Senior Vulnerability Assessment Analyst

Rividium
  • Washington, District of Columbia
    15 days ago

    Job Description

    Position Overview

    RiVidium Inc. seeking a highly skilled Senior Vulnerability Assessment Analyst to support enterprise cybersecurity and vulnerability management activities within a federal environment. The successful candidate will be responsible for identifying, analyzing, prioritizing, and helping remediate vulnerabilities across networks, systems, applications, and infrastructure.

    This role requires strong technical knowledge of vulnerability assessment methodologies, cybersecurity risk management, penetration testing concepts, and security assessment tools. The Senior Vulnerability Assessment Analyst will work closely with cybersecurity engineers, system administrators, ISSOs, security assessors, and program leadership to identify security weaknesses and reduce organizational risk.

    The ideal candidate will be able to translate technical vulnerability findings into actionable remediation recommendations and communicate cybersecurity risks effectively to both technical and non-technical stakeholders.

    Key Responsibilities

    • Conduct comprehensive vulnerability assessments of enterprise systems, networks, applications, servers, and infrastructure.
    • Identify, validate, analyze, and prioritize security vulnerabilities based on severity, exploitability, exposure, and mission impact.
    • Perform vulnerability scanning using industry-standard cybersecurity tools and technologies.
    • Analyze scan results and distinguish legitimate vulnerabilities from false positives.
    • Conduct technical validation and verification of identified vulnerabilities.
    • Support penetration testing and security testing activities as required.
    • Research emerging vulnerabilities, exploits, attack techniques, and threat trends.
    • Map identified vulnerabilities to applicable security controls, systems, assets, and risk categories.
    • Develop detailed vulnerability assessment reports documenting findings, evidence, risk levels, and recommended remediation actions.
    • Provide technical recommendations to system owners and engineering teams for vulnerability remediation.
    • Track remediation activities and verify that vulnerabilities have been appropriately mitigated.
    • Support vulnerability management processes, dashboards, metrics, and reporting.
    • Assist with continuous monitoring and ongoing security assessment activities.
    • Analyze vulnerability trends and identify systemic weaknesses across the enterprise.
    • Support Risk Management Framework (RMF), security assessment, and authorization activities.
    • Assist with Security Control Assessments (SCAs) and technical testing of applicable security controls.
    • Evaluate system configurations and security baselines for compliance with organizational and federal requirements.
    • Support security audits, assessments, and cybersecurity reviews.
    • Coordinate with ISSOs, ISSMs, system owners, engineers, administrators, and other cybersecurity personnel.
    • Maintain accurate vulnerability and remediation records.
    • Provide cybersecurity risk briefings and technical recommendations to program and customer leadership.
    • Stay current on Common Vulnerabilities and Exposures (CVEs), Common Vulnerability Scoring System (CVSS), threat intelligence, and emerging attack techniques.
    • Provide technical mentorship and guidance to junior vulnerability assessment analysts.

    Required Qualifications

    • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related field.
    • Demonstrated experience performing vulnerability assessments, vulnerability management, security testing, or cybersecurity analysis.
    • Strong understanding of network, operating system, application, and infrastructure vulnerabilities.
    • Experience using vulnerability scanning and assessment tools.
    • Ability to analyze vulnerability scan results and validate findings.
    • Knowledge of vulnerability scoring methodologies, including CVSS.
    • Understanding of common attack techniques, exploits, malware, and cybersecurity threats.
    • Experience developing technical vulnerability assessment reports and remediation recommendations.
    • Knowledge of cybersecurity risk management and security control assessment processes.
    • Understanding of NIST cybersecurity frameworks and federal security requirements.
    • Strong analytical, problem-solving, technical writing, and communication skills.
    • Ability to work independently while collaborating effectively with cybersecurity and engineering teams.

    Required Certifications

    Candidates must possess:

    • Certified Ethical Hacker (CEH)
    • Certified Information Systems Security Professional (CISSP)

    Preferred Qualifications

    • Offensive Security Certified Professional (OSCP)
    • GIAC Penetration Tester (GPEN)
    • Experience supporting federal civilian or Department of Defense cybersecurity programs.
    • Experience with NIST SP 800-53, NIST SP 800-37, and FISMA.
    • Experience supporting the Risk Management Framework (RMF).
    • Experience with Security Control Assessments and continuous monitoring.
    • Experience with penetration testing and ethical hacking.
    • Knowledge of web application, database, cloud, network, and endpoint vulnerabilities.
    • Experience with vulnerability management platforms and security dashboards.
    • Experience analyzing CVEs, CVSS scores, exploit availability, and threat intelligence.
    • Experience with cloud vulnerability assessment and security testing.
    • Familiarity with security tools such as Tenable/Nessus, Qualys, Rapid7, Burp Suite, Nmap, or similar technologies.

    Technical Skills

    The ideal candidate should have experience with:

    • Vulnerability Assessment
    • Vulnerability Management
    • Vulnerability Scanning
    • Penetration Testing
    • Ethical Hacking
    • Security Testing
    • CVE Analysis
    • CVSS Scoring
    • Threat and Risk Analysis
    • Network Security
    • Application Security
    • Web Application Security
    • Operating System Security
    • Cloud Security
    • Security Configuration Assessment
    • NIST RMF
    • NIST SP 800-53
    • FISMA
    • Security Control Assessment
    • Continuous Monitoring
    • POA&M Remediation
    • Security Reporting and Metrics
    • Threat Intelligence
    • Vulnerability Remediation
    • Security Architecture

    RiVidium Inc is seeking a 'Senior Vulnerability Assessment Analyst' to support a federal client. This position is contingent upon contract award and funding approval. As such, this job posting is intended to identify qualified candidates for a potential future opportunity and does not represent a currently available position. Compensation has not yet been determined and will be established based on contract requirements, candidate qualifications, experience, and applicable market conditions.

     

    Numbers & Facts

    LocationWashington, District of Columbia

    Skills

    • Access Authorizationunmatched
    • Analysis Skillsunmatched
    • Applications Securityunmatched
    • CEH - Certified Ethical Hackerunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Cloud Computingunmatched
    • Communication Skillsunmatched
    • Computer Hackingunmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Documentationunmatched
    • Establish Prioritiesunmatched
    • FISMA - Federal Information Security Management Actunmatched
    • Fundingunmatched
    • GPEN - GIAC Penetration Testerunmatched
    • Industry Standardsunmatched
    • Information Technology & Information Systemsunmatched
    • Internet Applicationunmatched
    • Internet Securityunmatched
    • Leadershipunmatched
    • Malwareunmatched
    • Mentoringunmatched
    • Metricsunmatched
    • NMapunmatched
    • Nessusunmatched
    • Network Securityunmatched
    • Network Systemsunmatched
    • Operating Systemsunmatched
    • Penetration Testingunmatched
    • Problem Solving Skillsunmatched
    • Reporting Dashboardsunmatched
    • Riskunmatched
    • Risk Managementunmatched
    • Risk Management Framework (RMF)unmatched
    • Security Analysisunmatched
    • Security Architectureunmatched
    • Security Auditingunmatched
    • Security Monitoringunmatched
    • Systems Administration/Managementunmatched
    • Systems Analysisunmatched
    • Systems Engineeringunmatched
    • Technical Presentationunmatched
    • Technical Writingunmatched
    • Testingunmatched
    • Threat and risk analysis (TRA)unmatched
    • Trend Analysisunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • Validation Testingunmatched
    • Vulnerability Scannersunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder