> Markdown version of [/jobs/ext/1954278-cybersecurity-vulnerability-analyst](https://www.wearedevelopers.com/jobs/ext/1954278-cybersecurity-vulnerability-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Vulnerability Analyst - **Company:** Peraton Inc - **Location:** Linthicum Heights, MD, United States - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Burp Suite, CompTIA Security+, Cyber Security, Kali Linux, Open Source Technology, Open Web Application Security, Software Vulnerability Management, Web Applications, Mitre Att&ck, SC Clearance, Information Technology, Vulnerability Analysis - **Published:** August 6, 2026 - **Apply:** https://us.experteer.com/career/view-jobs/cybersecurity-vulnerability-analyst-linthicum-md-usa-58811843 ## About the Role _ Develop proof-of-concept exploits to demonstrate real-world impact and aid mitigations * Coordinate with Vulnerability Management Analysts for system owner remediation and follow-up * Operate within on-site DoD environment (Baltimore-Metropolitan area) Tasks * Bachelor's degree with 5+ years of experience, or Master's with 3+ years, or PhD with 0+ years (information technology related field highly desired) * Active Secret clearance * Active IAT Level II certification (CompTIA Security+ preferred) * Pentesting experience * Knowledge of MITRE ATT&CK, CVSS, and NIST frameworks for severity assessment * Understanding of web exploitation concepts and OWASP Top 10 * Experience in professional IT or cybersecurity environments and investigating threats or vulnerabilities * Excellent customer service skills Key requirements * ## Description Experteer Overview In this role you will support a DoD Vulnerability Disclosure Program as part of a mission-driven security team. You will assess external vulnerability reports, determine reproducibility, and assign risk using industry frameworks. You will work hands-on with offensive tools to develop actionable vulnerability assessments for DoD systems. You will liaise with the hacker community and coordinate mitigations with system owners, influencing national security outcomes. Compensation / Benefits * Review and vet vulnerability reports submitted to the DoD VDP from external researchers * Assess report reproducibility, severity, and risk; produce DoD-approved formats * Utilize HackerOne Triage to prioritize reports and identify duplicates * Conduct web application vulnerability assessments using automated and manual techniques (Burp Suite, open-source tools) * Perform offensive testing with tools like Kali Linux on production networks, documenting procedures for customer use * Develop proof-of-concept exploits to demonstrate real-world impact and aid mitigations * Coordinate with Vulnerability Management Analysts for system owner remediation and follow-up * Operate within on-site DoD environment (Baltimore-Metropolitan area) Tasks * Bachelor's degree with 5+ years of experience, or Master's with 3+ years, or PhD with 0+ years (information technology related field highly desired) * Active Secret clearance * Active IAT Level II certification (CompTIA Security+ preferred) * Pentesting experience * Knowledge of MITRE ATT&CK, CVSS, and NIST frameworks for severity assessment * Understanding of web exploitation concepts and OWASP Top 10 * Experience in professional IT or cybersecurity environments and investigating threats or vulnerabilities * Excellent customer service skills Key requirements * ## Related Videos - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Capture the Flag 101](https://www.wearedevelopers.com/videos/416-capture-the-flag-101) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)