> Markdown version of [/jobs/ext/172502-cyber-threat-vulnerability-management-analyst](https://www.wearedevelopers.com/jobs/ext/172502-cyber-threat-vulnerability-management-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Threat/Vulnerability Management Analyst - **Company:** SkyePoint Decisions, Inc. - **Location:** Dulles, VA, United States (Remote available) - **Experience:** Experienced - **Salary:** $100,000.0 - $120,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Cloud Computing, CompTIA Security+, Cyber Security, Python (Programming Language), Pcap, Microsoft Security Essentials, Microsoft Office, Open Source Technology, Open Source Intelligence, Open Web Application Security, Windows PowerShell, Azure Active Directory, Security Content Automation Protocol, Security Information and Event Management, Software Vulnerability Management, Scripting, Cyber Threat Analysis, Tenable Nessus, Splunk, Qualys, Servicenow - **Published:** May 22, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=940861774d3da774 ## About the Role Do you have experience in Vuls?, Do you have a Bachelor's degree?, * BS degree and 5 years of relevant experience, or MS degree and 3 years of relevant experience. * CompTIA Security+ and CompTIA Cyber Security Analyst+ (or equivalent) required. * Hands-on experience with incident response, including analysis, containment, eradication, and recovery. * Experience with SCAP-compliant vulnerability tools (e.g., Tenable Nessus, Qualys) and vulnerability management processes. * Strong knowledge of OWASP, SIEM, EDR tools, and threat intelligence platforms. * Excellent communication skills and experience analyzing qualitative and quantitative data. * Proficiency with Microsoft Security Defender ATP, Office 365, Azure AD, and Cloud App Security. * Experience using open-source tools for malware investigation and ServiceNow for service management. * Must be able to pass a Public Trust clearance suitability determination. * Must be a U.S. citizen. Preferred Qualifications: * Desirable certifications: GCIH, ECIH, CEH, Splunk, and Microsoft certifications. * Experience creating and tuning Splunk dashboards and reports is highly preferred. * Scripting experience (PowerShell, Python) and familiarity with PCAP, remote forensics, Splunk UBA, and SOAR tools are a plus. ## Description * Monitor enterprise environments (including cloud) for vulnerabilities and configuration weaknesses across hardware and software assets. * Track and identify new vulnerabilities from various sources, communicating them effectively to stakeholders using multiple channels. * Prioritize vulnerability remediation based on asset risk profiles, severity ratings, and threat intelligence. * Advise stakeholders on false positives and recommend cost-effective remediation or mitigation solutions. * Coordinate, track, and report remediation of high-risk vulnerabilities (e.g., emergency directives, imminent threats). * Develop and report vulnerability metrics using dashboards or reports. * Collaborate with O&M teams to optimize scanning tools for enhanced visibility and security. * Identify program gaps, recommend improvements, and support implementation of vulnerability management plans. * Assess risks associated with unmitigated vulnerabilities and configuration weaknesses. * Support asset management efforts through identification, classification, and ownership. * Attend federal intelligence calls, summarize for stakeholders, and take necessary actions. * Gather and analyze threat indicators from trusted sources and OSINT, integrating them into EDR and SIEM tools. * Use ticketing systems to submit network block requests, apply endpoint blocks, and initiate incident response tickets. * Create and deliver reports or requests for information (RFIs) as needed, addressing both general and granular stakeholder needs. * Conduct proactive threat hunting using SIEM tools and participate in after-hours on-call rotations for incident response. * Investigate and analyze notable events from tools like Splunk and Microsoft 365 Defender. * Mentor junior analysts, assist with triage and investigation of incidents, and participate in tabletop exercises. * Contribute to the development of playbooks and standard operating procedures for incident response. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)