Demo

Jr. Vulnerability Assessment Analyst

System One
Crownsville, MD Contractor
POSTED ON 1/31/2025
AVAILABLE BEFORE 4/30/2025
Jr. Vulnerability Assessment Analyst
Location: Annapolis, MD (Hybrid)
Targeted Job Start Date: 2/24/2025
Min. Citizenship Status Required: US Citizen
Pay Rate: $30-35/hr W-2

Resumes to Criss Brient: cbrient@altaits.com

ALTA is looking for a Jr. Vulnerability Assessment Analyst with project lead experience and hands-on engineering experience. The Vulnerability Assessment Analyst will be responsible for the planning, implementation, maintenance, and support of the vulnerability management program for a State-Level Department of IT, Security Assessment Function.

Duties and Responsibilities:
  • Daily oversight of vulnerability management program
  • Serve as liaison between Security Assessment and Security Operation Center (SOC) functions on matters pertaining to vulnerability scanning for security assessment efforts
  • Plan, execute, monitor and control, and successfully close vulnerability management projects/tasks
  • Configure and schedule patch and secure configurations audit scan jobs (vulnerability scans)
  • Maintain configurations of patch and secure configurations scan jobs i.e., asset lists, scan plugins, STIGs audit files, CIS Benchmarks audit files, scan credentials
  • Troubleshoot and resolve failed patch and secure configurations scan jobs i.e., missing credentials, asset list updates, firewall issues
  • Analyze patch and secure configurations audit scan results and identify and document technical and procedural vulnerability findings
  • Research resolution strategies/measures for identified vulnerability findings and provide remediation/mitigation recommendations
  • Identify false positive findings and determine and advise on the criteria for validating the findings i.e., required artifacts
  • Prepare vulnerability management reports on the status of patch and secure configuration audit scans and associated remediation efforts
  • Communicate status vulnerability management efforts to include regular scheduled reports and as well as ad hoc reports
  • Ensure the vulnerability management platform maintains updated versions of secure configurations scans audit files i.e., proprietary vendor audit files, STIGs audit files, CIS Benchmarks audit files
  • Ensure that vulnerability management services are operating as expected i.e., completeness of the of each scope scan jobs, timely completion of scan jobs, up-to-date patch audit plugins
  • Ensure proper functioning of integrations between the vulnerability management platform and other tools such as asset management and risk management platforms
  • Ensure and data updates from vulnerability management platforms to asset management and risk management platform are running as scheduled
  • Maintain knowledge of applicable cyber defense policies, regulations, and compliance documents specifically related to cyber defense auditing.
  • Development and implementation operational and technical vulnerability management policies
  • Defining, developing, implementing, and processes and procedures for to support and maintain vulnerability management program

Education and Years of Experience: 
  • At least five (5) years of experience with NIST Risk Management Framework (RMF) supporting technical assessment (vulnerability scans) of control implementations and continuous monitoring post-system Authority to Operate (ATO)
  • At least three (3) years of hands-on experience in LAN Administration i.e., Hands-on administration of Windows OS and Linux OS, and hands-on basics administration of routers, switches, and firewalls.
  • At least two (2) years of hands-on experience with Tenable Security Center/ Nessus Scanners i.e., creating, maintaining, and running scan jobs and analyzing scan results
  • At least two (2) years of hands-on experience executing, monitoring and controlling, and closing security assessment projects
  • Associates or bachelor’s degree from an accredited college or university with a major in Computer Science, Information Systems, Engineering or related scientific or technical discipline.
  • Ability to work outside of regular business hours, the role may require on-call support after regular business hours or weekends.

Required Skills/Certifications:
  • At least 1 security management industry certifications such as Sec , CySA , etc.
  • Self-starter, able to gather requirements, plan, execute system deployment efforts.
  • Able to perform conduct vulnerability assessment of technical security controls, identify and validate findings, research resolutions, and provide remediation/mitigation recommendations.
  • LAN administration experience, particularly with Windows OS and Linux OS.
  • Experience with the vulnerability management tools such as Tenable Security Center/Nessus Scanners, Web Inspect, DB Protect etc.
  • Experience with Governance, Risk, and Compliance (GRC) platforms such as RSA Archer, ServiceNow GRC, CSAM
  • Customer-oriented with excellent issue follow-through and resolution abilities.
  • Excellent written and oral communication, and presentation skills.
  • Ability to effectively work both autonomously as well as on a team.
  • Outstanding interpersonal skills, strong work ethic, and self-motivated.
  • Utilize tools and analytical skills to plan and execute technical changes.
  • Relevant industry certification.

Desired Skills/Certifications:
  • Experience with the vulnerability management tools such as Tenable Security Center/Nessus Scanners, Web Inspect, DB Protect etc.
  • Experience with ServiceNow Governance, Risk, and Compliance (GRC) platforms
  • Experience with Window, Linux, Database, and Web Apps system administration.
  • Experience in project task technical analysis, planning, and estimation.
  • Experience with technology capabilities market research, technical analysis/review, and recommendation.
  • Other relevant industry certifications such as Security , CAP, CEH etc.
#M2

Salary : $30 - $35

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Jr. Vulnerability Assessment Analyst?

Sign up to receive alerts about other jobs on the Jr. Vulnerability Assessment Analyst career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$70,462 - $84,818
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$152,549 - $188,894
Income Estimation: 
$194,072 - $240,547
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at System One

System One
Hired Organization Address Annapolis, MD Other
As a Project Engineer, you will plan, direct, and coordinate construction activities for civil industrial projects such ...
System One
Hired Organization Address Arlington, VA Other
.Net Developer Rosslyn, VA (1-2 days onsite) Secret clearance is required Department of State Responsibilities: • Develo...
System One
Hired Organization Address Houston, TX Other
We’re looking for an experienced Senior Scheduler to drive the successful completion of our heavy civil construction pro...
System One
Hired Organization Address Lincoln, NE Contractor
Job Title : QC Lab Technician I Location : Lincoln, NE 68517 Type: Contract Job Description: Conduct sampling and/or tes...

Not the job you're looking for? Here are some other Jr. Vulnerability Assessment Analyst jobs in the Crownsville, MD area that may be a better fit.

Jr. Vulnerability Assessment Analyst

JASINT, Catonsville, MD

AI Assistant is available now!

Feel free to start your new journey!