> Markdown version of [/jobs/ext/1490601-systems-vulnerability-analyst-4](https://www.wearedevelopers.com/jobs/ext/1490601-systems-vulnerability-analyst-4). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Systems Vulnerability Analyst 4 - **Company:** Markon, LLC. - **Location:** Fort Meade, MD, United States - **Salary:** $205,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Network Analysis, CompTIA Security+, Computer Networks, Intrusion Detection and Prevention, Information Systems Security Architecture Professional, Python (Programming Language), Network Architecture, Red Team (Cyber Security), Zero Trust Network Access, Scripting, Computer Network Operations, Mitre Att&ck, Reliability of Systems, Purple Team (Cyber Security), Cyber Warfare, Blue Team (Cyber Security), Vulnerability Analysis - **Published:** July 29, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9065089/systems-vulnerability-analyst-4 ## About the Role * TS/SCI with Active Polygraph with this Customer. * Bachelor's degree and 11+ years of experience in cybersecurity, vulnerability analysis, or cyber operations. * Demonstrated experience conducting Red Team assessments and developing mitigation reports. * Experience supporting Blue Team and Purple Team operations. * Experience performing network analysis, anomaly detection, and identifying Indicators of Compromise (IOCs). * Experience applying the MITRE ATT&CK framework during vulnerability assessments and threat analysis. * Experience with NIST, ISO 27001, or comparable cybersecurity frameworks. * Experience developing automation or analysis tools using Python. * Strong analytical, communication, and technical writing skills. * Willingness to travel OCONUS in support of customer mission requirements. Desired * Experience implementing or assessing Zero Trust architectures supporting Computer Network Exploitation (CNE), Computer Network Operations (CNO), network infrastructure, or system hardening. * Experience performing penetration testing or offensive security assessments. * Relevant cybersecurity certifications such as CISSP, GPEN, GXPN, GCIH, GCFA, GCIA, OSCP, or equivalent. * Experience supporting Intelligence Community or Department of Defense cyber operations. ## Description Markon is seeking a Systems Vulnerability Analyst to support the Fort Meade customer by identifying, assessing, and mitigating vulnerabilities across mission-critical systems and enterprise networks. This role conducts security assessments, analyzes network activity for indicators of malicious behavior, and develops mitigation strategies that strengthen the customer's cybersecurity posture. Working alongside Red, Blue, and Purple Teams, the Systems Vulnerability Analyst supports offensive and defensive cyber operations while helping implement security best practices and Zero Trust principles. * Conduct vulnerability assessments and Red Team activities to identify security weaknesses across enterprise systems and networks. * Analyze assessment results and develop detailed mitigation strategies and technical recommendations to reduce cyber risk. * Support Blue Team and Purple Team operations by validating defensive controls and improving detection capabilities. * Analyze network traffic, system logs, and security event data to identify malicious or unauthorized activity. * Perform threat hunting activities using Indicators of Compromise (IOCs), behavioral analysis, and the MITRE ATT&CK framework. * Assess network architectures and security controls to identify vulnerabilities and improve system resilience. * Support Zero Trust initiatives through evaluation of network infrastructure, system hardening, and cybersecurity architecture. * Apply NIST, ISO 27001, and other cybersecurity frameworks to support security assessments and compliance activities. * Develop Python scripts or automation tools to support vulnerability analysis, reporting, and security assessments. * Prepare technical assessment reports, risk analyses, and mitigation recommendations for Government stakeholders. * Travel OCONUS as required to support customer mission requirements. ## Related Videos - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Oops! Stories of supply chain shenanigans](https://www.wearedevelopers.com/videos/245-oops-stories-of-supply-chain-shenanigans) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j)