VULNERABILITY MGMT ANALYST

Areté

Falls Church (VA)

On-site

USD 110,000 - 145,000

Full time

28 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flextime
Paid Time Off
Parental Leave
401(k) match
Education Assistance
Medical Insurance

Job summary

Areté seeks a Vulnerability Management Analyst to own the end-to-end remediation cycle across desktops, servers, and network devices at our Falls Church, VA facility. You will scan, prioritize, qualify patches, deploy, and verify closures while coordinating with Cyber Security staff.

This hands-on role requires a TS clearance and the ability to travel occasionally, with after-hours support as needed. You will analyze Rapid7/Tenable scans, develop risk-based remediation plans considering

Qualifications

  • Active Top Secret clearance or ability to maintain one.
  • CompTIA Security+ CE within 120 days of employment.
  • Minimum 3 years in system administration, security, or vulnerability roles.
  • Strong Windows Server and RHEL troubleshooting and hardening skills.
  • Experience with patch management tools and change windows.
  • Ability to automate recurrent tasks with scripting.

Responsibilities

  • Conduct regular vulnerability assessments and remediation across multiple environments.
  • Analyze scan results and develop risk-prioritized remediation plans.
  • Execute patching within approved maintenance windows and test patches.
  • Qualify patches and document rollback plans for safe deployment.
  • Develop compensating controls for unresolved vulnerabilities.
  • Coordinate patches with system owners and communicate impacts.
  • Verify remediation via rescans and maintain metrics on timeliness and coverage.
  • Automate scanning, patching, and reporting workflows to improve efficiency.

Skills

Vulnerability mgmt
Remediation coordination
Scripting (PowerShell/Bash/Python)
Stakeholder communication

Education

CompTIA Security+ CE
Bachelor's degree in IT / related field

Tools

Rapid7
ACAS / Tenable
Qualys

Job description

Areté is looking for the person who makes sure vulnerabilities actually get closed — not just found. As our Vulnerability Management Analyst in Falls Church, VA, you will own the end-to-end remediation cycle — scanning, prioritization, patch qualification, deployment, and verification — across desktops, servers, network devices, and standalone systems on multiple sites and networks, working closely with Areté's Cyber Security staff.

This is a hands‑on execution role, and you will be measured on whether vulnerabilities close on a recurring, risk-prioritized cadence. Equally important is doing so without breaking the business: qualifying patches before they are pushed, understanding which applications depend on pinned or vendor-locked component versions, coordinating maintenance windows with system owners, and having a tested rollback path when a patch goes wrong.

The selected candidate must hold an active Top Secret clearance and be able to maintain it. This position is onsite at our Falls Church, VA facility. The candidate may be required to travel occasionally and provide some afterhours support. This is an exempt non-supervisory full-time position.

Primary Responsibilities
  • Conduct regular vulnerability assessments and serve as the technical expert with primary responsibility for vulnerability scanning and remediation of desktops, servers, network devices, and other systems across multiple sites, networks, and standalone environments.
  • Analyze scan results from Rapid7 and Tenable Security Center (ACAS) and produce a risk-prioritized remediation plan that accounts for severity, exploitability, exposure, asset criticality, and known‑exploited‑vulnerability status — not raw CVSS alone.
  • Execute continuous, recurring patching schedules against that prioritization, within maintenance windows authorized by the appropriate change control board.
  • Qualify patches before deployment: test in a representative environment, identify dependencies on pinned or vendor-supported component versions, assess impact to line‑of‑business and server applications, and document a rollback plan.
  • Identify vulnerabilities that cannot be resolved by patching alone — pinned application dependencies, end‑of‑life software, vendor‑locked systems — and develop compensating controls, mitigation strategies, or upgrade recommendations in coordination with system owners and Cyber Security.
  • Coordinate with system owners and end users on upcoming patches and projected impacts, including reboots, service interruptions, and network‑wide effects.
  • Verify remediation through rescanning and closure validation; track exceptions, deviations, and accepted risks through to resolution or formal acceptance.
  • Automate recurring scanning, patching, reporting, and remediation workflows to reduce manual effort and improve consistency.
  • Maintain vulnerability management processes and standard operating procedures, and maintain and report metrics for the function — remediation timeliness, aging, coverage, patch success and failure rates, and recurring problem areas.
  • Prepare and present reports on vulnerability management activities to IT and senior management, communicating complex technical information to non‑technical stakeholders.
  • Stay current on emerging threats, actively exploited vulnerabilities, and vendor advisories, and recommend proactive measures.
  • Other duties, as assigned.
Experiences And Background We Look For
  • Active Top Secret clearance, with the ability to maintain it.
  • Must have or be able to obtain a CompTIA Security+ CE certification within 120 days of employment, in accordance with DoDM 8140.03 and DFARS 252.239-7001.
  • Minimum of 3 years working as a System Administrator, Systems Engineer, Network Administrator, Vulnerability Analyst, or similar role.
  • Proficient understanding of computer hardware, software, and operating systems — primarily Microsoft Windows Server and Red Hat Enterprise Linux — with strong system troubleshooting skills across both.
  • Working knowledge of vulnerability scanning products such as Rapid7 (preferred), Tenable Security Center/Nessus (ACAS), or Qualys.
  • Experience with patch management tools such as PDQ Deploy, SCCM/MECM, WSUS, YUM/DNF, or Red Hat Satellite — including testing and qualifying patches prior to deployment, coordinating change‑managed maintenance windows, and executing rollback when required.
  • Working scripting ability in PowerShell, Bash, or Python sufficient to automate recurring scan parsing, patch orchestration, and reporting tasks.
  • Strong interpersonal and written communication skills, with the ability to work autonomously, produce technical documentation, and negotiate remediation timelines with system owners who have competing priorities.
Nice To Have
  • TS/SCI access with polygraph.
  • Advanced automation experience building patch orchestration or vulnerability reporting tooling.
  • Experience patching and maintaining airgapped, standalone, or classified systems, including offline content management and update ingestion.
  • Familiarity with DISA STIGs, SCAP Compliance Checker, and DoD or federal compliance frameworks (NIST 800-53, NIST 800-171, RMF).
  • Experience with container and application dependency scanning, and with SBOM-based vulnerability identification.
  • Experience managing vulnerabilities in third‑party and line‑of‑business applications where a vendor pins supported runtime or library versions.
  • Industry certifications such as CySA+, Network+, CCNA, RHCSA, Microsoft AZ‑800/801 or MD‑102, GIAC GCED/GEVA, or vendor certifications in Rapid7 or Tenable/ACAS.
  • Bachelor's Degree in an Information Technology related discipline.
We have an impressive range of benefits, programs, and perks that we offer:
Generous PTO and Leave Times
  • Flextime Scheduling
  • Bereavement
  • Paid Time Off (PTO)
  • Paid Parental Leave
Financial Benefits
  • Company-funded 5% contribution to your 401(k) retirement plan
  • Company-funded 5% contribution to your Employee Stock Ownership Plan
  • Continuing Education Assistance
Health, Medical, And Wellness Benefits
  • Medical Insurance
  • Dental & Vision Insurance
  • Life Insurance and Long-Term Disability (LTD)
  • Vision Reimbursement
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

VULNERABILITY MGMT ANALYST
VULNERABILITY MGMT ANALYST

Arete Associates • Falls Church (VA)

On-site
USD 110,000 - 150,000
Flextime Scheduling
Bereavement
PTO
+8
Senior Security Analyst Vulnerability Management
Senior Security Analyst Vulnerability Management

Compass Pointe Consulting, LLC • Bethesda (MD)

On-site
USD 110,000 - 140,000
Vulnerability Management Specialist
Vulnerability Management Specialist

Core Specialty Insurance Services, Inc. • Cincinnati (OH)

Hybrid
USD 80,000 - 100,000
Medical, dental, vision, and life insurance
Short and long-term disability insurance
401(k) plan with company match
+1
Vulnerability Management Analyst
Vulnerability Management Analyst

DANE LLC • Chantilly (VA)

Hybrid
USD 70,000 - 90,000
Life/STD/LTD insurance
401(k) plan
Paid time off
+5
Vulnerability Management Analyst - Remediation Specialist
Vulnerability Management Analyst - Remediation Specialist

Areté • Falls Church (VA)

On-site
USD 110,000 - 145,000
Flextime
Paid Time Off
Parental Leave
+3
Vulnerability Management Analyst
Vulnerability Management Analyst

TIME Systems • Camp Springs (MD)

On-site
USD 90,000 - 130,000
Health coverage
Dental coverage
Vision coverage
+3
Vulnerability Assessment Analyst with Security Clearance
Vulnerability Assessment Analyst with Security Clearance

ShorePoint, LLC • Albuquerque (NM)

On-site
USD 90,000 - 130,000
PTO 144 hours per year
11 holidays
Health insurance 85% premium covered
+2
Vulnerability Management Analyst
Vulnerability Management Analyst

DANE, LLC • Chantilly (VA)

Hybrid
USD 75,000 - 95,000
Life/STD/LTD
FSA/DCA
401(k)
+7
Vulnerability Analyst IV
Vulnerability Analyst IV

ARUP Laboratories • Salt Lake City (UT)

On-site
USD 110,000 - 160,000
Network Vulnerability Analyst | Secret clearance at General Dynamics Information Technology San[...]
Network Vulnerability Analyst | Secret clearance at General Dynamics Information Technology San[...]

General Dynamics Information Technology • San Diego (CA)

On-site
USD 100,000 - 140,000
401(k) plan with company match
Health, dental, and vision coverage
Paid vacation and holidays
+4