DFC - Vulnerability Management Analyst

cFocus Software Incorporated

  • Washington, DC
  • 3 days ago
  • Remote
    Want to know if you’re a fit?
    Upload your resume and let our AI show you.

    Skills

    • Analysis Skillsunmatched
    • Authenticationunmatched
    • CISA - Certified Information Systems Auditorunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Cloud Applicationsunmatched
    • Communication Skillsunmatched
    • CompTIA Security+unmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Data Qualityunmatched
    • Documentationunmatched
    • Establish Prioritiesunmatched
    • FISMA - Federal Information Security Management Actunmatched
    • Governmentunmatched
    • Groundskeepingunmatched
    • Information Technology & Information Systemsunmatched
    • International Financeunmatched
    • Internet Securityunmatched
    • Microsoft Product Familyunmatched
    • Nessusunmatched
    • Reconciliationunmatched
    • Record Keepingunmatched
    • Riskunmatched
    • Risk Analysisunmatched
    • Risk Managementunmatched
    • Risk Management Framework (RMF)unmatched
    • Security Complianceunmatched
    • ServiceNowunmatched
    • Software Engineeringunmatched
    • Software Patchesunmatched
    • Support Documentationunmatched
    • System Validationunmatched
    • Systems Administration/Managementunmatched
    • Time Managementunmatched
    • Traceabilityunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • Vulnerability Scannersunmatched
    • Writing Skillsunmatched

    Description

    cFocus Software seeks a Vulnerability Management Analyst to join our program supporting the United States International Defense Finance Agency (DFC). This position is remote. This position requires an Active Public Trust clearance.Qualifications:
    • Active Public Trust clearance
    • B.S. Computer Science, Information Technology, or a related field
    • 5+ years of cybersecurity experience, including three or more years in vulnerability management, security compliance, POA&M management, or a closely related function.
    • Hands-on experience analyzing authenticated scan results and validating vulnerabilities using Tenable Nessus, Qualys, Microsoft Defender, or comparable enterprise platforms.
    • Demonstrated ability to assess vulnerability risk using CVSS, exploitability, CISA KEV status, asset criticality, exposure, mission impact, threat intelligence, and compensating controls.
    • Experience creating and maintaining POA&M records, tracking remediation milestones, reconciling GRC and ticketing systems, validating closure evidence, and documenting false-positive determinations.
    • Working knowledge of FISMA, the NIST Risk Management Framework, NIST SP 800-53 controls, NIST SP 800-40 vulnerability and patch-management principles, CISA KEV/BOD 22-01 requirements, and federal continuous-monitoring expectations.
    • Ability to communicate technical risk clearly to federal cybersecurity leaders, System Owners, engineers, administrators, auditors, and nontechnical stakeholders.
    • Strong analytical writing, data-quality, documentation, prioritization, and time-management skills in a deadline-driven environment.
    • Active Security+, CySA+, CEH, GCVA, CISSP or other relevant security certifications preferred.
    Duties:
    • Coordinate authenticated vulnerability scans with DFC stakeholders at frequencies aligned with policy, system criticality, exposure, threat conditions, and Government direction.
    • Analyze output from Tenable, Qualys, Microsoft Defender, and other Government-approved vulnerability, endpoint, configuration, and posture-management platforms.
    • Validate scanner findings against the operational environment and distinguish valid findings from false positives using documented rationale and supporting evidence.
    • Assess and assign severity using CVSS, DFC policy, exploitability, known-exploitation status, asset criticality, external exposure, mission impact, and relevant threat intelligence.
    • Recommend risk-informed remediation priorities, actions, timelines, evidence requirements, and closure criteria.
    • Coordinate with engineering, operations, application, cloud, endpoint, and system administration teams to establish remediation ownership, dependencies, and target completion dates
    • Provide rapid analysis and coordination for CISA Known Exploited Vulnerabilities (KEV), Binding Operational Directive 22-01 requirements, CISA Emergency Directives, vendor-declared zero-days, and vulnerabilities with active exploitation.
    • Notify the ISSM within four hours of applicable CISA notification, vendor disclosure, Government notification, or Contractor identification.
    • Verify exposure across applicable CSAM authorization boundaries and deliver a written impact assessment within one business day.
    • Document affected systems, boundaries and assets; severity; exposure; exploitability; known exploitation; mission impact; remediation ownership; required timelines; recommended action; and residual-risk considerations.
    • Track emergency remediation against CISA-, DFC-, or Government-directed deadlines and provide written confirmation of remediation status, compliance status, residual risk, and closure evidence.
    • Use CSAM as the authoritative POA&M and compliance ledger and ServiceNow as the operational remediation ticketing record.
    • Create complete POA&M items in CSAM within three business days after finding identification or Government direction, unless the Government establishes another deadline.
    • Populate and maintain required fields, including identifier, weakness description, affected system and control, severity, source, responsible owner, required resources, scheduled completion date, milestones, status, residual risk, and closure evidence.
    • Maintain bidirectional traceability so each applicable ServiceNow remediation ticket links to its CSAM POA&M item and each CSAM POA&M record references the appropriate ServiceNow ticket.
    • Track remediation through closure, monitor milestone integrity and aging, and coordinate scheduled-completion-date changes only after federal authorization.
    • Conduct monthly ServiceNow-to-CSAM reconciliation; identify stale or duplicate records, missing links or evidence, inconsistent status, inaccurate dates, and other data-quality issues; issue a written discrepancy log and track gaps to resolution.
    • Prepare risk-acceptance or exception recommendation packages when remediation cannot be completed within applicable timelines or scheduled-completion-date constraints.
    • Document the affected system and weakness, operational and mission impacts, exploitability, exposure, residual risk, compensating controls, remediation constraints, proposed duration and expiration, review interval, and conditions for continued acceptance.
    • Route recommendation packages to the AODR through the COR and ISSM for federal decision and accurately record approved decisions in CSAM.
    • Clearly preserve federal authority: do not accept risk for DFC, approve exceptions, extend POA&M dates without authorization, or make final closure decisions.

    Powered by JazzHR

    Numbers & Facts

    LocationWashington, DC (
    Remote
    )

    Similar Jobs

    See more jobs