Vulnerability Analyst (Remote)

OXLEY ENTERPRISES INC
Stafford, United States of America
20 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Intermediate
Compensation
$ 118K

Job location

Remote
Stafford, United States of America

Tech stack

Data analysis
Software System Penetration Testing
Automation of Tests
CompTIA Security+
Information Systems
Red Team (Cyber Security)
Software Vulnerability Management
Software Repository
Information Technology
Tenable Nessus
Patch Management
Nessus
Tools for Reporting
Plan of Action and Milestones
Vulnerability Analysis

Job description

Position Description: The Vulnerability Analyst conducts ad-hoc, prescribed, and recurring vulnerability scans across infrastructure, containers, applications, and code repositories, coordinating remediation with Operations and Engineering teams., * Sedentary Work - Exerting up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects.

  • Typing, communicating, repetitive motions.
  • Close visual acuity to prepare and analyze data, view computer monitors and read. May need to view presentation screens and other visual aids in a virtual setting.
  • Inside environmental conditions with protection from outside elements.

Security: Active Federal Civilian Public Trust clearance

  • U.S. Citizenship or Permanent Resident that has lived in the United States for at least 3 years

Federal Civilian Public Trust Consists of a review of up to but not limited to:

  • Covers 10 year period and in some instances lifetime events
  • OPM Security Investigations Index (SII)
  • DOD Defense Central Investigations Index (DCII)
  • National Agency Check (NAC) records
  • FBI name check
  • FBI fingerprint check
  • Credit report check
  • Written inquiries to previous employers and references listed on the application for employment
  • Potential interviews with the subject, spouse, neighbors, supervisor, coworkers
  • Law enforcement check
  • Court records check
  • Education check - Attendance and Degrees

Acceptable Credentials

Tasks/activities include, but are not limited to:

  • Conducts ad-hoc, prescribed, and recurring vulnerability scans for platform and all hosted applications
  • Reports scan results to Operations and Engineering team members
  • Conducts patch management, configuration changes, corrective actions, or Plan of Action and Milestones (POA&M) creation
  • Documents and reports scan findings in accordance with VA RMF and POA&M processes including uploading scan results to the appropriate scan repository
  • Performs upkeep of the Continuous Monitoring system security reporting tool and provides high-level reporting to portfolio Information System Owners
  • Ensures routine vulnerability scanning of infrastructure, containers, applications, and code repositories across production, staging, and sandbox environments
  • Tracks, reports, and ensures remediation of vulnerabilities within defined timelines coordinating with Operations and Engineering teams
  • Supports penetration testing, red team activities, and independent security assessments as required
  • Validates security control effectiveness through automated testing, configuration validation, and periodic assessments
  • Contributes vulnerability remediation status summaries to the monthly RMF, security, and Authorization to Operate (ATO) status report

Requirements

Minimum/General Experience: 5 years of experience in vulnerability management or security scanning

Minimum Education: Bachelor's Degree in cybersecurity, information technology, or related field; CompTIA Security+ or Global Information Assurance Certification (GIAC) Enterprise Vulnerability Assessor (GEVA) (preferred)

Essential Skills/Qualifications:

  • Expert experience conducting ad-hoc, prescribed, and recurring vulnerability scans using Nessus or equivalent scanning tools
  • Expert ability to document and report scan findings in accordance with established processes
  • Excellent experience supporting routine vulnerability scanning of infrastructure, containers, applications, and code repositories
  • Excellent ability to track, report, and ensure remediation of vulnerabilities
  • Excellent knowledge of Continuous Monitoring system security reporting tools
  • Above average ability to support penetration testing, red team activities, and independent security assessments
  • Above average experience validating security control effectiveness through automated testing and configuration validation
  • Experience supporting a federal agency
  • Excellent verbal and written communication skills

Benefits & conditions

4.04.0 out of 5 stars Stafford, VA 22554 Remote $90,897 - $118,016 a year - Full-time, Pulled from the full job description

  • Prescription drug insurance
  • Health insurance
  • Vision insurance
  • Dental insurance
  • Life insurance
  • Disability insurance, CompensationBenefits: The annual projected pay range for this position is $90,897 - $118,016 with consideration being given to various factors including but not limited to qualifications, experience, job responsibilities, and geographic location.

Oxley Enterprises, Inc. offers a full array of benefits including:

  • Medical, dental, vision and prescription drug coverage for you and your family.
  • Life Insurance, short-term disability and long-term disability paid for by the Company.
  • Supplemental coverages including Accident, Critical Illness, and Hospital.
  • Additional Life insurance coverage for you and your dependents.
  • 401k plan with various options to select based on your retirement goals.

Oxley Enterprises, Inc. is a certified service-disabled veteran-owned (SDVOSB), veteran-owned (VOSB), and woman-owned small business (WOSB) that has 26 years of experience building and delivering quality IT systems and programs. Oxley is ranked in the INC 5000 7 times (2016, 2017, 2018, 2021, 2023, 2024, 2025). Oxley is a 2019 - 2025 Department of Labor HIRE Vets Medallion Award Winner. Oxley is Virginia Values Veterans certified.

Apply for this position