Cybersecurity Vulnerability Analyst

Peraton

Maryland

On-site

USD 90,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Peraton is seeking a Cybersecurity Vulnerability Analyst in our Linthicum, MD office in support of our DoD customer as part of a highly talented, highly motivated, and high-performing team. The Analyst will review vulnerability reports, assess severity, and draft DoD-format statements for system owner coordination and mitigation.

The role focuses on vulnerability discovery, threat analysis, and coordinating with the hacker community via the Vulnerability Disclosure Program to protect national

Qualifications

  • Bachelor's degree with 5+ years of experience, or Master’s with 3+ years, or PhD with 0+ years. Degrees in IT, CS, Cybersecurity, IS, SWE, or Data Science preferred.
  • Active Secret clearance required.
  • Active IAT Level II cert (CompTIA Security+ preferred).
  • Strong understanding of information security principles and practices.

Responsibilities

  • Review DoD Vulnerability Disclosure Program reports for reproducibility and value.
  • Assess vulnerabilities for severity and risk; draft DoD-approved formats for coordination.
  • Liaise with the hacker community and Vulnerability Management team to coordinate mitigations.
  • Conduct web app vulnerability testing using automated and manual methods (Burp Suite, others).
  • Utilize Kali Linux and other tools to analyze production networks and document steps for reusable assessments.

Skills

Pentesting
Threat analysis
Vulnerability assessment
Customer service
Security awareness

Education

Bachelor's degree
Master's degree
PhD

Tools

Kali Linux
Burp Suite

Job description

Required Qualifications:
  • Education: Bachelor's degree and 5+ years of experience, or Master's and 3+ years of experience, or PhD and 0+ years of experience. A degree in one of the following fields of study is highly desired: Information Technology, Computer Science, Cybersecurity, Information Systems, Software Engineering, or Data Science. An additional 4 years of relevant experience or specialized training may be considered in lieu of Bachelor's degree.
  • Security Clearance: Active Secret clearance.
  • Certifications: Active IAT Level II certification (CompTIA Security+ preferred).
  • In-depth understanding of information security principles and practices.
  • Pentesting experience.
  • Utilize MITRE ATT&CK, CVSS, and NIST frameworks to assess vulnerability severity and risk impact.
  • In-depth understanding of web exploitation concepts and techniques.
  • Knowledge and understanding of the Open Web Application Security Project (OWASP) top 10.
  • Experience operating in a professional IT or cybersecurity environment.
  • Experience investigating security events, threats and/or vulnerabilities.
  • Understand information security principles, technologies and practices.
  • Excellent customer service skills.
Preferred Additional Skills:
  • CEH, CCNA-Security, CySA+, OSCP (or equivalent), PenTest+ or similar certification a plus.
  • Completed multiple Hack-The-Box penetration testing labs and challenges, developing hands-on expertise in vulnerability enumeration, exploitation, privilege escalation, and post-exploitation techniques within realistic, adversarial environments.
  • Must possess an in-depth understanding of penetration testing methodology, including recon, exploit, persistence, etc.
  • Must have a solid understanding of networking protocols, their uses, and their potential misuses.
  • Programming experience in one or more languages, experience in HTLM/CSS or SQL.
  • Experience with one or more scripting languages such as PowerShell, Bash, Python or Perl.

Peraton is seeking a Cybersecurity Vulnerability Analyst in our Linthicum, MD office in support of our Department of Defense (DoD) customer as part of a highly talented, highly motivated, and high-performing team. This position offers a unique opportunity to work at the forefront of cyber investigations, digital forensics, cyber threat analysis, and mission support in a dynamic and collaborative environment. The successful candidate will contribute to protecting national security interests by leveraging technical expertise, analytical skills, and innovative problem-solving to address complex cyber challenges.

This Cybersecurity Vulnerability Analyst supports a Vulnerability Disclosure Program (VDP) within the federal government and is responsible for reviewing and vetting security vulnerability reports submitted to the DoD VDP from outside hackers. The Analyst will evaluate the reports to ensure the vulnerability is reproducible and therefore valuable to the customer. They will assess each vulnerability for severity and assign an associated risk statement. The HackerOne Triage console tool will be utilized to assist in assigning and prioritizing reports. It will also assist the Analyst in helping identify duplicate submissions. Valid reports will be written in a DoD approved format and sent to the Vulnerability Management Analyst team for system owner coordination and mitigation. The Vulnerability Analyst will be a VDP liaison with the hacker community.

The Vulnerability Analyst will also:
  • Utilize offensive toolsets such as Kali Linux to safely analyze production networks and systems, documenting steps and procedures to produce usable vulnerability assessments for the customer.
  • Identify and investigate vulnerabilities, asses exploit potential, and document findings and remedies for presentation to facilitate mitigations on customer systems.
  • Conduct web application vulnerability assessment testing using both automated tools and manual web exploitation techniques, using tools such as Burp Suite and open-source toolsets.
  • Utilize a variety of industry standard security tools to conduct automated scans against systems and applications.
  • Develop and execute proof-of-concept exploits to demonstrate the real-world impact of identified vulnerabilities, utilizing various web exploitation methods.

This position is fully on-site M-F in the Baltimore-Metropolitan area.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

External Job Posting Title Cybersecurity Vulnerability Analyst
External Job Posting Title Cybersecurity Vulnerability Analyst

Peraton • Linthicum (MD)

On-site
USD 104,000 - 166,000
Cybersecurity Vulnerability Analyst
Cybersecurity Vulnerability Analyst

Peraton • Linthicum (MD)

On-site
USD 66,000 - 106,000
Potential for overtime
Discretionary bonuses
DoD Vulnerability Analyst: Offensive Security & VDP
DoD Vulnerability Analyst: Offensive Security & VDP

Peraton • Linthicum (MD)

On-site
USD 104,000 - 166,000
ME00629-System Vulnerability Analyst 4
ME00629-System Vulnerability Analyst 4

Momentum Engineering, Inc • Fort Meade (MD)

On-site
USD 150,000 - 200,000
11 paid holidays
Minimum of 3 weeks PTO
Company-sponsored medical plan
+2
ME00629-System Vulnerability Analyst 4
ME00629-System Vulnerability Analyst 4

Momentum Engineering, Inc. • Fort Meade (MD)

On-site
USD 150,000 - 200,000
11 paid holidays
Minimum of 3 weeks PTO
Company sponsored group medical plan
+2
Vulnerability Assessment Analyst with Security Clearance
Vulnerability Assessment Analyst with Security Clearance

ShorePoint, LLC • Albuquerque (NM)

On-site
USD 90,000 - 130,000
PTO 144 hours per year
11 holidays
Health insurance 85% premium covered
+2
Cyber Security Analyst
Cyber Security Analyst

22nd Century Technologies Inc. • Lexington Park (MD)

On-site
USD 80,000 - 120,000
Penetration Tester / Red Team Operator
Penetration Tester / Red Team Operator

Digital Global Connectors • McLean (VA)

Hybrid
USD 120,000 - 190,000
ME00629-System Vulnerability Analyst 4
ME00629-System Vulnerability Analyst 4

Momentum Engineering • Fort Meade (MD)

On-site
USD 150,000 - 200,000
Paid holidays (11 days)
Minimum 3 weeks PTO
Company sponsored medical plan
+1
Cyber Data Analyst
Cyber Data Analyst

Peraton • Maryland

On-site
USD 110,000 - 150,000