Vulnerability Assessment Analyst
Core
Safeguarding critical systems by configuring and executing vulnerability scans, analyzing threat intelligence, and interpreting vulnerability announcements for US federal government clients.
Role type
Vulnerability Assessment Analyst
Builds
Security documentation (System Body of Evidence artifacts) and risk management support for federal programs
Domain
US Federal Government / Cybersecurity
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
vulnerability scanning, threat intelligence analysis, risk assessment, security testing, incident response, System Security Plan (SSP) development, Plan of Actions and Milestones (POA&M) management, Security Control Traceability Matrix (SCTM) creation, Risk Assessment Reports (RAR) generation, Concept of Operations (CONOPS) development
Preferred skills
8140 Advanced certification, CISM, CISA, CISSP, CySA+, SecurityX, CFR, GPEN, GSNA, network protocol knowledge, secure system architecture, host and network access controls
Technologies
eMASS package, STIG checklists, RMF framework
Responsibilities
Evaluate scan results and prepare comprehensive reports; Brief leadership on risk landscape and emerging threats; Collaborate with ISSEs and ISSOs for information assurance support; Develop and publish System Body of Evidence (BOE) artifacts
Seniority
Mid-level, hands-on IC