> Markdown version of [/jobs/ext/3597259-vulnerability-management-security-analyst](https://www.wearedevelopers.com/jobs/ext/3597259-vulnerability-management-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Vulnerability Management & Security Analyst - **Company:** Torch Technologies, Inc. - **Location:** Huntsville, AL, United States - **Experience:** Expert - **Salary:** $105,000.0 - $128,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Systems Engineering, Microsoft Azure, Bash Shell, Cloud Computing, Cloud Computing Security, CompTIA Security+, Cyber Security, Computer Networks, System Configuration, Linux, Windows PowerShell, Security Content Automation Protocol, Virtual Machines, Software Vulnerability Management, Information Technology, Tenable Nessus, Plan of Action and Milestones, Vulnerability Analysis - **Published:** October 6, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88537751/1 ## About the Role * U.S. Citizenship * Active DoW Secret clearance. * Bachelor's degree in Information Technology, Cybersecurity, or related field, plus 2+ years of hands-on DoD cybersecurity analysis and vulnerability scanning experience (or 5+ years without degree). * 2+ years utilizing Assured Compliance Assessment Solution (ACAS) / Tenable Nessus for network, host, and credentialed scanning. * Practical experience applying and verifying DISA STIGs across Linux and Windows operating systems. * Current DoD 8570/8140 IAT Level II certification (e.g., CompTIA Security+ CE, CySA+, or GSEC) * Strong problemsolving skills and ability to troubleshoot complex issues * Effective communication and collaboration skills, * Active Top Secret clearance with SCI eligibility. * Experience configuring and running ACAS scans inside Microsoft Azure Government or AWS GovCloud environments. * Experience utilizing PowerShell or Bash scripts to automate STIG finding verification and remediation. * Hands-on experience creating, updating, and closing POA&M entries directly in eMASS. * Familiarity with Microsoft Defender for Cloud, Secure Score tracking, and Azure Policy compliance states. * Strong technical documentation, briefing, and reporting experience Schedule:M-F; 8-5 ## Description Torch Technologies is seeking a Vulnerability Management & Security Analyst to provide day-to-day scanning, STIG assessment, and remediation tracking for J7 JTSD's cloud migration systems. Working under the guidance of the Primary Government Project Lead and Lead Cybersecurity Specialist, you will ensure all Azure workloads remain hardened and compliant with DoD standards. As a Vulnerability Management & Security Analyst your duties will include the following, but are not limited to: * Conduct scheduled and ad-hoc vulnerability assessments across Azure Government virtual machines and network components using ACAS (Tenable Nessus). * Evaluate and document system compliance against DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs) using SCAP tools and STIG Viewer. * Collaborate with cloud and systems engineers to provide actionable remediation guidance for identified vulnerabilities and IAVAs. * Populate and maintain Plan of Action & Milestones (POA&M) records within eMASS to ensure accurate risk reporting to Authorizing Officials. * Monitor cloud security hygiene using Microsoft Defender for Cloud and DISA Continuous Monitoring dashboards.