Vulnerability Management Analyst
SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure and Operations, and Applications Development and Maintenance IT service provider headquartered in Dulles, Virginia with operations across the U.S. We provide innovative enterprise-wide solutions as well as targeted services addressing the complex challenges faced by our federal government clients. Our focus is on enabling our clients to deliver their mission most efficiently and effectively – anytime, anywhere, securely. We combine technical expertise, mission awareness, and an empowered workforce to produce meaningful results.
This is a contingent position based on contract win.
SkyePoint Decisions is seeking a Vulnerability Management Analyst to support a cybersecurity program by identifying, analyzing, tracking, and reporting security vulnerabilities across enterprise systems, applications, databases, cloud environments, and network infrastructure. The Analyst collaborates with system owners, security engineers, RMF personnel, and operational teams to ensure vulnerabilities are properly assessed, prioritized, remediated, and verified in accordance with HHS and Federal cybersecurity requirements.
The position plays a key role in maintaining a strong security posture through continuous monitoring, risk analysis, remediation tracking, and compliance reporting.
Responsibilities:
- Perform vulnerability assessments and analysis across information systems and infrastructure.
- Perform threat-informed prioritization using exploitability, threat intelligence, CISA Known Exploited Vulnerabilities (KEV), mission criticality, system exposure, and compensating controls.
- Assess vulnerability risk within the context of system criticality, data sensitivity, and organizational risk tolerance.
- Develop vulnerability dashboards, remediation metrics, trend analyses, and executive reporting products.
- Review and analyze vulnerability scan results from enterprise security tools.
- Validate findings to determine severity, exploitability, and potential impact.
- Conduct risk-based prioritization of vulnerabilities and security weaknesses.
- Coordinate with technical teams to assess remediation requirements and timelines.
- Manage the full lifecycle of vulnerability identification, remediation, and closure.
- Track vulnerabilities from discovery through remediation and validation.
- Maintain vulnerability repositories, remediation records, and status reporting.
- Monitor remediation progress and escalate overdue findings as appropriate.
- Verify corrective actions and document closure activities.
- Support continuous monitoring activities across systems and applications.
- Analyze vulnerability trends and identify recurring issues.
- Evaluate security risks associated with discovered vulnerabilities.
- Collaborate with RMF/A&A teams to support Authorization to Operate (ATO) activities.
- Assist with the management and tracking of Plans of Action and Milestones (POA&Ms).
- Provide vulnerability-related evidence and documentation for audits, assessments, and authorization activities.
Required Qualifications:
- Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Engineering, or a related field.
- Minimum 5 years of experience in cybersecurity, vulnerability management, information assurance, or security operations supporting Federal environments.
- Experience supporting POA&M development, remediation tracking, corrective action validation, or vulnerability closure activities.
- Experience conducting vulnerability assessments and remediation tracking.
- Familiarity with:
- NIST RMF (SP 800-37)
- NIST SP 800-53 Rev. 5
- FISMA
- Federal cybersecurity compliance requirements
- Risk assessment methodologies
- Experience analyzing vulnerability data and developing remediation recommendations.
- Strong analytical, problem-solving, and communication skills.
- U.S. Citizenship required.
- Ability to obtain and maintain a Public Trust.
Preferred Qualifications:
- One or more of the following certifications:
- Security+
- Certified Ethical Hacker (CEH)
- CISSP
- GIAC Vulnerability Assessment (GVA)
- GIAC Information Security Fundamentals (GISF)
- GSEC
- CAP (Certified Authorization Professional)
- CISM
- CRISC
- Experience supporting HHS or other Federal civilian agencies.
- Experience working within FISMA-compliant environments.
- Knowledge of cloud security and vulnerability management practices.
- Experience supporting continuous diagnostics and mitigation (CDM) initiatives.
- Understanding of FedRAMP and Zero Trust security principles.
- Experience coordinating remediation activities across multiple stakeholders.
Compensation:
Salary Range: $110,000 - $130,000
The SkyePoint Decisions salary range for this position is a general guideline only. It represents an estimated range for this position and is just one piece of our total compensation package.
Salary at SkyePoint is determined by various factors, including but not limited to location, work schedule, the candidate’s combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability, market data and business considerations.
In addition to a competitive salary, SkyePoint offers benefits including a certification incentive program, PTO, floating federal holiday options, several insurance options including HMO and High Deductible plans with Health Savings Accounts [HSAs], Flex Spending Accounts [FSAs], Full Dental Plans, Vision, ST/LT Disability, Life Insurance, and 401k matched.
What We Can Offer You:
- At SkyePoint, we go B.I.G. (beginning in GRATITUDE) by recognizing all we have and giving back to our employees, families, and communities. It instills a positive mindset that permeates all we do. By beginning in gratitude, SkyePoint can continue to spread living in gratitude each day.
- Great Benefits: Several insurance options including HMO and High Deductible plans with Health Savings Accounts [HSAs], Flex Spending Accounts [FSAs], Full Dental Plans, ST/LT Disability, Life Insurance, floating federal holiday options, and 401k matched
- Certificate Incentive Program: To promote professional development, we recognize and reward employees who obtain new certifications aligned with business needs.
- Flexible Work Environment
SkyePoint Decisions is an established ISO 9001:2015 and ISO/IEC 27001:2013 certified small business and appraised at CMMI Level 3 for Services and Development. We possess a common vision of excellence and foster a collaborative team culture built upon individual performance and accountability. We invest in our people and systems to create value for our clients. It is the SkyePoint Way. We are grateful for the opportunity to work with exceptional people and give back to the communities we serve. Our employees value the flexibility at SkyePoint that allows them to balance quality work and their personal lives.
SkyePoint Decisions is a participating E-Verify Employer.
U.S. Citizenship is required for most positions.
Equal Opportunity Employer/Veterans/Disabled.
CCPA Disclosure Notice Here
Apply for this job
*
indicates a required field