services and improve federal security programs. You will analyze security architecture, engage stakeholders, and measure software compliance...
- Cybersecurity Vulnerability Analyst (Incident Manager III) Description Supporting our prime contractor and their U.S. Government customer to provide cybersecurity vulnerability analysis support to reduce the prevalence and impact of vulnerabilities and exploitable conditions...For contractors
- ...S. Government customer to provide cybersecurity vulnerability analysis support to reduce the prevalence and impact... ...(CIKR). The Cybersecurity Vulnerability Analyst utilizes cybersecurity best practices, risk management techniques, critical thinking, and strong analytical...
- Our client is seeking a Network Vulnerability Analyst to join their team in Washington, D.C. . As a key part of the security team, you will support various initiatives related to vulnerability management and network security. Responsibilities Operate and manage vulnerability...
- A leading cybersecurity consultancy is seeking a Cybersecurity Vulnerability Analyst based in Arlington, VA. The role requires an active Top Secret Security Clearance and 5+ years of experience, focusing on vulnerability analysis for federal clients. Candidates must exhibit...
- ...and defend your culture. Join USCIS, America's frontline defense against illegal foreign infiltration and fraud. As a Management and Program Analyst, you will be responsible for implementing, coordinating, and supporting major Division-wide operations, services, and programs...Full timeContract workPart timeWork at officeImmediate startRemote workOverseas
- Job Title This position is located in the National Oceanic and Atmospheric Administration (NOAA), National Environmental Satellite, Data, and Information Service (NESDIS), Office of the Chief Financial Officer/Chief Administrative Officer (CFO/CAO), Mission Support ...Work at officeRemote work
- ...Supervisory Management And Program Analyst Protect your homeland and defend your culture. Join USCIS, America's frontline defense against illegal foreign infiltration and fraud. As a Supervisory Management and Program Analyst, you will provide oversight of a wide range...Remote work
- ...Management And Program Analyst This specific position will be filled in Silver Spring, MD. Additional duty locations are listed for future vacancies and/or vacancies that may be filled throughout the Department of Commerce. Please select locations for which you want...
$140.5k - $210.5k
Sr. Cybersecurity Analyst II (Sr Vulnerability Analyst) - Information Technology Primary Location: DC‑Washington Employee Status: Regular Overtime... ...data analysis platforms, security information and event management (SIEM) systems, and security orchestration tools....Work at officeRelocation$140.5k - $210k
...depth solution with a central security information and event management (SIEM) system and security orchestration tools. Develops an expert... ..., eradication, and remediation. Oversees implementation of vulnerability scans and ensures operational systems are adequately patched...Full timeWork at office- ASRC Federal is looking for a Vulnerability Assessor in Alexandria, VA who will support the DoWEA Enterprise Cyber Program. This hybrid role involves identifying and analyzing system vulnerabilities to enhance cybersecurity compliance. The ideal candidate will have over...
- ...Koniag Government Services company, is seeking an experienced Vulnerability Analyst II to support the U.S. Small Business Administration (SBA)... ...effectiveness. Support the development of vulnerability management program documentation—policies, procedures, scanning methodologies...Flexible hours
$107.9k - $195.05k
A leading technology firm seeks an experienced Vulnerability Assessor in Arlington, VA. The role involves assessing and managing vulnerabilities, configuring security scans, and collaborating with teams to enhance cybersecurity capabilities. The ideal candidate should have...$140.5k - $210.5k
The Federal Reserve System is hiring a Sr. Cybersecurity Analyst II in Washington, DC, to oversee the implementation of cybersecurity... ...intelligence analysis, incident response, and leading vulnerability management projects. The position is on-site in Washington and offers...- Position Overview The Department of Environmental Services (DES) is seeking a Transportation Operations Management Analyst to join our Operations team within the Transportation Engineering and Operations (TE&O) Bureau. TE&O manages over 900 miles of roadway and works to...Permanent employmentTemporary workWork at office
- Program Management Operations Analyst III (Mid) Clearance Type: None Scope: Manages and directs the work of project managers and provides managerial financial and administrative oversight for multiple projects. Responsibilities Portfolio Oversight: Monitor project scopes...
- ## (Cyber) Incident Management Analyst - Weekend Night ShiftApplylocations: Arlington, VAtime type: Full timeposted on: Posted Todayjob requisition... ...cyber space operations, cyber defense and resiliency, vulnerability research, ubiquitous technical surveillance, data...Contract workImmediate startShift workNight shiftWeekend work
- A leading IT staffing firm is seeking a Business Systems Analyst III for a critical project with the SEC in Washington, DC. In this role, you will support the Enterprise Management System Team by providing technical services and conducting proof of concepts, while participating...
- Architect of the Capitol in Washington, DC, seeks a qualified specialist to serve as the jurisdiction lead over Family and Medical Leave Act and workers' compensation. The role requires meeting OPM qualification standards for General Schedule positions and ensuring eligibility...
- ...service and not for profit, we measure our success in the impact of our service. Position Overview ANSER is seeking an Operations Management Analyst to support the Office of the Secretary of War (OSW), Director of Administration and Management (DA&M), Organizational and...Contract workWork at officeMonday to Friday
- People, Technology & Processes, LLC is seeking a Program Management Operations Analyst III to oversee project management operations in Washington, D.C. The role involves managing project scopes, costs, and schedules while developing and implementing effective standards...
$109k - $116k
# Management Analyst (Business Analysis, Associate)The MIL CorporationFull TimejuniorArlington, Virginia, USPosted Yesterday## Role OverviewThe MIL Corporation is hiring a entry-level Management Analyst (Business Analysis, Associate). This is a full-time role in Arlington...Full timeContract workWork at officeShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vulnerability Management Analyst. Be the first to apply!
- business analyst law firm Suitland, MD
- business analyst healthcare Suitland, MD
- public sector business analyst Suitland, MD
- records management analyst Suitland, MD
- senior business analyst contract Suitland, MD
- business analyst part time remote Suitland, MD
- business analyst Suitland, MD
- fiserv business analyst Suitland, MD
- management analyst Suitland, MD
- business development analyst Suitland, MD

