Cyber Vulnerability Management Analyst at General Dynamics Information Technology
, , United States -
Full Time


Start Date

Immediate

Expiry Date

09 May, 26

Salary

166750.0

Posted On

08 Feb, 26

Experience

5 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Computer Security Exploits, Cybersecurity, Security Operations, Security Practices, System Security, Cyber Data Analytics, Vulnerability Management, Risk Management, Networking Concepts, Vulnerability Scanning Tools, Remediation Guidance, Technical Risk Communication, Collaboration, Dashboard Development, Reporting, Mentoring

Industry

IT Services and IT Consulting

Description
Type of Requisition: Regular Clearance Level Must Currently Possess: None Clearance Level Must Be Able to Obtain: None Public Trust/Other Required: MBI (T2) Job Family: Cyber and IT Risk Management Job Qualifications: Skills: Computer Security Exploits, Cybersecurity, Security Operations, Security Practices, System Security Certifications: None Experience: 4 + years of related experience US Citizenship Required: No Job Description: Seize your opportunity to make a personal impact as a Cyber Vulnerability Management Analyst to support a federal customer’s enterprise cybersecurity program. The analyst will play a critical role in operating and enhancing the Vulnerability Management (VM) lifecycle by analysing vulnerability scan data, validating findings, prioritizing risk, and coordinating remediation activities across complex enterprise environments. This position requires hands-on experience with enterprise vulnerability scanning tools, strong cyber data analytics skills, and the ability to communicate technical risk clearly to system owners, engineers, and cybersecurity leadership. *Candidates must be able to travel to customer location to obtain badging and fingerprinting prior to starting* *Candidate must have resided in the US in the past 3 of 5 years* Responsibilities: Analyze raw vulnerability scan results and provide clear, actionable findings to system owners and stakeholders Validate vulnerabilities, identify false positives, and confirm technical risk and exploitability Provide practical remediation guidance aligned with system architecture and operational constraints Track vulnerability remediation status and support risk-based prioritization Works closely with the risk management and other teams to determine system risks based upon vulnerability results and ensure compensating and/or mitigating controls are in place. Operate and support vulnerability scanning tools across multiple platforms, including Tenable Security Center, Tenable.io, Nessus Manager, Nessus Network Monitor, NetSparker/Invicti Enterprise, CodeDX, Coverty, Black Duck, Seeker, and Guardium Database Scanner. Has a Solid understanding of networking concepts, including TCP/IP, DNS, DHCP, VPN, and firewalls from a security perspective. Develop and adhere to Standard Operating Procedures (SOP). Comfortable with interfacing the customer, cross-functional teams and application owners on vulnerability metrics and findings. Adhere to Service Level Agreements (SLA) for service request support. Mentor and train team members & program successors. Participates in special projects, as needed. Works with Program and Project management throughout the period of performance. Supports technical problems that occur and on-call support for non-business hours. Provide Weekly and on-demand Status Reports on work performed. Required Skills: 4+ years of cybersecurity experience, with a strong focus on vulnerability management and security operations 3+ years Hands-on experience with enterprise vulnerability scanning tools (Tenable, Nessus, Invicti, etc.) Strong cyber data analytics skills and experience developing dashboards and reports Knowledge of current vulnerability trends, exploits, and threat intelligence Experience working in a federal IT or regulated environment Ability to manage multiple priorities and work independently with minimal supervision Strong collaboration and teamwork skills Strong cyber data analytics skills and experience developing dashboards and reports (Excel, Pivot Tables, charts, graphs, Power BI or other tools) Must be able to obtain a Public Trust and successfully pass a thorough government background screening process (forms/fingerprinting). Desired Skills: Preference to candidates local to the DMV Area. Experience with MS Office suite (Word, Excel, PP, Visio, SharePoint, etc.) Experience with NIST, FISMA, and federal cybersecurity policy requirements. Experience with any HHS agencies or entities (CMS, HRSA, NIH, etc.) Demonstrated strong technical skills and analytic abilities, as well as experience performing system security analysis and risk management. Demonstrated experience performing complex technical tasks with minimal direction. Possesses experience with communicating potentials risks to stakeholders. Possess a broad knowledge of security best practices, policies and guidance. The likely salary range for this position is $123,250 - $166,750. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range. Scheduled Weekly Hours: 40 Travel Required: Less than 10% Telecommuting Options: Remote Work Location: Any Location / Remote Additional Work Locations: Total Rewards at GDIT: Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. GDIT typically provides new employees with 15 days of paid leave per calendar year to be used for vacations, personal business, and illness and an additional 10 paid holidays per year. Paid leave and paid holidays are prorated based on the employee’s date of hire. The GDIT Paid Family Leave program provides a total of up to 160 hours of paid leave in a rolling 12 month period for eligible employees. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most. We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology. Join our Talent Community to stay up to date on our career opportunities and events at gdit.com/tc. Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans Join our 30,000 everyday heroes. We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 30 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology. For more information about GDIT's Privacy Policy, click here: https://www.gdit.com/privacy-policy/notices/
Responsibilities
The Cyber Vulnerability Management Analyst will analyze vulnerability scan results and provide actionable findings to system owners. They will validate vulnerabilities, track remediation status, and support risk-based prioritization.
Loading...