> Markdown version of [/jobs/ext/3238953-vulnerability-assessment-analyst-information-systems-security](https://www.wearedevelopers.com/jobs/ext/3238953-vulnerability-assessment-analyst-information-systems-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Vulnerability Assessment Analyst - Information Systems Security - **Company:** Caci Inc - **Location:** Jessup, MD, United States - **Experience:** Expert - **Salary:** $86,600.0 - $181,800.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Unix, CompTIA Security+, Cyber Security, System Configuration, Linux, Linux Security Modules, Service Pack, Software Vulnerability Management, Software Security, Tenable Nessus, Nessus, CIS Benchmarks, Vulnerability Analysis - **Published:** September 10, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9154311/vulnerability-assessment-analyst-information-systems-security ## About the Role CACI is seeking a highly skilled Systems Security Engineer to work on-site in Annapolis Junction, MD, supporting enterprise vulnerability management and cybersecurity operations. The ideal candidate will have hands-on experience with Tenable Security Center and Nessus, Linux and Windows environments, vulnerability assessments, STIG remediation, and continuous security monitoring. This role requires a strong understanding of system and application vulnerabilities, excellent analytical skills, and the ability to work independently while collaborating effectively with ISS and other technical teams., * Bachelor's degree with 7 years of experience. * DoD 8570 IAT Level II certification requirements. * CEH or CompTIA Security+ CE certification. * Hands-on experience with enterprise vulnerability management and scanning solutions, particularly Tenable/Nessus. * Familiarity with DISA STIGs, Tenable Audit Files, and/or CIS Benchmarks. * Knowledge of system and application security threats, vulnerabilities, and remediation practices. * Working knowledge of Linux/Unix and Windows administration. * Experience with patch deployment and system configuration. * Understanding of networking and enterprise IT environments. * Strong analytical, troubleshooting, and problem-solving skills with exceptional attention to detail. Desired: * In-depth knowledge of vulnerability assessment methodologies, tools, and industry best practices. * Experience managing vulnerability remediation across complex enterprise environments. * Ability to independently manage assignments and take ownership of tasks from initiation through completion. * Demonstrated ability to collaborate effectively with ISS, engineering, and other technical teams. * Strong communication skills with the ability to clearly present technical findings and security risks to management and stakeholders. ## Description * Maintain, optimize, and administer the Tenable Security Center infrastructure and associated scanning environments. * Conduct security patching, vulnerability assessments, and Nessus scans across Linux Security Center servers and Windows/Linux scanning servers. * Install, configure, maintain, and update Tenable Nessus and Tenable Security Center software. * Configure and fine-tune scanning policies, asset lists, and security configurations to provide comprehensive vulnerability coverage. * Perform vulnerability assessments across multiple device types and operating systems using Tenable Security Center. * Conduct continuous monitoring of customer assets using Nessus to identify and evaluate security vulnerabilities. * Review and analyze Nessus/ACAS scan results, including successful, unsuccessful, and potential scan results. * Identify and support remediation of DISA STIGs and system vulnerabilities across Tenable servers and scanning infrastructure. * Analyze vulnerability data and prepare clear, comprehensive reports for management and technical stakeholders. * Monitor and track vulnerability remediation activities to support timely resolution. * Collaborate with ISS and other technical teams to address vulnerabilities and strengthen the customer's security posture. * Communicate security risks, assessment findings, and remediation status to stakeholders. * Maintain accurate records of vulnerabilities, security activities, and related findings. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [WeAreDevelopers LIVE - Node and Package Security](https://www.wearedevelopers.com/videos/2138-wearedevelopers-live-node-and-package-security) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [The Time Paradox: Building Timezone-Safe Python/Django Applications](https://www.wearedevelopers.com/videos/1915-the-time-paradox-building-timezone-safe-python-django-applications) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)