> Markdown version of [/jobs/ext/2568879-cyber-vulnerability-management-sme](https://www.wearedevelopers.com/jobs/ext/2568879-cyber-vulnerability-management-sme). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Vulnerability Management SME - **Company:** TEKSYSTEMS INC. - **Location:** Fort Liberty, NC, United States - **Experience:** Expert - **Contract:** Contract - **Skills:** Amazon Web Services, Data Analysis, Antivirus Softwares, Microsoft Azure, Cloud Computing, CompTIA Security+, Cyber Security, Computer Telephony Integration, Linux, Intrusion Detection and Prevention, Log Analysis, Red Hat Enterprise Linux, Software Vulnerability Management, EndPointSecurity, Google Cloud, Cloud Platform System, Azure Security Center, ArcSight Event Correlation, Splunk, Servicenow, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 8, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9114406/cyber-vulnerability-management-sme ## About the Role * Technical Training, Certification(s) or Degree with 10+ years of experience * Splunk or Elastic for Cloud * Endpoint Detection & Response (EDR) tools * Antivirus platforms * ServiceNow, Remedy, or similar ticketing systems Compliance / Certifications (Preferred): * DoD 8570 / 8140 compliant certification * CompTIA Security+ * CySA+ * Network+ * CASP+ * GIAC certifications (GCIH, GCFA, etc.) Security Clearance Level: TS/SCI Required, · This position requires an active DoD Clearance (Secret, Top Secret, Top Secret/SCI) or the ability to be obtain an (Interim Secret, Interim Top Secret) · Because an active or interim DoD clearance is required, U.S. Citizenship is required ## Description The SME Information Security Analyst (Vulnerability Management) serves as the technical lead for deploying, configuring, and maintaining the enterprise vulnerability management environment. This position focuses on optimizing Tenable Security Center within Linux/Red Hat infrastructures and ensuring compliance with DISA STIGs, NSA guidelines, and organizational cybersecurity policies. The analyst supports Enterprise Communications and hybrid environments across AWS, Microsoft Azure, and Google Cloud. This role requires deep technical expertise, strong analytical skills, and collaboration with engineering, cybersecurity, and leadership teams across the command., Vulnerability Management Operations * Install, configure, and maintain Tenable Security Center and scanning components on Linux/Red Hat platforms. * Ensure vulnerability management systems meet DISA STIG, NSA, and cybersecurity policy requirements. * Manage credentialed and non-credentialed scans, schedules, asset groups, and plugin updates. * Troubleshoot scanner/system issues to ensure accurate and continuous vulnerability detection. Analysis & Reporting * Analyze scan results to identify weaknesses, misconfigurations, and emerging threats. * Validate findings, assess severity, and prioritize remediation based on mission needs. * Produce recurring reports, dashboards, and metrics for Command Leadership. * Translate complex technical findings into clear remediation guidance for engineering teams. Mitigation Support & POA&M Management * Provide expert guidance on mitigation, configuration hardening, and patching strategies. * Support development and maintenance of POA&Ms for unresolved vulnerabilities. * Track remediation progress to ensure compliance with published cyber directives. Enterprise Communications Support * Support enterprise communications systems and services to ensure secure hybrid operations. * Assist with monitoring and securing cloud/on-prem workloads using enterprise security tools. * Collaborate with cloud, network, and communications teams to ensure secure configurations and continuous monitoring. Threat Detection & Response * Support threat detection using Microsoft Defender for Endpoint and cloud environments including AWS, Azure, and Google Cloud. * Conduct log analysis, event correlation, and investigation of suspicious activity. * Assist with incident reporting, documentation, and escalation procedures. * Contribute to detection rule tuning, alert fidelity improvements, and endpoint hardening. * Identify coverage gaps and recommend improvements; document findings in After-Action Reports with SOC, EPT, and CTI partners. * Develop guardrails, configuration baselines, and automation artifacts to reduce vulnerability recurrence. * Support surge response activities through rapid scanning, validation, and remediation assistance. ## Related Videos - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)