Vulnerability Analyst

Y-12 National Security Complex

Oak Ridge (TN)

On-site

USD 85,000 - 110,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

The Y-12 National Security Complex is seeking a Vulnerability Analyst to analyze data streams, interpret threats, vulnerabilities, and likelihood of asset exposure, and provide mitigations for exploitable assets.

The role requires experience in cybersecurity assessment, incident response, and collaboration across teams to strengthen enterprise defenses. On-site Oak Ridge location with competitive salary and benefits.

Qualifications

  • Bachelor's degree in engineering/science/information technology discipline is required.
  • Master's degree in engineering/science/information technology discipline is preferred.
  • Eight or more years of education and/or relevant experience may be considered to satisfy educational and years-of-experience requirements.

Responsibilities

  • Identify systemic security issues based on vulnerability and configuration data.
  • Share insights about threat environment to improve risk posture.
  • Conduct vulnerability scans and assess robustness of security systems.
  • Review logs and analyze security events to support remediation.

Skills

Cybersecurity analysis
Vulnerability assessment
Threat intelligence
Network security concepts
Log review

Education

Bachelor's degree in engineering/science/information technology
Master's degree in engineering/science/information technology

Tools

Snort
nmap
Wireshark
tcpdump

Job description

Vulnerability Analyst

Location: Oak Ridge, TN

Career Level: Associate to Senior Specialist

Job Specialty: Cyber Security

What You'll Do

The Vulnerability Analyst is responsible for analyzing key data streams and interpreting threats, vulnerabilities, impacts, and likelihood of asset exposure. The aggregation of ingested data informs analysis with key identifiers to generate a holistic view of the enterprise and provide recommended mitigations and/or remediation of possible exploitable assets. The analyst also assists Vulnerability and Compliance Assessment Management with cyber analysis to support requested exception requests. Responsible for cybersecurity assessment/analysis and provides recommendations for enterprise‑level systems and applications designs. Involved in a wide range of cybersecurity areas, including system architectures, firewalls, inspection and analysis tools, encryption components and networking architectures. Involved in security reporting and analysis to regulatory agencies.

Position Duties and Responsibilities
  • Identify systemic security issues based on the analysis of vulnerability and configuration data.
  • Share meaningful insights about the context of an organization’s threat environment that improve its risk management posture.
  • Apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, and non‑repudiation).
  • Host/network access control mechanisms (e.g., access control list, capabilities lists).
  • Conduct vulnerability scans and recognize vulnerabilities in security systems.
  • Assess the robustness of security systems and designs.
  • Detect host and network‑based intrusions via intrusion detection technologies (e.g., Snort).
  • Ability to mimic threat behaviors.
  • Support penetration testing tools and techniques.
  • Use social engineering techniques (e.g., phishing, baiting, tailgating).
  • Support network analysis tools to identify vulnerabilities (e.g., fuzzing, nmap).
  • Review logs to identify evidence of past intrusions.
  • Conduct application vulnerability assessments.
  • Perform impact/risk assessments.
  • Develop insights about the context of an organization’s threat environment.
  • Analyze organization's cyber defense policies and configurations and evaluate compliance with regulations and organizational directives.
  • Maintain knowledge of applicable cyber defense policies, regulations, and compliance documents specifically related to cyber defense auditing.
What You Can Expect
  • Meaningful work and unique opportunities to support missions vital to national and global security.
  • Top‑notch, dedicated colleagues.
  • Generous pay and benefits with a stable organization.
  • Career advancement and professional development programs.
  • Work‑life balance fostered through flexible work options and wellness initiatives.
Minimum Job Requirements
  • Bachelor's degree in engineering/science/information technology discipline.
  • Master's degree in engineering/science/information technology discipline.
  • Eight or more years of education and/or relevant experience may be considered to satisfy educational and years‑of‑experience requirements for this posting.
Preferred Job Requirements
  • Knowledge of computer networking concepts and protocols, and network security methodologies.
  • Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.
  • Knowledge of cybersecurity threats and vulnerabilities.
  • Knowledge of risk management processes (e.g., methods for assessing and mitigating risk).
  • Knowledge of cryptography and cryptographic key management concepts.
  • Knowledge of cybersecurity specific operational impacts of cybersecurity lapses.
  • Knowledge of cybersecurity application vulnerabilities.
  • Knowledge of network access, identity, and access management (e.g., public key infrastructure, Oauth, OpenID, SAML, SPML).
  • Knowledge of how traffic flows across the network (e.g., TCP, IP, OSI, ITIL).
  • Knowledge of programming language structures and logic.
  • Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross‑site scripting, PL/SQL injections, race conditions, covert channel, replay, return‑oriented attacks, malicious code).
  • Knowledge of systems diagnostic tools and fault identification techniques.
  • Knowledge of what constitutes a network attack and a network attack’s relationship to both threats and vulnerabilities.
  • Knowledge of different classes of attacks (e.g., passive, active, insider, close‑in, distribution attacks).
  • Knowledge of system administration, network, and operating system hardening techniques.
  • Knowledge of cyber‑attack stages (e.g., reconnaissance, scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks).
  • Knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense‑in‑depth).
  • Knowledge of security models (e.g., Bell‑LaPadula, Biba, Clark‑Wilson).
  • Knowledge of system administration concepts for operating systems such as but not limited to Unix/Linux, IOS, Android, and Windows.
  • Knowledge of packet‑level analysis using appropriate tools (e.g., Wireshark, tcpdump).
  • Knowledge of network protocols such as TCP/IP, DHCP, DNS, and directory services.
  • Knowledge of penetration testing principles, tools, and techniques.
  • Knowledge of application security risks (e.g., OWASP Top 10).
Additional Qualifications
  • Requires a Q clearance; qualified candidates will be considered regardless of current clearance status. Ability to obtain and maintain a DOE Q clearance is required.
  • May require entry into the Material Access Areas and participation in human reliability programs, including counter‑intelligence evaluations and polygraph examinations.
Equal Opportunity Employer Statement

CNS is an equal opportunity employer. All qualified applicants will receive consideration for employment based on merit and without regard to race, color, religion, sex, sexual orientation, national origin, protected veteran status or disability.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vulnerability Analyst
Vulnerability Analyst

VetJobs • Oak Ridge (TN)

On-site
USD 90,000 - 130,000
Cybersecurity Vulnerability Analyst
Cybersecurity Vulnerability Analyst

Node.Digital LLC • Arlington (VA)

On-site
Medical
Dental
Vision
+4
ME00629-System Vulnerability Analyst 4
ME00629-System Vulnerability Analyst 4

Momentum Engineering, Inc • Fort Meade (MD)

On-site
USD 150,000 - 200,000
11 paid holidays
Minimum of 3 weeks PTO
Company-sponsored medical plan
+2
ME00629-System Vulnerability Analyst 4
ME00629-System Vulnerability Analyst 4

Momentum Engineering, Inc. • Fort Meade (MD)

On-site
USD 150,000 - 200,000
11 paid holidays
Minimum of 3 weeks PTO
Company sponsored group medical plan
+2
Cyber Risk & Vulnerability Analyst
Cyber Risk & Vulnerability Analyst

VetJobs • Oak Ridge (TN)

On-site
USD 90,000 - 130,000
VULNERABILITY ASSESSMENT ANALYST
VULNERABILITY ASSESSMENT ANALYST

Quantum Research International Inc • Springfield (VA)

On-site
USD 85,000 - 120,000
ME00629-System Vulnerability Analyst 4
ME00629-System Vulnerability Analyst 4

Momentum Engineering • Fort Meade (MD)

On-site
USD 150,000 - 200,000
Paid holidays (11 days)
Minimum 3 weeks PTO
Company sponsored medical plan
+1
VULNERABILITY ASSESSMENT ANALYST
VULNERABILITY ASSESSMENT ANALYST

Quantum Research International • Springfield (VA)

On-site
USD 95,000 - 150,000
Vulnerability Assessment Analyst with Security Clearance
Vulnerability Assessment Analyst with Security Clearance

ShorePoint, LLC • Albuquerque (NM)

On-site
USD 90,000 - 130,000
PTO 144 hours per year
11 holidays
Health insurance 85% premium covered
+2
Vulnerability Assessment Analyst
Vulnerability Assessment Analyst

KIHOMAC • Huntsville (AL)

On-site
USD 128,000 - 134,000
Health Care Plan (Medical, Dental & Vision)
Retirement Plan (401k, IRA)
Life Insurance
+4