VULNERABILITY ASSESSMENT ANALYST

Quantum Research International

Springfield (VA)

On-site

USD 95,000 - 150,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Quantum Research International, Inc. in Springfield, VA, seeks a Vulnerability Management Analyst to support NGA Defender RMF assessments on-site. You will evaluate systems, coordinate task orders, and develop defense-in-depth measures to reduce risk.

Candidates should have a technical degree or equivalent certifications (Security+, PenTest+, etc.), hands-on experience with Nessus/ACAS/Tenable, and strong networking knowledge to prioritize remediation actions and ensure compliance.

Qualifications

  • Bachelor’s degree in Computer Science, Cybersecurity, IT or related field.
  • Experience with vulnerability management and security assessments.
  • Certifications such as Security+, PenTest+, GSEC acceptable in lieu of degree.

Responsibilities

  • Perform assessments of systems and networks within the environment and identify deviations from policy.
  • Review, promulgate, and track Cyber Task Orders; coordinate with owners to resolve findings.
  • Develop measures of effectiveness for defense-in-depth architectures against vulnerabilities.
  • Identify systemic security issues from vulnerability and configuration data (STIG).
  • Prioritize vulnerability reduction activities based on threat data and mission importance.
  • Conduct vulnerability scans and mitigate vulnerabilities in security systems.
  • Analyze web app vulnerability assessments and recommend remediation actions.
  • Apply cybersecurity/privacy principles to organizational requirements.

Skills

Vulnerability mgmt
Threat analysis
Networking concepts
Cybersecurity fundamentals
Tableau

Education

Bachelor's degree in Computer Science, Cybersecurity, IT or related field

Tools

Nessus
ACAS
Tenable

Job description

Overview
Quantum Research International, Inc. (Quantum ) is a certified DoD Contractor providing services and products to US/Alliedgovernments and industry in the following main areas: (1) Cybersecurity, High Performance Computing Systems, Cloud Services and Systems; (2) Space and Ground Support Systems; (3) Aviation Systems; (4) Missile Systems; (5) Artificial Intelligence/ Machine Learning Systems and Experimentation/Training; and (6) Audio Visual Systems and Services. Quantum’s Corporate Office is in Huntsville, AL, but Quantum actively hires for positions nationwide and internationally. We pride ourselves on providing high quality support to the U.S. Government and our Nation’s Warfighters. In addition to our corporate office, we have physical locations in Aberdeen; MD; Colorado Springs, CO; Orlando, FL; Crestview, FL; Madison, AL, and Tupelo, MS.

Overview
Quantum Research International, Inc. (Quantum ) is a certified DoD Contractor providing services and products to US/Alliedgovernments and industry in the following main areas: (1) Cybersecurity, High Performance Computing Systems, Cloud Services and Systems; (2) Space and Ground Support Systems; (3) Aviation Systems; (4) Missile Systems; (5) Artificial Intelligence/ Machine Learning Systems and Experimentation/Training; and (6) Audio Visual Systems and Services. Quantum’s Corporate Office is in Huntsville, AL, but Quantum actively hires for positions nationwide and internationally. We pride ourselves on providing high quality support to the U.S. Government and our Nation’s Warfighters. In addition to our corporate office, we have physical locations in Aberdeen; MD; Colorado Springs, CO; Orlando, FL; Crestview, FL; Madison, AL, and Tupelo, MS.

Mission
As a member of the NGA Defender Cybersecurity Vulnerability Management team, the contractor executes the Vulnerability Management aspect of the Risk Management Framework (RMF) in accordance with NIST SP 800-37 R2 (or subsequent versions) and National Geospatial-Intelligence Agency\'s (NGA) RMF Implementation Guide (RIG) for all NGA-authorized systems. This position supports NGA in Springfield, VA and is on-site only. No remote/hybrid work.

Responsibilities

  • Perform assessments of systems and networks within the network environment or enclave and identify where systems/networks deviate from acceptable configurations, enclave policy, or local policy.
  • Review, promulgate, and track Cyber Task Orders. Coordinate and assist the relevant information system owners to resolve findings.
  • Develop measures of effectiveness for defense-in-depth architectures against known vulnerabilities.
  • Identify systemic security issues based on the analysis of vulnerability and configuration (STIG) data.
  • Prioritize vulnerability reduction activities based on threat data, vulnerability severity, and mission criticality.
  • Conduct vulnerability scans and mitigate vulnerabilities in security systems.
  • Analyze web application vulnerability assessments to recommend remediation action for known web application vulnerabilities and misconfigurations.
  • Apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).

Requirements

  • Bachelor’s degree (technically relevant degree preferred). In lieu of degree, candidates may qualify with experience combined with one of the following: Security+, PenTest+, GSEC, GICSP, GCSA, GCIH, GCED, FITSP-A, CPTE, Cloud+, RCCE Level 1, CEH (Practical).
  • TS/SCI eligible, subject to CI Polygraph.
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology or other relevant fields.
  • Experience in vulnerability management using tools such as Nessus, ACAS, Tenable, etc.
  • Knowledge of computer networking concepts and protocols, and network security methodologies, risk management processes (e.g., methods for assessing and mitigating risk), and laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.
  • Knowledge of cyber threats and vulnerabilities, and operational impacts of cybersecurity lapses.
  • Knowledge of cryptography and cryptographic key management concepts
  • Knowledge of applicable cyber defense policies, regulations, and compliance documents specifically related to cyber defense auditing.
  • Knowledge of what constitutes a network attack and a network attack’s relationship to both threats and vulnerabilities.
  • Ability to collaborate with IT asset owners to create vulnerability remediation plans using a positive customer service mindset.

Desired/Preferred Skills

  • Experience with vulnerability and/or threat data visualization (Tableau, etc).

Equal Opportunity Employer/Affirmative Action Employer M/F/D/V

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, veteran status, genetic information, sexual orientation, gender identity, or any other characteristic protected by law. *Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

VULNERABILITY ASSESSMENT ANALYST
VULNERABILITY ASSESSMENT ANALYST

Quantum-Research-International,-Inc • Springfield (VA)

On-site
USD 90,000 - 130,000
VULNERABILITY ASSESSMENT ANALYST
VULNERABILITY ASSESSMENT ANALYST

Quantum Research International Inc • Springfield (VA)

On-site
USD 85,000 - 120,000
Vulnerability Management Analyst - RMF/NIST
Vulnerability Management Analyst - RMF/NIST

Quantum Research International Inc • Springfield (VA)

On-site
USD 85,000 - 120,000
RMF Vulnerability Analyst - Cyber Defense
RMF Vulnerability Analyst - Cyber Defense

Quantum Research International • Springfield (VA)

On-site
USD 95,000 - 150,000
RMF Vulnerability Analyst – Onsite in Springfield, VA
RMF Vulnerability Analyst – Onsite in Springfield, VA

Quantum-Research-International,-Inc • Springfield (VA)

On-site
USD 90,000 - 130,000
Vulnerability Analyst
Vulnerability Analyst

Y-12 National Security Complex • Oak Ridge (TN)

On-site
USD 85,000 - 110,000
Vulnerability Assessment Analyst with Security Clearance
Vulnerability Assessment Analyst with Security Clearance

ShorePoint, LLC • Albuquerque (NM)

On-site
USD 90,000 - 130,000
PTO 144 hours per year
11 holidays
Health insurance 85% premium covered
+2
ME00629-System Vulnerability Analyst 4
ME00629-System Vulnerability Analyst 4

Momentum Engineering, Inc • Fort Meade (MD)

On-site
USD 150,000 - 200,000
11 paid holidays
Minimum of 3 weeks PTO
Company-sponsored medical plan
+2
ME00629-System Vulnerability Analyst 4
ME00629-System Vulnerability Analyst 4

Momentum Engineering, Inc. • Fort Meade (MD)

On-site
USD 150,000 - 200,000
11 paid holidays
Minimum of 3 weeks PTO
Company sponsored group medical plan
+2
Remote Vulnerability Analyst — Cyber Hygiene & Risk Assessments
Remote Vulnerability Analyst — Cyber Hygiene & Risk Assessments

Boston Government Services, LLC (BGS) • Knoxville (TN)

On-site