Talent.com
Vulnerability Assessment Analyst

Vulnerability Assessment Analyst

The Johns Hopkins University Applied Physics LaboratoryLaurel, MD, United States
job_description.job_card.variable_days_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

Description

Do you love being part of a team of highly skilled, motivated, and dedicated professionals responsible for protecting sensitive data while administering enterprise Information Systems (IS) that support the Johns Hopkins University Applied Physics Laboratory (JHUAPL) mission?

Do you want to integrate vulnerability management, cybersecurity, and compliance within our enterprise, sector, and department networks?

Do you have a deep-seated passion for protecting our Nation's sensitive information?

If so, we're looking for someone like you to join our team at APL.

We are seeking a dedicated Vulnerability Assessment Analyst to help protect APL's unclassified, enterprise information technology infrastructure, including unclassified systems and components. In this role, you will be responsible for identifying, assessing, and remediating vulnerabilities as they pertain to risk in our information systems while ensuring compliance with relevant regulations and standards. You'll actively work with our defensive cybersecurity teams to evaluate, assess, and remediate vulnerabilities in accordance with risk management in our information systems. As a member of our team, you'll contribute to Cybersecurity, Compliance Management and Oversight of our unclassified information systems in support of Sponsor / Program needs.

As a Vulnerability Assessment Analyst, you will...

  • Conduct vulnerability scans and analyze data to prioritize remediation for an enterprise environment.
  • Assess and identify systemic security issues based on the analysis of vulnerability and configuration data.
  • Configure and maintain Tenable Products to ensure compliance and the latest updates.
  • Analyze organization's cybersecurity policies and configurations and evaluate compliance with regulations and organizational directives.
  • Prepare audit reports that identify technical and procedural findings and provide recommended remediation strategies and solutions.
  • Perform technical (evaluation of technology) and non-technical (evaluation of people and operations) risk and vulnerability assessments of relevant technology focus areas, including local computing environments, networks and infrastructure, control systems and operational environments, enclave boundaries, supporting infrastructure, and applications.
  • Conduct risk assessments and provide recommendations on the selection of cost-effective security controls to mitigate risks, including the protection of information, systems, and processes.
  • Research Vulnerability Management products, vulnerabilities, solutions, and root causes.
  • Stay current with the latest industry best practices, technology trends, and security vulnerabilities as they pertain to the Lab's technologies, and attend DoD ACAS / Tenable Product Meetings.
  • Work with other compliance analysts to maintain System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), supporting artifacts, and other compliance-related documentation.
  • Collaborate with cross-functional teams, including IT, contracts, and legal, to ensure security requirements are integrated into system development and operations.
  • Support the Risk Management Framework (RMF) lifecycle activities, including asset categorization, CMMC practice application, and continuous assessment & monitoring.
  • Help support both internal and external audits and assessments related to CMMC, NIST SP800-171, Privacy & Health Controls, and other cybersecurity and compliance-related activities.
  • Assist with developing and implementing a corrective action plan to address any identified compliance gaps, risks, and monitoring changes to the DFARS, CMMC, NIST SP800-171, FedRAMP, and other RMF and cybersecurity-related standards and regulations, and update internal processes accordingly.

Qualifications

You meet our minimum qualifications for the job if you...

  • Possess a B.S. Degree in Information Technology, Cybersecurity, Computer Science, Information Systems, Data Science, or other related field, or equivalent years of professional work experience.
  • 4+ years' experience developing, managing, or having direct implementation responsibility for vulnerability management tools, processes, policies, and plans for enterprise information technology systems.
  • Have experience working with Vulnerability Management products (e.g., Tenable)
  • Possess strong analytical, technical, and research skills, with a passion for data quality and process rigor.
  • Possess a good understanding of system-level software and operating systems, to include Windows, macOS, Linux, virtualization, and containerization, as well as a working knowledge of computing hardware, desktop applications, computer networking, and cloud technologies.
  • Experienced in contextualizing vulnerability and threat risk by assessing actual impact to organizational systems rather than relying solely on vendor or government-provided ratings.
  • Have experience with system monitoring, audit logging, aggregation, and correlation tools (e.g., Splunk).
  • Hands-on experience building analytical reports, dashboards, and interactive visualizations across platforms such as Splunk and Power BI.
  • Aggregate and correlate vulnerability data from various sources to improve product interoperability, identify blind spots, and design custom detection and remediation workflows.
  • Have a strong working knowledge of NIST SP 800-171, 800-53 and 800-37, and particularly the DoD Cybersecurity Maturity Model Certification (CMMC) Program, and the ability to support risk-based decisions and ensure compliance across the enterprise.
  • Be able to obtain the CMMC Certified Professional (CCP) credential within the first six (6) months of hire.
  • Possess a comprehensive understanding of government cybersecurity compliance standards, regulations, and policies, with the ability to communicate requirements to all stakeholders necessary to support the enterprise system, including configuration changes, application patching, incident response, vulnerability mitigation, and risk management.
  • Are able to obtain a Secret security clearance. If selected, you will be subject to a government security clearance investigation and must meet the requirements for access to classified information. Eligibility requirements include U.S. citizenship.
  • You'll go above and beyond our minimum requirements if you...

  • Meet and demonstrate intermediate DoD 8140.03 Cyberspace Workforce Qualification and Management Program requirements through training and / or certifications (e.g., Security+, equivalent, or higher security certification).
  • Possess a Master's degree in Information Technology, Cybersecurity, Computer Science, Information Systems, Data Science, or other related field, or equivalent years of professional work experience.
  • Meet and demonstrate advanced DoD 8140.03 Cyberspace Workforce Qualification and Management Program requirements through training and / or certifications (e.g., CISSP, equivalent, or higher security certification).
  • Have additional experience in cybersecurity supporting domains such as intelligence analysis, Security Operations Center (SOC) support, governance, and / or risk management, Development, Security, Operations (DevSecOps), computer forensics, policy creation, technical writing, incident response, disaster recovery, etc.
  • About Us

    Why Work at APL?

    The Johns Hopkins University Applied Physics Laboratory (APL) brings world-class expertise to our nation's most critical defense, security, space and science challenges. While we are dedicated to solving complex challenges and pioneering new technologies, what makes us truly outstanding is our culture. We offer a vibrant, welcoming atmosphere where you can bring your authentic self to work, continue to grow, and build strong connections with inspiring teammates.

    At APL, we celebrate our differences of perspectives and encourage creativity and bold, new ideas. Our employees enjoy generous benefits, including a robust education assistance program, unparalleled retirement contributions, and a healthy work / life balance. APL's campus is located in the Baltimore-Washington metro area. Learn more about our career opportunities at http : / / www.jhuapl.edu / careers .

    All qualified applicants will receive consideration for employment without regard to race, creed, color, religion, sex, gender identity or expression, sexual orientation, national origin, age, physical or mental disability, genetic information, veteran status, occupation, marital or familial status, political opinion, personal appearance, or any other characteristic protected by applicable law. APL is committed to providing reasonable accommodation to individuals of all abilities, including those with disabilities. If you require a reasonable accommodation to participate in any part of the hiring process, please contact Accommodations@jhuapl.edu .

    The referenced pay range is based on JHU APL's good faith belief at the time of posting. Actual compensation may vary based on factors such as geographic location, work experience, market conditions, education / training and skill level with consideration for internal parity. For salaried employees scheduled to work less than 40 hours per week, annual salary will be prorated based on the number of hours worked. APL may offer bonuses or other forms of compensation per internal policy and / or contractual designation. Additional compensation may be provided in the form of a sign-on bonus, relocation benefits, locality allowance or discretionary payments for exceptional performance. APL provides eligible staff with a comprehensive benefits package including retirement plans, paid time off, medical, dental, vision, life insurance, short-term disability, long-term disability, flexible spending accounts, education assistance, and training and development. Applications are accepted on a rolling basis.

    Minimum Rate

    $100,000 Annually

    Maximum Rate

    $227,500 Annually

    serp_jobs.job_alerts.create_a_job

    Vulnerability Analyst • Laurel, MD, United States

    Job_description.internal_linking.related_jobs
    Exploitation Analyst

    Exploitation Analyst

    Prime Time Consulting, L.L.CFort Meade, Maryland, United States, 20755
    serp_jobs.job_card.full_time
    Prime Time Consulting provides clients with expert intelligence analysis services.Our clients include defense contractors, industrial and service corporations, and departments and agencies of the U...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Project Analyst

    Project Analyst

    LeidosFairfax Station, VA, US
    serp_jobs.job_card.full_time
    Project Analyst – National Security Program | Reston, VA.Support a Mission That Matters.In this role, you’ll support a high-impact program that directly contributes to our customer&rsqu...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    Vulnerability Management

    Vulnerability Management

    Innova SolutionsManassas, VA,Virginia,United States
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    A client of Innova Solutions is immediately hiring for a.As Vulnerability Management you will be.Defining and implementing vulnerability management and patching policies for on-premises infrastruct...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Travel Board Certified Behavioral Analyst (BCBA) - School in Frederick, MD

    Travel Board Certified Behavioral Analyst (BCBA) - School in Frederick, MD

    AlliedTravelCareersFrederick, MD, US
    serp_jobs.job_card.full_time
    AlliedTravelCareers is working with Aequor to find a qualified BCBA - School in Frederick, Maryland, 21701!.Aequor is now hiring a full-time Board Certified Behavior Analyst (BCBA) for the 2023-202...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Travel Board Certified Behavioral Analyst (BCBA) - School in Salisbury, MD

    Travel Board Certified Behavioral Analyst (BCBA) - School in Salisbury, MD

    AlliedTravelCareersGermantown, Maryland, US
    serp_jobs.job_card.full_time
    AlliedTravelCareers is working with Aequor to find a qualified BCBA - School in Salisbury, Maryland, 21801!.Aequor is now hiring a full-time Board Certified Behavior Analyst (BCBA) for the 2023-202...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    Vulnerability Researcher : All Levels (Applicants must already hold a TS clearance or higher)

    Vulnerability Researcher : All Levels (Applicants must already hold a TS clearance or higher)

    Cipher Tech SolutionsVienna, VA, USA
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    The candidate will be working independently as a Vulnerability Researcher to identify flaws in software.The candidate must be familiar with the latest techniques in vulnerability research and demon...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    Cybersecurity Vulnerability Analyst

    Cybersecurity Vulnerability Analyst

    Node.DigitalArlington, VA, US
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Cybersecurity Vulnerability Analyst.Must have an active Top Secret Security Clearance.Government customer to provide cybersecurity vulnerability analysis support to reduce the prevalence and impact...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Vulnerability Researcher / Exploit Developer

    Vulnerability Researcher / Exploit Developer

    REDLattice, Inc.Maryland, MD, United States
    serp_jobs.job_card.full_time
    Vulnerability Researcher / Exploit Developer.At REDLattice, we are a global leader in providing differentiated cyber products and services. As we continue to evolve in a rapidly changing cyber lands...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Insider Threat Program Investigative Team Analyst

    Insider Threat Program Investigative Team Analyst

    LeidosUpper Marlboro, MD, US
    serp_jobs.job_card.full_time
    The Digital Modernization Sector at Leidos currently has an opening for a UAM Investigative Team Analyst supporting the HEITS Contract as part of the Department of Homeland Security (DHS) Insider T...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Equipment Certification Specialist I (#1874)

    Equipment Certification Specialist I (#1874)

    BNBIFort Detrick, MD, United States
    serp_jobs.job_card.temporary
    The National Biodefense Analysis and Countermeasures Center (NBACC) is a one-of-a-kind facility located on Fort Detrick in Frederick MD and is dedicated to defending the nation against biological t...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Maritime Surveillance LFA / CLFA System Design and Operations Analyst

    Maritime Surveillance LFA / CLFA System Design and Operations Analyst

    The Johns Hopkins University Applied Physics LaboratoryLaurel, MD, United States
    serp_jobs.job_card.temporary
    Are you looking to be on the cutting edge of new and innovative ways to deploy active sonar capabilities within the Maritime Surveillance domain?. Are you passionate about working with groundbreakin...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Customs and Border Protection Officer

    Customs and Border Protection Officer

    U.S. Customs and Border ProtectionPrince Frederick, Maryland, US
    serp_jobs.job_card.full_time +1
    Customs and Border Protection (CBP) offers those interested in a career in law enforcement an exceptional opportunity to work with an elite team of highly trained professionals whose camaraderie, p...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Travel Board Certified Behavioral Analyst (BCBA) - School in Baltimore, MD

    Travel Board Certified Behavioral Analyst (BCBA) - School in Baltimore, MD

    AlliedTravelCareersColumbia, Maryland, US
    serp_jobs.job_card.full_time
    AlliedTravelCareers is working with Aequor to find a qualified BCBA - School in Baltimore, Maryland, 21201!.Aequor is now hiring a full-time Board Certified Behavior Analyst (BCBA) for the 2023-202...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Senior Security Engineer

    Senior Security Engineer

    Legal & General AmericaFrederick, MD, United States
    serp_jobs.job_card.full_time
    At Legal & General America, we aim to make a positive difference in the lives of our customers, partners, colleagues, and the communities in which they live. As a recognized market leader of term li...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Travel CT Tech - $3,467 per week in Lutherville Timonium, MD

    Travel CT Tech - $3,467 per week in Lutherville Timonium, MD

    AlliedTravelCareersGermantown, Maryland, US
    serp_jobs.job_card.full_time
    AlliedTravelCareers is working with Medical Solutions to find a qualified CT Tech in Lutherville Timonium, Maryland, 21093!. A facility in Lutherville Timonium, MD is seeking its next amazing CT Tec...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Travel Board Certified Behavioral Analyst (BCBA) - School in Bowie, MD

    Travel Board Certified Behavioral Analyst (BCBA) - School in Bowie, MD

    AlliedTravelCareersColumbia, Maryland, US
    serp_jobs.job_card.full_time
    AlliedTravelCareers is working with Aequor to find a qualified BCBA - School in Bowie, Maryland, 20715!.Aequor is now hiring a full-time Board Certified Behavior Analyst (BCBA) for the 2023-2024 sc...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    BSA QC Specialist (Hybrid) (Richmond, VA / Reston, VA / Columbia, MD)

    BSA QC Specialist (Hybrid) (Richmond, VA / Reston, VA / Columbia, MD)

    Atlantic Union BankColumbia, MD, United States
    serp_jobs.job_card.full_time
    The BSA Quality Control Specialist is responsible for day-to-day oversight of the department's quality control program, including periodic risk-based sample quality reviews of work produced by AML ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    Cyber Analyst - Vulnerability Manager

    Cyber Analyst - Vulnerability Manager

    ConnsciGaithersburg, MD, USA
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Vulnerability & Compliance Testing : .Conduct authenticated vulnerability scans and compliance evaluations across networks, systems, endpoints, and cloud platforms. Evaluate system, network, and i...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days