Job Title: Mid-Level Vulnerability Management AnalystLocation: Bethesda, Maryland
Type: Direct Hire / Perm
Work Model: 99% remote with occasional onsite for meetings
Security Clearance: Public Trust Position Summary The Mid-Level Vulnerability Management Analyst performs vulnerability scanning, analysis, reporting, remediation tracking, and stakeholder coordination across NIH/OD-managed systems.
Key Responsibilities
- Perform scheduled and ad hoc credentialed vulnerability scans.
- Review and analyze vulnerability scan results.
- Identify critical and known exploited vulnerabilities.
- Monitor the CISA KEV Catalog and other approved sources.
- Notify technical contacts of vulnerabilities and configuration issues.
- Develop remediation recommendations.
- Track vulnerabilities through closure and validate remediation.
- Support High Value Asset assessments.
- Prepare recurring and ad hoc vulnerability reports.
- Maintain documentation and support process improvements.
Minimum Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field.
- 3-6 years of cybersecurity experience with vulnerability management.
- Experience with enterprise vulnerability management platforms.
- Knowledge of CVEs, CVSS, KEVs, NIST guidance, and FISMA.
- Strong analytical and communication skills.
Recommended Certifications
- CompTIA Security+
- CompTIA CySA+
- GIAC Certified Vulnerability Assessor (GCVA)
- ISC2 Certified in Cybersecurity (CC)
- Tenable Certified Professional
- Qualys VMDR Certification
System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.
#M-2
#LI-CB5
Ref: #856-Baltimore-S1