Vulnerability Analyst

Careerwebsite

Arlington, Northern (VA, KY)

Hybrid

USD 70,000 - 126,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Leidos in Arlington, VA is seeking a Vulnerability Analyst to join the CESO team. The role focuses on enforcing security controls, conducting risk assessments, and maintaining RMF documentation for a secure cloud migration.

Requires TS/SCI clearance and DoDD 8140/IAT II certification; experience with ACAS, SEIM tools, and IAVA reporting is preferred. This is an on-site position with responsibility across multiple DoD security domains.

Qualifications

  • Bachelor's degree and 2+ years of related IT security experience; additional experience, education, or training may be considered in lieu of degree.
  • Active TS/SCI security clearance required
  • DoDD 8140 compliant certification, at minimum IAT Level II (e.g., Security+ CE), at start.
  • Experience with DISA security model, controls, and authorization processes for standard computing systems and cloud computing across the DoD
  • Experience with IAVA and related reporting (CISA)
  • Experience creating IA documentation such as SCTM, RAR, SAR and maintaining POA&Ms
  • Experience with ACAS and SEIM tools
  • Experience with security settings for vendor/DISA best practices
  • Candidate may be asked to obtain a CI Polygraph in the future

Responsibilities

  • Meet regulatory and non-regulatory compliance demands across the CESO environment.
  • Assist in management and maintenance of the IAVA program for CESO systems.
  • Manage and enforce information security policies and train end-users on security practices.
  • Conduct security and risk assessments using RMF, NIST, Common Criteria; mitigate risk via controls and testing.
  • Develop, update, and track RMF documentation from customer data.
  • Ensure data privacy; perform vulnerability management, business continuity, and disaster recovery activities.
  • Coordinate with infrastructure, storage, database, and app teams to align vulnerability activities.
  • Maintain documentation and compliance reports supporting CESO's secure cloud migration.
  • Protect information and maintain security controls to reduce risk across CESO system/site/program

Skills

Regulatory compliance
Risk assessment
Security training
Vulnerability management

Education

Bachelor's degree

Tools

ACAS
SEIM tools
Splunk
eMASS

Job description

We are currently seeking a Vulnerability Analyst to join the Compartmented Enterprise Services Office (CESO) effort. This program is establishing a modern secure web service (SWS) operation as part of a state-of-the-art, highly automated platform capable of supporting a rapidly expanding customer population.

This position is based in Arlington, VA and is 100% on-site.

Requires a TS/SCI US Government Security Clearance to start.

Primary Responsibilities
  • Responsible for meeting both regulatory (Legal and Mandated Requirements) and non-regulatory (Real-World Threat Reduction) compliance demands across the CESO environment.
  • Assist in the management and maintenance of the IAVA (Information Assurance Vulnerability Alerts) program for CESO systems.
  • Manage and enforce information security policies, and train and educate end-users on proper security practices.
  • Conduct security and risk assessments using established frameworks (e.g., NIST, RMF, Common Criteria), mitigating risk via security controls and testing and evaluation to certify and accredit commercial security products used within the CESO platform.
  • Develop, update, organize, maintain, and track RMF documentation using information obtained from the customer.
  • Ensure privacy of data throughout its lifecycle; perform vulnerability management (scanning, assessment, reporting, and mitigation verification), business continuity, and disaster recovery activities.
  • Coordinate with infrastructure, storage, database, and application teams to align vulnerability management activities with CESO's operational and compliance requirements.
  • Maintain documentation, operational procedures, and compliance reports supporting CESO's secure cloud migration.
  • Responsible for a combination of duties to protect information and maintain security controls across the CESO system, site, or program in order to reduce risk.
Basic Qualifications
  • Bachelor's degree and 2+ years of related IT security experience; additional experience, education, or training may be considered in lieu of degree.
  • Active TS/SCI security clearance required
  • DoDD 8140 compliant certification, at minimum IAT Level II (e.g., Security+ CE), at start.
  • Experience with the Defense Information Systems Agency (DISA) security model, controls, and authorization processes for standard computing systems and cloud computing across the Department of Defense
  • Experience conducting activities associated with Information Assurance Vulnerability Alerts (IAVA) for example, Cybersecurity and Infrastructure Security Agency (CISA).
  • Experience with creating Information Assurance documentation such as Security Control Traceability Metrics (SCTM), Risk Assessment Report (RAR), Security Assessment Report (SAR) and maintaining POA&Ms (Plans of Action and Milestones).
  • Experience with ACAS and SEIM tools.
  • Experience with application and hardware security settings for vendor and/or DISA best business practices.
  • Candidate may be asked to obtain a CI Polygraph in the future.
Preferred Qualifications
  • Prior experience with DISA and DISA's support to mission partners.
  • TS/SCI with CI Polygraph preferred.
  • Experience with ACAS, SPLUNK, ACT (cybersecurity event), IAVA reporting, and eMASS.
  • Familiarity with vulnerability management across enterprise applications and infrastructure (e.g., Oracle, SQL Server, Exchange, virtualization platforms, Windows, Red Hat).
  • Understanding of disaster recovery and business continuity concepts as they apply to secure cloud migrations.

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.

Pay Range

Pay Range $69,550.00 - $125,725.00

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com.

Pay and Benefits

Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits.

Securing Your Data

Beware of fake employment opportunities using Leidos’ name. Leidos will never ask you to provide payment‑related information during any part of the employment application process (i.e., ask you for money), nor will Leidos ever advance money as part of the hiring process (i.e., send you a check or money order before doing any work). Further, Leidos will only communicate with you through emails that are generated by the Leidos.com automated system - never from free commercial services (e.g., Gmail, Yahoo, Hotmail) or via WhatsApp, Telegram, etc. If you received an email purporting to be from Leidos that asks for payment-related information or any other personal information (e.g., about you or your previous employer), and you are concerned about its legitimacy, please make us aware immediately by emailing us at LeidosCareersFraud@leidos.com.

If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission.

Commitment to Non-Discrimination

All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Vulnerability Analyst
Vulnerability Analyst

Leidos • Arlington (VA)

On-site
USD 70,000 - 126,000
Vulnerability Analyst
Vulnerability Analyst

Leidos Inc • Arlington (VA)

On-site
USD 70,000 - 126,000
Vulnerability Analysis Subject Matter Expert (SME)
Vulnerability Analysis Subject Matter Expert (SME)

Via Logic LLC • Lorton (VA)

On-site
USD 131,000 - 237,000
Vulnerability Analysis Subject Matter Expert (SME)
Vulnerability Analysis Subject Matter Expert (SME)

Leidos • Lorton (VA)

On-site
USD 131,000 - 237,000
Senior Security Engineer
Senior Security Engineer

Leidos Inc • Bethesda (MD)

On-site
USD 108,000 - 195,000
Cyber Infrastructure Support Lead
Cyber Infrastructure Support Lead

Leidos Inc • Concord (MA)

On-site
USD 108,000 - 195,000
Senior Security Engineer
Senior Security Engineer

Leidos • Bethesda (MD)

On-site
USD 108,000 - 195,000
Junior Security Engineer
Junior Security Engineer

Via Logic LLC • Bethesda (MD)

On-site
USD 70,000 - 126,000
Junior Security Engineer
Junior Security Engineer

Leidos Inc • Bethesda (MD)

On-site
USD 70,000 - 126,000
Vulnerability Assessment Analyst
Vulnerability Assessment Analyst

Leidos Inc • Dallas (TX)

On-site
USD 108,000 - 195,000