Cyber Vulnerability Assessment Analyst - Intermediate

NewSat North America LLC
  • Colorado Springs, CO
    1 day ago

    Job Description

    Job Description

    Job Description

    POSITION SUMMARY

    NewSat is seeking an Intermediate-level Vulnerability Assessment Analyst to support our U.S. Space Force (USSF) customer. This position performs vulnerability assessment and remediation-tracking activities across a platform spanning more than 42 deployed environments across approximately 900 servers at multiple classification levels.


    Working with only periodic high-level guidance, the Intermediate VAA executes recurring and ad hoc assessments, validates findings, and supports remediation and continuous monitoring activities in non-routine and sometimes complicated situations. This role supports the task order’s Continuous Cyber Monitoring, Threat Assessment and Risk Mitigation, and Body of Evidence artifact management service areas.

    KEY RESPONSIBILITIES

    •      Execute scheduled and ad hoc vulnerability scans across the existing environment and during assessment of new connections using ACAS/Nessus and DoD-approved assessment tooling.

    •      Apply DISA STIGs and SCAP benchmarks; validate compliance results and research findings to confirm or dismiss false positives.

    •      Analyze scan output, correlate findings across environments, and document results in standardized assessment reports.

    •      Track remediation actions to closure with system owners; support POA&M entry, updates, and supporting evidence.

    •      Assemble Body of Evidence (BoE) artifacts supporting Certificate to Field (CtF), Authority to Connect (ATC) and continuous monitoring requirements.

    •      Support assessment of cloud and container workloads, including AWS tenant spaces and EKS-hosted services.

    •      Escalate complex, high-risk, or disputed findings to the Advanced VAA or Security Architect for adjudication.

    •      Maintain assessment documentation, scan configurations, and reporting cadence in accordance with program procedures.

    REQUIRED QUALIFICATIONS

    •      Active TS clearance with SCI eligibility; ability to meet program-directed access requirements.

    •      Minimum 4 years of cybersecurity experience with direct vulnerability assessment or vulnerability management responsibility.

    •      Security+ CE or equivalent DoD 8140 / 8570 baseline certification current at time of hire.

    •      Hands-on experience with ACAS/Nessus or comparable scanning platforms and with STIG/SCAP compliance checking.

    •      Familiarity with RMF, NIST SP 800-53 control families, and POA&M processes.

    •      Ability to work non-routine assessment tasks with only periodic high-level supervision.

    PREFERRED QUALIFICATIONS

    •      Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or a related field.

    •      Experience supporting DoD, IC, or space ground system programs.

    •      Certifications such as CySA+, CEH, GCIH, or GSEC.

    •      Exposure to containerized or cloud environments (Kubernetes/EKS, AWS).

    •      Scripting familiarity (Python, PowerShell, Bash) for reporting and data reduction.

    \nCompany Description

    NewSat provides cost-competitive, best-of-breed, global C5ISR solutions to ensure mission success for our customers. Our small business provides solutions to many industry partners, both as a prime contractor and value-added subcontractor.

    Company Description

    NewSat provides cost-competitive, best-of-breed, global C5ISR solutions to ensure mission success for our customers. Our small business provides solutions to many industry partners, both as a prime contractor and value-added subcontractor.

    Numbers & Facts

    LocationColorado Springs, CO

    Skills

    • Adjudicationunmatched
    • Advertising Schedulingunmatched
    • Amazon Web Services (AWS)unmatched
    • Analysis Skillsunmatched
    • Bash Scriptingunmatched
    • Benchmarkingunmatched
    • Business Solutionsunmatched
    • Cadenceunmatched
    • Cloud Computingunmatched
    • CompTIA Security+unmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Data Reductionunmatched
    • Defense Information Systems Agency (DISA)unmatched
    • DoD Directive 8140unmatched
    • DoD Directive 8570unmatched
    • Documentationunmatched
    • Documentation Standardsunmatched
    • GCIH - GIAC Certified Incident Handlerunmatched
    • GSEC - GIAC Security Essentials Certificationunmatched
    • Information Technology & Information Systemsunmatched
    • Integrated Circuits (ICs)unmatched
    • Internet Securityunmatched
    • Machine Toolunmatched
    • Maintain Complianceunmatched
    • Multiplatform/Cross-Platformunmatched
    • Nessusunmatched
    • Python Programming/Scripting Languageunmatched
    • Riskunmatched
    • Risk Managementunmatched
    • Scripting (Scripting Languages)unmatched
    • Security Architectureunmatched
    • Security Attacksunmatched
    • Sensitive Compartmented Information (SCI)unmatched
    • Small Businessunmatched
    • Threat and risk analysis (TRA)unmatched
    • Top Secret Clearanceunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • United States Department of Defense (DoD)unmatched
    • Vulnerability Scannersunmatched
    • Windows PowerShellunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder