Talent.com
Vulnerability Assessment Analyst

Vulnerability Assessment Analyst

Calibre SystemsSpringfield, Virginia, US
job_description.job_card.30_days_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

CALIBRE is an employee-owned mission focused solutions and digital transformation company. We are currently seeking a Vulnerability Assessment Analyst to support work we are doing in Springfield, VA. This position will be on site. This position performs assessments of systems and networks within the NE or enclave and identifies where those systems / networks deviate from acceptable configurations, enclave policy, or local policy. Measures effectiveness of defense-in-depth architecture against known vulnerabilities. Additional duties :

  • Analyze organization's cyber defense policies and configurations and evaluate compliance with regulations and organizational directives.
  • Conduct and / or support authorized penetration testing on enterprise network assets.
  • Maintain deployable cyber defense audit toolkit (e.g., specialized cyber defense software and hardware) to support cyber defense audit missions.
  • Maintain knowledge of applicable cyber defense policies, regulations, and compliance documents specifically related to cyber defense auditing.
  • Prepare audit reports that identify technical and procedural findings, and provide recommended remediation strategies / solutions.
  • Conduct required reviews as appropriate within environment (e.g., Technical Surveillance, Countermeasure Reviews [TSCM], TEMPEST countermeasure reviews).
  • Perform technical (evaluation of technology) and nontechnical (evaluation of people and operations) risk and vulnerability assessments of relevant technology focus areas (e.g., local computing environment, network UNCLASSIFIED 96 UNCLASSIFIED and infrastructure, enclave boundary, supporting infrastructure, and applications).
  • Make recommendations regarding the selection of cost-effective security controls to mitigate risk (e.g., protection of information, systems and processes). Required Skills
  • Skill in conducting vulnerability scans and recognizing vulnerabilities in security systems.
  • Skill in assessing the robustness of security systems and designs.
  • Skill in detecting host and network based intrusions via intrusion detection technologies (e.g., Snort).
  • Skill in mimicking threat behaviors.
  • Skill in the use of penetration testing tools and techniques.
  • Skill in the use of social engineering techniques. (e.g., phishing, baiting, tailgating, etc.).
  • Skill in using network analysis tools to identify vulnerabilities. (e.g., fuzzing, nmap, etc.).
  • Skill in reviewing logs to identify evidence of past intrusions.
  • Skill in conducting application vulnerability assessments.
  • Skill in performing impact / risk assessments.
  • Skill to develop insights about the context of an organization’s threat environment
  • Skill to apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).
  • Ability to identify systemic security issues based on the analysis of vulnerability and configuration data.
  • Ability to apply programming language structures (e.g., source code review) and logic.
  • Ability to share meaningful insights about the context of an organization’s threat environment that improve its risk management posture.
  • Ability to apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation). required Experience
  • Knowledge of computer networking concepts and protocols, and network security methodologies.
  • Knowledge of risk management processes (e.g., methods for assessing and mitigating risk).
  • Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.
  • Knowledge of cybersecurity and privacy principles.
  • Knowledge of cyber threats and vulnerabilities.
  • Knowledge of specific operational impacts of cybersecurity lapses.
  • Knowledge of application vulnerabilities.
  • Knowledge of cryptography and cryptographic key management concepts
  • Knowledge of data backup and recovery.
  • Knowledge of host / network access control mechanisms (e.g., access control list, capabilities lists).
  • Knowledge of cybersecurity and privacy principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).
  • Knowledge of network access, identity, and access management (e.g., public key infrastructure, Oauth, OpenID, SAML, SPML).
  • Knowledge of how traffic flows across the network (e.g., Transmission Control Protocol [TCP] and Internet Protocol [IP], Open System Interconnection Model [OSI], Information Technology Infrastructure Library, current version [ITIL]).
  • Knowledge of programming language structures and logic.
  • Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, Procedural Language / Structured Query Language [PL / SQL] and injections, race conditions, covert channel, replay, return-oriented attacks, malicious code).
  • Knowledge of systems diagnostic tools and fault identification techniques.
  • Knowledge of what constitutes a network attack and a network attack’s relationship to both threats and vulnerabilities.
  • Knowledge of interpreted and compiled computer languages.
  • Knowledge of different classes of attacks (e.g., passive, active, insider, close-in, distribution attacks).
  • Knowledge of cyber attackers (e.g., script kiddies, insider threat, non-nation state sponsored, and nation sponsored).
  • Knowledge of system administration, network, and operating system hardening techniques.
  • Knowledge of cyber attack stages (e.g., reconnaissance, scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks). K0179 : Knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
  • Knowledge of security models (e.g., Bell-LaPadula model, Biba integrity model, Clark-Wilson integrity model).
  • Knowledge of ethical hacking principles and techniques. K0210 : Knowledge of data backup and restoration concepts.
  • Knowledge of system administration concepts for operating systems such as but not limited to Unix / Linux, IOS, Android, and Windows operating systems.
  • Knowledge of infrastructure supporting information technology (IT) for safety, performance, and reliability.
  • Knowledge of an organization's information classification program and procedures for information compromise.
  • Knowledge of packet-level analysis using appropriate tools (e.g., Wireshark, tcpdump).
  • Knowledge of cryptology.
  • Knowledge of network protocols such as TCP / IP, Dynamic Host Configuration, Domain Name System (DNS), and directory services. K0342 : Knowledge of penetration testing principles, tools, and techniques.
  • Knowledge of an organization’s threat environment.
  • Knowledge of Application Security Risks (e.g. Open Web Application Security Project Top 10 list) Must haves :
  • Current / Active TS / SCI security clearance
  • 4+ years experience
  • IAT Level 2 Certification (Comp TIA Security+ or CCNA or CISSP
  • Two Penetration Testing Certifications (e.g., GPEN, GWAT, GCIH, CEH, GPYC, LPT, CPT)
serp_jobs.job_alerts.create_a_job

Vulnerability Analyst • Springfield, Virginia, US

Job_description.internal_linking.related_jobs
  • serp_jobs.job_card.promoted
Senior Inspector (Cyber)

Senior Inspector (Cyber)

AmentumWashington, DC, US
serp_jobs.job_card.full_time
Amentum is seeking a Senior Inspector (Cyber) to support our U.Department of Energy and Counterintelligence (DOE-IN) contract. Positions will be based in the Washington, D.Serves as Senior Inspector...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
  • serp_jobs.job_card.promoted
Technical Surveillance Countermeasures Lead

Technical Surveillance Countermeasures Lead

Clearance JobsSpringfield, VA, US
serp_jobs.job_card.full_time +1
Technical Surveillance Countermeasures Lead.As the senior Technical Surveillance Countermeasures (TSCM) Lead, you will ensure TSCM team compliance in conducting and completion of all TSCM activitie...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
  • serp_jobs.job_card.promoted
Cyber Security Engineer

Cyber Security Engineer

Rampant TechnologiesChantilly, VA, US
serp_jobs.job_card.full_time
A Rampant Technologies Cybersecurity Engineer (CSE) is a key resource that is a part of the Rampant team.Principal Engineer overseeing the CSE team to deliver innovative Cyber Security solutions th...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
  • serp_jobs.job_card.promoted
  • serp_jobs.job_card.new
Cyber Security Analyst Lead

Cyber Security Analyst Lead

ManTechSpringfield, VA, US
serp_jobs.job_card.full_time
The Cyber Security Analyst Lead is responsible for the detection, identification, analysis, and reporting of cyber threats, intrusions, anomalous activities, and potential misuse of systems.This ro...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
  • serp_jobs.job_card.promoted
Senior Cyber Security Engineer

Senior Cyber Security Engineer

Chenega CorporationWashington, DC, United States
serp_jobs.job_card.full_time
Hybrid, must reside in the Washington D.Chenega Services & Federal Solutions, LLC,.Senior Cyber Security Engineer.Power Apps, Power BI, and Power Automate experience. IT experts supporting a federal...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
  • serp_jobs.job_card.promoted
Senior Inspector (Cyber)

Senior Inspector (Cyber)

Clearance JobsWashington, DC, US
serp_jobs.job_card.full_time
Amentum is seeking a Senior Inspector (Cyber) to support our U.Department of Energy and Counterintelligence (DOE-IN) contract. Positions will be based in the Washington, D.Ensure proper documentatio...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
  • serp_jobs.job_card.promoted
Lead Security Engineer

Lead Security Engineer

Foxhole TechnologyLeesburg, VA, United States
serp_jobs.job_card.full_time
Job Title : Lead Security Engineer.Location : Leesburg, VA -Hybrid (Onsite 3 days per week).Foxhole Technology provides robust cybersecurity and IT support capabilities for federal civilian and defe...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
  • serp_jobs.job_card.promoted
Cyber Security Engineer

Cyber Security Engineer

Leidos IncBethesda, MD, United States
serp_jobs.job_card.full_time
Are you ready to join Leidos all-star team? Through training, teamwork, and exposure to challenging technical work, let Leidos show how to accelerate your career path. Leidos has an exciting opening...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
  • serp_jobs.job_card.promoted
Cyber Security Engineer

Cyber Security Engineer

Via Logic LLCBethesda, MD, United States
serp_jobs.job_card.full_time
Leidos has an exciting opening for you, our next.TS / SCI Cyber Security Engineer.Task Orders under the DOMEX Technology Platform (DTP) contract supporting NMEC. Have impact as part of a mission focus...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
  • serp_jobs.job_card.promoted
Counterintelligence Threat Analyst

Counterintelligence Threat Analyst

Clearance JobsSpringfield, VA, US
serp_jobs.job_card.full_time
Counterintelligence Threat Analyst.Louis, MO Government / Military Clearance Required : TS / SCI with ability to obtain CI Polygraph Full-Time | Contingent (Anticipated Award September 2025) Protect Na...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
  • serp_jobs.job_card.promoted
Senior Malware Analyst

Senior Malware Analyst

LeidosAlexandria, VA, US
serp_jobs.job_card.full_time
Leidos has a current job opportunity for a.DISA GSM-O program in Alexandria, VA.An active Top Secret security clearance and demonstrated advanced technical ability in reverse engineering custom pro...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
  • serp_jobs.job_card.promoted
Cyber Analyst - ConMon

Cyber Analyst - ConMon

Leidos IncAlexandria, VA, United States
serp_jobs.job_card.full_time
Leidos is seeking multiple ConMon Analysts to be responsible for overseeing and monitoring authorized IT systems (re-authorization and new systems) throughout their lifecycle for security posture i...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
  • serp_jobs.job_card.promoted
Technical Surveillance Countermeasures Lead

Technical Surveillance Countermeasures Lead

Booz Allen HamiltonSpringfield, VA, US
serp_jobs.job_card.full_time +1
Technical Surveillance Countermeasures Lead.As the senior Technical Surveillance Countermeasures (TSCM) Lead, you will ensure TSCM team compliance in conduct and completion of all TSCM activities, ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
  • serp_jobs.job_card.promoted
Surveillance Investigator

Surveillance Investigator

Allied UniversalFredericksburg, VA, United States
serp_jobs.job_card.full_time
Advance Your Career in Insurance Claims with Allied Universal Compliance and Investigation Services.Allied Universal Compliance and Investigation Services is the premier destination for a career in...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
  • serp_jobs.job_card.promoted
Senior Malware Analyst

Senior Malware Analyst

Leidos IncAlexandria, VA, United States
serp_jobs.job_card.full_time
Leidos has a current job opportunity for a.DISA GSM-O program in Alexandria, VA.An active Top Secret security clearance and demonstrated advanced technical ability in reverse engineering custom pro...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
  • serp_jobs.job_card.promoted
Senior Cyber Security Engineer

Senior Cyber Security Engineer

ManTechChantilly, VA, United States
serp_jobs.job_card.full_time
ManTech seeks a motivated, career and customer-oriented.Senior Cyber Security Engineer.Senior Cyber Security engineers are responsible for the quality of cyber security related solution delivery, d...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
  • serp_jobs.job_card.promoted
  • serp_jobs.job_card.new
Security Professional - Tech / Media Unarmed Patrol

Security Professional - Tech / Media Unarmed Patrol

Allied UniversalLeesburg, VA, United States
serp_jobs.job_card.full_time
Security Professional - Tech / Media Unarmed Patrol.Monday, Tuesday, Wednesday, Saturday, Sunday.Allied Universal, North America's leading security and facility services company, offers rewarding car...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
  • serp_jobs.job_card.promoted
Vulnerability Assessment Analyst

Vulnerability Assessment Analyst

Calibre SystemsSpringfield, VA, United States
serp_jobs.job_card.full_time
CALIBRE is an employee-owned mission focused solutions and digital transformation company.We are currently seeking a Vulnerability Assessment Analyst to support work we are doing in Springfield, VA...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
  • serp_jobs.job_card.promoted
Global Threat Analyst

Global Threat Analyst

GoogleWashington, DC, US
serp_jobs.job_card.full_time
Security is at the core of Google's design and development process : it is built into the DNA of our products.The same is true of our offices. You're an expert who shares our seriousness about securi...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
  • serp_jobs.job_card.promoted
Senior Technical Surveillance Countermeasures Lead

Senior Technical Surveillance Countermeasures Lead

Tetrad Digital IntegritySpringfield, VA, US
serp_jobs.job_card.permanent
Senior Technical Surveillance Countermeasures (TSCM) Lead.Tetrad Digital Integrity (TDI) is a leading-edge cybersecurity firm with a mission to safeguard and protect our customers from increasing t...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days