Vulnerability Management Analyst

DANE, LLC

Chantilly (VA)

Hybrid

USD 75,000 - 95,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Life/STD/LTD
FSA/DCA
401(k)
Employee discounts
Paid time off
401(k) matching
Dental insurance
Health insurance
Tuition assistance
Vision insurance

Job summary

DANE LLC is seeking a Vulnerability Management Analyst (junior) to support vulnerability tracking, remediation coordination, and security metrics reporting in a federal technology environment. You will work hands-on with Tenable/Nessus, iPost, Power BI, Excel, and ticketing systems to ensure data is accurate and actionable.

This hybrid Arlington-based role requires a Bachelor’s degree in CS or equivalent and 1–3 years of relevant experience, plus an active DoD Secret Clearance or higher.

Qualifications

  • 1–3 years of cybersecurity operations, vulnerability management, SOC, cyber GRC, IT ops, or app security support.
  • Hands-on Tenable/Nessus experience: credentialed scans, CVE findings, KEV, EOL/EOS tracking.
  • Intermediate Power BI (Power Query, data modeling, DAX) and strong Excel skills for reporting.
  • Experience with iPost, ServiceNow, CA ServiceDesk, Jira, or SharePoint for remediation tracking.
  • Familiarity with EOL/EOS software tracking, patch compliance, and remediation documentation.
  • Strong attention to detail and ability to translate technical findings for leadership.

Responsibilities

  • Run authorized Tenable/Nessus scans with credentialed profiles and review exports to identify CVEs, KEV status, and asset impact.
  • Validate findings as true/false positives, track vulnerability age, and escalate unresolved issues.
  • Support the full vulnerability lifecycle from intake through closure evidence collection.
  • Monitor KEV and Critical/High findings against federal timelines and flag aging or blocked items for escalation.
  • Build and maintain Power BI dashboards and Excel reports covering vulnerability posture and KPIs.
  • Produce recurring deliverables and document KPI definitions and data sources.
  • Reconcile data across Tenable/Nessus, iPost, ServiceNow/CA ServiceDesk, Jira, SharePoint, and Excel exports.
  • Coordinate with security, development, infrastructure, database, and cloud teams to drive remediation.

Skills

Tenable/Nessus
Power BI
Excel
Vulnerability management
Data analysis
Jira

Education

Bachelor's degree in computer science or equivalent

Tools

iPost
ServiceNow
CA ServiceDesk
Jira
SharePoint

Job description

Description

Looking for a place that invests in you from day one? At DANE, we offer aggressive PTO, strong benefits, and ongoing learning opportunities, backed by a culture that values and supports our team.

We are seeking a Vulnerability Management Analyst (Tenable/Nessus & Metrics) to support vulnerability tracking, remediation coordination, and security metrics reporting in a federal technology environment. This is a junior-level role (1–3 years of experience) focused on execution and coordination, working hands‑on with Tenable/Nessus, iPost, Power BI, Excel, and ticketing systems to ensure that vulnerability data is accurate, actionable, and reportable.

Benefits
  • Life/STD/LTD
  • FSA/DCA
  • 401(k)
  • Employee discounts
  • Paid time off
  • 401(k) matching
  • Dental insurance
  • Health insurance
  • Tuition assistance
  • Vision insurance
Location

Hybrid - Onsite, Arlington, VA,1 day/week and as needed

Job Type

Full Time

Education

Minimum of a Bachelor’s degree in computer science or Equivalent

Experience

Minimum 1 year of relevant experience

Clearance

Must hold an Active DoD Secret Clearance or higher

Responsibilities
  • Run authorized Tenable/Nessus scans using credentialed scan profiles and review exports to identify CVEs, plugin findings, KEV status, EOL/EOS software risks, and affected assets.
  • Validate findings as true or false positives, track vulnerability age using first-seen/last-seen dates, and upscale unresolved findings to senior security staff or system owners.
  • Support the full vulnerability lifecycle from intake and triage through ownership assignment, remediation tracking, retest/rescan validation, and closure evidence collection.
  • Monitor KEV and Critical/High findings against federal remediation timelines (e.g., BOD 22-01) and flag aging, stale, or blocked findings for escalation.
  • Build and maintain Power BI dashboards and Excel reports covering vulnerability posture, patch compliance, KEV status, finding aging, and ownership tracking using Power Query, slicers, and basic DAX measures.
  • Produce recurring deliverables, including Critical/High aging reports, Tenable/iPost reconciliation summaries, EOL/EOS tracking, and executive snapshots; document KPI definitions and data sources.
  • Reconcile vulnerability data across Tenable/Nessus, iPost, ServiceNow/CA ServiceDesk, Jira, SharePoint, POA'M trackers, and Excel exports to identify mismatches and coverage gaps.
  • Coordinate with security, development, infrastructure, database, and cloud teams and ISSO stakeholders to drive remediation through closure.
Requirements
  • 1–3 years of experience in cybersecurity operations, vulnerability management, SOC, cyber GRC, IT operations, or application security support; working knowledge of CVE, CVSS, KEV, false positives, POA'M tracking, risk acceptance, and vulnerability aging.
  • Hands‑on Tenable/Nessus experience: executing credentialed scans, analyzing plugin output and CVE findings, validating true/false positives, and building dashboards, saved filters, and exports for KEV, Critical/High, EOL/EOS, and aging tracking.
  • Intermediate Power BI (Power Query, data modeling, DAX, slicers) and strong Excel skills (pivot tables, VLOOKUP/XLOOKUP, conditional formatting, deduplication) for vulnerability reporting and KPI tracking.
  • Experience with iPost, ServiceNow, CA ServiceDesk, Jira, or SharePoint for remediation tracking; ability to reconcile data across multiple tools, identify mismatches, and maintain accurate ownership and evidence records.
  • Familiarity with EOL/EOS software tracking, patch compliance, remediation exceptions, risk acceptance documentation, and closure evidence collection.
  • Strong attention to detail, comfort working with large and messy datasets, and clear communication skills for translating technical findings into plain-language updates for leadership and non-technical stakeholders.
Preferred Qualifications
  • Experience supporting federal cybersecurity programs or regulated environments; familiarity with NIST SP 800-53, RMF, A&A, ATO, POA'M lifecycle management, CISA BOD 22-01, and FedRAMP vulnerability requirements.
  • Exposure to DevSecOps and application security tooling: SAST, DAST, SCA, container image scanning, secrets scanning, or Software Bill of Materials (SBOM) analysis.
  • Basic understanding of enterprise patching for Windows Server, Windows workstations, .NET Framework, Java JRE, SQL Server, and endpoint agents; familiarity with Splunk or other SIEM platforms.
  • Experience developing SOPs, RACI matrices, or workflow documentation in a security or IT operations context.
  • Relevant certifications such as CompTIA Security+, CySA+, CEH, or equivalent entry‑to‑mid‑level cybersecurity credentials.

DANE LLC is an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Flexible work from home options available.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vulnerability Management Analyst
Vulnerability Management Analyst

DANE LLC • Chantilly (VA)

Hybrid
USD 70,000 - 90,000
Life/STD/LTD insurance
401(k) plan
Paid time off
+5
Vulnerability Management Analyst
Vulnerability Management Analyst

Foxhole Technology • Arlington (VA)

Hybrid
USD 70,000 - 95,000
Vulnerability Management Lead
Vulnerability Management Lead

K2United, LLC. • Washington

On-site
USD 130,000 - 170,000
Vulnerability Management Lead
Vulnerability Management Lead

K2Share LLC • Washington

On-site
USD 120,000 - 180,000
Vulnerability Management Analyst — Hybrid/Remote Options
Vulnerability Management Analyst — Hybrid/Remote Options

DANE, LLC • Chantilly (VA)

Hybrid
USD 75,000 - 95,000
Life/STD/LTD
FSA/DCA
401(k)
+7
cybersecurity Analyst with vulnerability management
cybersecurity Analyst with vulnerability management

Themesoft Inc. • Burlington (MA)

On-site
USD 70,000 - 90,000
ME00629-System Vulnerability Analyst 4
ME00629-System Vulnerability Analyst 4

Momentum Engineering, Inc • Fort Meade (MD)

On-site
USD 150,000 - 200,000
11 paid holidays
Minimum of 3 weeks PTO
Company-sponsored medical plan
+2
ME00629-System Vulnerability Analyst 4
ME00629-System Vulnerability Analyst 4

Momentum Engineering, Inc. • Fort Meade (MD)

On-site
USD 150,000 - 200,000
11 paid holidays
Minimum of 3 weeks PTO
Company sponsored group medical plan
+2
SME Cyber Vulnerability Management
SME Cyber Vulnerability Management

General Dynamics Information Technology • Fort Bragg (NC)

On-site
USD 110,000 - 150,000
Senior Vulnerability Analyst
Senior Vulnerability Analyst

PRI Global • O’Fallon (MO)

On-site
USD 110,000 - 160,000