> Markdown version of [/jobs/ext/1181264-vulnerability-analyst-remote](https://www.wearedevelopers.com/jobs/ext/1181264-vulnerability-analyst-remote). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Vulnerability Analyst (Remote) - **Company:** OXLEY ENTERPRISES INC - **Location:** Stafford, VA, United States (Remote available) - **Experience:** Experienced - **Salary:** $90,897.0 - $118,016.0 - **Contract:** Permanent contract - **Skills:** Data Analysis, Software System Penetration Testing, Automation of Tests, CompTIA Security+, Information Systems, Red Team (Cyber Security), Software Vulnerability Management, Software Repository, Information Technology, Tenable Nessus, Patch Management, Nessus, Tools for Reporting, Plan of Action and Milestones, Vulnerability Analysis - **Published:** July 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=c14ab3ec61d46057 ## About the Role Minimum/General Experience: 5 years of experience in vulnerability management or security scanning Minimum Education: Bachelor's Degree in cybersecurity, information technology, or related field; CompTIA Security+ or Global Information Assurance Certification (GIAC) Enterprise Vulnerability Assessor (GEVA) (preferred) Essential Skills/Qualifications: * Expert experience conducting ad-hoc, prescribed, and recurring vulnerability scans using Nessus or equivalent scanning tools * Expert ability to document and report scan findings in accordance with established processes * Excellent experience supporting routine vulnerability scanning of infrastructure, containers, applications, and code repositories * Excellent ability to track, report, and ensure remediation of vulnerabilities * Excellent knowledge of Continuous Monitoring system security reporting tools * Above average ability to support penetration testing, red team activities, and independent security assessments * Above average experience validating security control effectiveness through automated testing and configuration validation * Experience supporting a federal agency * Excellent verbal and written communication skills ## Description Position Description: The Vulnerability Analyst conducts ad-hoc, prescribed, and recurring vulnerability scans across infrastructure, containers, applications, and code repositories, coordinating remediation with Operations and Engineering teams., * Sedentary Work - Exerting up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects. * Typing, communicating, repetitive motions. * Close visual acuity to prepare and analyze data, view computer monitors and read. May need to view presentation screens and other visual aids in a virtual setting. * Inside environmental conditions with protection from outside elements. Security: Active Federal Civilian Public Trust clearance * U.S. Citizenship or Permanent Resident that has lived in the United States for at least 3 years Federal Civilian Public Trust Consists of a review of up to but not limited to: * Covers 10 year period and in some instances lifetime events * OPM Security Investigations Index (SII) * DOD Defense Central Investigations Index (DCII) * National Agency Check (NAC) records * FBI name check * FBI fingerprint check * Credit report check * Written inquiries to previous employers and references listed on the application for employment * Potential interviews with the subject, spouse, neighbors, supervisor, coworkers * Law enforcement check * Court records check * Education check - Attendance and Degrees Acceptable Credentials Tasks/activities include, but are not limited to: * Conducts ad-hoc, prescribed, and recurring vulnerability scans for platform and all hosted applications * Reports scan results to Operations and Engineering team members * Conducts patch management, configuration changes, corrective actions, or Plan of Action and Milestones (POA&M) creation * Documents and reports scan findings in accordance with VA RMF and POA&M processes including uploading scan results to the appropriate scan repository * Performs upkeep of the Continuous Monitoring system security reporting tool and provides high-level reporting to portfolio Information System Owners * Ensures routine vulnerability scanning of infrastructure, containers, applications, and code repositories across production, staging, and sandbox environments * Tracks, reports, and ensures remediation of vulnerabilities within defined timelines coordinating with Operations and Engineering teams * Supports penetration testing, red team activities, and independent security assessments as required * Validates security control effectiveness through automated testing, configuration validation, and periodic assessments * Contributes vulnerability remediation status summaries to the monthly RMF, security, and Authorization to Operate (ATO) status report ## Related Videos - [Data Science in Retail](https://www.wearedevelopers.com/videos/586-data-science-in-retail) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Data Science on Software Data](https://www.wearedevelopers.com/videos/162-data-science-on-software-data) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [The Innovation Formula: Fast Prototyping, Data Analysis, and Real User Insights](https://www.wearedevelopers.com/videos/1421-the-innovation-formula-fast-prototyping-data-analysis-and-real-user-insights) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)