Req ID: RQ214272
Type of Requisition: Regular
Clearance Level Must Be Able to Obtain: None
Public Trust/Other Required: MBI (T2)
Job Family: Cyber and IT Risk Management
Skills:
Computer Security Exploits,Cybersecurity,Security Operations,Security Practices,System Security
Certifications:
Tenable Security Center Specialist Certification | Tenable Network Security - Tenable Network Security, Security + - CompTIA - CompTIA, CrowdStrike Certified Falcon Administrator (CCFA) | CrowdStrike - CrowdStrike, Tenable Certified Nessus Auditor (TCNA) | Tenable Network Security - Tenable Network Security, CompTIA Security+ CE | CompTIA - CompTIA
Experience:
4 + years of related experience
Job Description:
Seize your opportunity to make a personal impact as a Cyber Vulnerability Management Analyst to support a federal customer's enterprise cybersecurity program. The analyst will play a critical role in operating and enhancing the Vulnerability Management (VM) lifecycle by analysing vulnerability scan data, validating findings, prioritizing risk, and coordinating remediation activities across complex enterprise environments.
This position requires hands-on experience with enterprise vulnerability scanning tools, strong cyber data analytics skills, and the ability to communicate technical risk clearly to system owners, engineers, and cybersecurity leadership.
Candidates must be able to travel to customer location to obtain badging and fingerprinting prior to starting
Candidate must have resided in the US in the past 3 of 5 years
Responsibilities:
Analyze raw vulnerability scan results and provide clear, actionable findings to system owners and stakeholders
Validate vulnerabilities, identify false positives, and confirm technical risk and exploitability
Provide practical remediation guidance aligned with system architecture and operational constraints
Track vulnerability remediation status and support risk-based prioritization
Works closely with the risk management and other teams to determine system risks based upon vulnerability results and ensure compensating and/or mitigating controls are in place.
Operate and support vulnerability scanning tools across multiple platforms, including Tenable Security Center, Tenable.io, Nessus Manager, Nessus Network Monitor, NetSparker/Invicti Enterprise, CodeDX, Coverty, Black Duck, Seeker, and Guardium Database Scanner.
Has a Solid understanding of networking concepts, including TCP/IP, DNS, DHCP, VPN, and firewalls from a security perspective.
Develop and adhere to Standard Operating Procedures (SOP).
Comfortable with interfacing the customer, cross-functional teams and application owners on vulnerability metrics and findings.
Adhere to Service Level Agreements (SLA) for service request support.
Mentor and train team members & program successors.
Participates in special projects, as needed.
Works with Program and Project management throughout the period of performance.
Supports technical problems that occur and on-call support for non-business hours.
Provide Weekly and on-demand Status Reports on work performed.
Required Skills:
4+ years of cybersecurity experience, with a strong focus on vulnerability management and security operations
3+ years Hands-on experience with enterprise vulnerability scanning tools (Tenable, Nessus, Invicti, etc.)
Strong cyber data analytics skills and experience developing dashboards and reports
Knowledge of current vulnerability trends, exploits, and threat intelligence
Experience working in afederal IT or regulated environment
Ability to manage multiple priorities and work independently with minimal supervision
Strong collaboration and teamwork skills
Strong cyber data analytics skills and experience developing dashboards and reports (Excel, Pivot Tables, charts, graphs, Power BI or other tools)
Must be able to obtain a Public Trust and successfully pass a thorough government background screening process (forms/fingerprinting).
Desired Skills:
Preference to candidates local to the DMV Area.
Experience with MS Office suite (Word, Excel, PP, Visio, SharePoint, etc.)
Experience with NIST, FISMA, and federal cybersecurity policy requirements.
Experience with any HHS agencies or entities (CMS, HRSA, NIH, etc.)
Demonstrated strong technical skills and analytic abilities, as well as experience performing system security analysis and risk management.
Demonstrated experience performing complex technical tasks with minimal direction.
Possesses experience with communicating potentials risks to stakeholders.
Possess a broad knowledge of security best practices, policies and guidance.
The likely salary range for this position is $123,250 - $166,750. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. GDIT typically provides new employees with 15 days of paid leave per calendar year to be used for vacations, personal business, and illness and an additional 10 paid holidays per year. Paid leave and paid holidays are prorated based on the employee's date of hire. The GDIT Paid Family Leave program provides a total of up to 160 hours of paid leave in a rolling 12 month period for eligible employees. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.
We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.
Join our Talent Community to stay up to date on our career opportunities and events at https://gdit.com/tc.
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans