Torch Technologies is seeking a Vulnerability Management & Security Analyst to provide day-to-day scanning, STIG assessment, and remediation tracking for J7 JTSD's cloud migration systems. Working under the guidance of the Primary Government Project Lead and Lead Cybersecurity Specialist, you will ensure all Azure workloads remain hardened and compliant with DoD standards.
As a Vulnerability Management & Security Analyst your duties will include the following, but are not limited to:- Conduct scheduled and ad-hoc vulnerability assessments across Azure Government virtual machines and network components using ACAS (Tenable Nessus).
- Evaluate and document system compliance against DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs) using SCAP tools and STIG Viewer.
- Collaborate with cloud and systems engineers to provide actionable remediation guidance for identified vulnerabilities and IAVAs.
- Populate and maintain Plan of Action & Milestones (POA&M) records within eMASS to ensure accurate risk reporting to Authorizing Officials.
- Monitor cloud security hygiene using Microsoft Defender for Cloud and DISA Continuous Monitoring dashboards.
Qualifications- U.S. Citizenship
- Active DoW Secret clearance.
- Bachelor's degree in Information Technology, Cybersecurity, or related field, plus 2+ years of hands-on DoD cybersecurity analysis and vulnerability scanning experience (or 5+ years without degree).
- 2+ years utilizing Assured Compliance Assessment Solution (ACAS) / Tenable Nessus for network, host, and credentialed scanning.
- Practical experience applying and verifying DISA STIGs across Linux and Windows operating systems.
- Current DoD 8570/8140 IAT Level II certification (e.g., CompTIA Security+ CE, CySA+, or GSEC)
- Strong problem-solving skills and ability to troubleshoot complex issues
- Effective communication and collaboration skills
Preferred Qualifications- Active Top Secret clearance with SCI eligibility.
- Experience configuring and running ACAS scans inside Microsoft Azure Government or AWS GovCloud environments.
- Experience utilizing PowerShell or Bash scripts to automate STIG finding verification and remediation.
- Hands-on experience creating, updating, and closing POA&M entries directly in eMASS.
- Familiarity with Microsoft Defender for Cloud, Secure Score tracking, and Azure Policy compliance states.
- Strong technical documentation, briefing, and reporting experience
Schedule: M-F; 8-5
Work Location: Suffolk, VA or Huntsville, AL - Hybrid / Flexible On-Site.
Travel: Yes, 0-10%
Relocation Assistance Available: No
Position Contingent Upon Award of Contract: No
Salary Range for VA: $105,000-$128,000
The salary range information is a general guideline only. Several factors can influence the salary for a position including but not limited to, Federal Government contract labor categories and contract wage rates, geographic location, business considerations, scope and responsibilities of the position, local or other applicable market conditions, and internal equity. Other factors include the candidate's qualifications such as relevant prior work experience, specific skills and competencies, education/training, and certifications.
#LI-DK1
Benefits:Torch Technologies is proud to offer a stable and professional work environment, a competitive salary, and an excellent, comprehensive benefit package including: ESOP participation, 401(k) match, medical, dental, vision, life insurance, short-term disability, long-term disability, flexible spending accounts, Health Saving Accounts and Health Reimbursement Accounts, EAP, education assistance, paid time off, and holidays.