Cybersecurity Vulnerability Analyst

Joint Activities

$104K — $166K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor’s degree (5+ years experience) or Master’s (3+ years) or PhD (0+ years) in IT, Computer Science, Cybersecurity, or similar field.
  • Active Secret security clearance required.
  • Active IAT Level II certification (CompTIA Security+ preferred).
  • In-depth understanding of information security principles and practices.
  • Experience with penetration testing (pentesting).
  • Knowledge of MITRE ATT&CK, CVSS, and NIST frameworks for assessing vulnerabilities.
  • Familiarity with OWASP Top 10 web exploitation techniques.

Responsibilities

  • Support the Vulnerability Disclosure Program by reviewing external vulnerability reports.
  • Evaluate the reproducibility and severity of reported vulnerabilities.
  • Utilize HackerOne Triage console for report prioritization and duplicate identification.
  • Conduct vulnerability assessments using offensive toolsets like Kali Linux.
  • Perform web application testing with tools like Burp Suite and automated solutions.
  • Document vulnerability findings and propose mitigations based on assessments.
  • Develop proof-of-concept exploits to showcase vulnerabilities' real-world impact.

Benefits

  • Fully on-site position in the Baltimore-Metropolitan area, M-F schedule.
  • Opportunities for growth in a federal government cybersecurity role.
  • Access to advanced cybersecurity tools and offensive techniques.
  • Collaborative environment liaising with the hacker community.
  • Potential for professional development certifications and training.
Full Job Description
Responsibilities

This Cybersecurity Vulnerability Analyst supports a Vulnerability Disclosure Program (VDP) within the federal government and is responsible for reviewing and vetting security vulnerability reports submitted to the DoD VDP from outside hackers. The Analyst will evaluate the reports to ensure the vulnerability is reproducible and therefore valuable to the customer. They will assess each vulnerability for severity and assign an associated risk statement. The HackerOne Triage console tool will be utilized to assist in assigning and prioritizing reports. It will also assist the Analyst in helping identify duplicate submissions. Valid reports will be written in a DoD approved format and sent to the Vulnerability Management Analyst team for system owner coordination and mitigation. The Vulnerability Analyst will be a VDP liaison with the hacker community.

 

The Vulnerability Analyst will also:

  • Utilize offensive toolsets such as Kali Linux to safely analyze production networks and systems, documenting steps and procedures to produce usable vulnerability assessments for the customer.
  • Identify and investigate vulnerabilities, asses exploit potential, and document findings and remedies for presentation to facilitate mitigations on customer systems.
  • Conduct web application vulnerability assessment testing using both automated tools and manual web exploitation techniques, using tools such as Burp Suite and open-source toolsets.
  • Utilize a variety of industry standard security tools to conduct automated scans against systems and applications.
  • Develop and execute proof-of-concept exploits to demonstrate the real-world impact of identified vulnerabilities, utilizing various web exploitation methods.

This position is fully on-site M-F in the Baltimore-Metropolitan area.

 

#DC3bonus

Qualifications

Required Qualifications:

  • Education: Bachelor’s degree and 5+ years of experience, or Master’s and 3+ years of experience, or PhD and 0+ years of experience. A degree in one of the following fields of study is highly desired: Information Technology, Computer Science, Cybersecurity, Information Systems, Software Engineering, or Data Science. An additional 4 years of relevant experience or specialized training may be considered in lieu of Bachelor's degree.
  • Security Clearance: Active Secret clearance.
  • Certifications: Active IAT Level II certification (CompTIA Security+ preferred).
  • In-depth understanding of information security principles and practices.
  • Pentesting experience.
  • Utilize MITRE ATT&CK, CVSS, and NIST frameworks to assess vulnerability severity and risk impact.
  • In-depth understanding of web exploitation concepts and techniques.
  • Knowledge and understanding of the Open Web Application Security Project (OWASP) top 10.
  • Experience operating in a professional IT or cybersecurity environment.
  • Experience investigating security events, threats and/or vulnerabilities.
  • Understand information security principles, technologies and practices.
  • Excellent customer service skills.

Preferred Additional Skills:

  • CEH, CCNA-Security, CySA+, OSCP (or equivalent), PenTest+ or similar certification a plus.
  • Completed multiple Hack-The-Box penetration testing labs and challenges, developing handson expertise in vulnerability enumeration, exploitation, privilege escalation, and postexploitation techniques within realistic, adversarial environments.
  • Must possess an in-depth understanding of penetration testing methodology, including recon, exploit, persistence, etc.
  • Must have a solid understanding of networking protocols, their uses, and their potential misuses.
  • Programming experience in one or more languages, experience in HTLM/CSS or SQL.
  • Experience with one or more scripting languages such as PowerShell, Bash, Python or Perl.
Target Salary Range$104,000 - $166,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual’s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

Similar Jobs

More Jobs at Joint Activities

More Information Technology Jobs

Find similar Cybersecurity Vulnerability Analyst jobs: