Job Requirements
Ashburn, VA
Secret Polygraph Unspecified
Mid Level Career (5+ yrs experience)
$100,000 - $140,000
Job Description
Vulnerability Assessment Analyst
Summary:
The Vulnerability Assessment Analyst Junior conducts technical vulnerability and configuration-compliance assessments of CBP systems, applications, databases, and network infrastructure. The role executes approved scans, validates findings, prepares assessment results, supports remediation, and maintains accurate assessment records. One source row listed a 5+ year minimum for the same Junior title; this description preserves the standard 3+ year profile while noting that specific requisitions may apply the higher threshold.
Location:
- Primary duty location: Government site in the Washington, DC metropolitan area, primarily Ashburn, VA.
- Telework may be approved, but should not be the expectation.
- Travel to CBP locations may be required based on assigned work; role-specific travel expectations are identified below
Qualifications:
- Vulnerability assessment, penetration testing, cybersecurity operations, system administration, network engineering, or related experience; specific requisitions may require 5+ years
- Experience using automated vulnerability scanning tools and manual validation techniques across systems, applications, databases, and network infrastructure
- Knowledge of vulnerability prioritization, SCAP-compatible tools, configuration compliance, STIG checks, ISVMs, FISMA continuous monitoring, and POA&M support
- Ability to analyze scan results, distinguish valid findings, document risk and impact, and recommend practical remediation
- Security+ required; CySA+, CEH, GIAC, CISSP, or vendor-specific vulnerability management certification preferred
- Strong technical writing and stakeholder briefing skills; U.S. citizenship and ability to obtain and maintain the required investigation or clearance
Duties and Responsibilities:
- Create, schedule, execute, and monitor vulnerability and configuration-compliance scans in accordance with approved standards and master schedules
- Review and validate scan results, investigate anomalous findings, and develop clear vulnerability reports and remediation recommendations
- Coordinate scanning and testing with system owners, ISSOs, ISSMs, Government leads, network operations, and other stakeholders
- Maintain scan policies, zones, repositories, asset inventories, application issue repositories, assessment records, and knowledge-base content
- Support ad hoc or emergency scans, incident investigations, audits, ISVM enumeration, DHS scorecard analysis, and data calls
- Track remediation progress, conduct follow-on assessments, identify trends, and brief stakeholders on risk, impact, and recommended actions
- Support specialized assessments, tool evaluations, SOP development, and integration of reports or data feeds with approved third-party tools
- Travel to CBP facilities to perform on-site assessments when directed
Decision-Making Authority:
The Vulnerability Assessment Analyst Junior may execute approved assessment procedures, validate routine findings, maintain assessment records, and recommend remediation or escalation. Changes to assessment scope, rules, production configurations, or formal risk disposition require senior and Government approval.
Salary Range
$100,000 - $140,000
group id: 10364120