Vulnerability Management Analyst

10 hours, 39 minutes ago
Full-time
Senior
Cybersecurity
Copper River Management

Copper River Management

Copper River Management specializes in delivering innovative IT solutions and services to federal, state, local, and enterprise clients, leveraging its status as an Alaska Native Tribal Owned SBA 8(a) participant to support diverse missions across vari...

Internet Software & Services
11-50
Founded 2006

Description

  • Perform vulnerability assessments and analyze security weaknesses across NIH systems and infrastructure.
  • Review vulnerability scan results and validate findings for severity, exploitability, and impact.
  • Use threat intelligence, CISA KEV, mission criticality, exposure, and compensating controls to prioritize remediation efforts.
  • Assess vulnerability risk in the context of system criticality, data sensitivity, and organizational risk tolerance.
  • Develop dashboards, remediation metrics, trend analyses, and executive reporting products.
  • Coordinate with technical teams on remediation requirements, timelines, and corrective actions.
  • Track vulnerabilities through identification, remediation, validation, and closure.
  • Maintain vulnerability repositories, remediation records, and status reports.
  • Monitor remediation progress, escalate overdue findings, and document closure activities.
  • Support continuous monitoring, ATO activities, POA&M tracking, audits, and authorization evidence requests.

Requirements

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field.
  • Minimum 5 years of experience in cybersecurity, vulnerability management, information assurance, or security operations supporting Federal environments.
  • Experience supporting POA&M development, remediation tracking, corrective action validation, or vulnerability closure activities.
  • Experience conducting vulnerability assessments and remediation tracking.
  • Familiarity with NIST RMF (SP 800-37), NIST SP 800-53 Rev. 5, FISMA, Federal cybersecurity compliance requirements, and risk assessment methodologies.
  • Experience analyzing vulnerability data and developing remediation recommendations.
  • Strong analytical, problem-solving, and communication skills.
  • Ability to obtain and maintain an NIH Public Trust.
  • One or more relevant certifications preferred, including Security+, CEH, CISSP, GVA, GISF, GSEC, CAP, CISM, or CRISC.
  • Preferred experience supporting NIH, HHS, or other Federal civilian agencies, FISMA-compliant environments, CDM initiatives, cloud security, FedRAMP, and Zero Trust.

Benefits

  • $115,000 to $131,000 USD annual pay range.
  • Comprehensive medical, dental, and vision coverage.
  • Flexible Spending Account for healthcare and dependent care.
  • Health Savings Account with a high-deductible medical plan.
  • 401(k) retirement plan with employer match.
  • Open leave policy and paid holidays.
  • Tuition reimbursement, transportation expense account, and employee assistance program.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

SOC Supervisor

Central Transportation Services, Inc. 11-50 transportation/trucking/railroad

CTS is seeking a remote SOC Supervisor to lead daily security operations, incident response, and team performance within its managed services environment.

SIEM
10 hours, 54 minutes ago

Senior Governance, Risk, and Compliance (GRC) Analyst (Remote)

RainFocus 251-1K IT Services

RainFocus is hiring a Senior Governance, Risk, and Compliance (GRC) Analyst to own and advance its security and privacy compliance program for a fast-growing event software platform serving enterprise customers.

1 day, 11 hours ago

OSINT Analyst - Vessel Identification

Kpler 251-1K Professional Services

Kpler is hiring an OSINT Analyst for its Maritime Domain Awareness team to adjudicate difficult vessel identifications, investigate identity manipulation, and improve the accuracy of its unified vessel records and detection models.

Machine Learning
1 day, 11 hours ago

IT Intern - 6 months FTC

Swapcard 251-1K Professional Services

Swapcard is hiring a remote IT Intern to support its global IT & Security team in keeping internal systems, devices, and employee access running smoothly for a fully distributed event-tech company.

Cybersecurity JIRA macOS Notion
1 day, 11 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers