Jobedly Post a Job

Vulnerability Management Analyst

The Copper River Family of Companies · Remote
RemoteFull-timeCopper River Cyber SolutionsTechnology$111,000–$150,000/yr
Apply on Jobedly ⚡ One-click AI Apply

About the Vulnerability Management Analyst role

Vulnerability Management Analyst positions focus on delivering results in their domain. This page aggregates open Vulnerability Management Analyst roles and what employers typically expect.

Copper River Cyber Solutions is seeking a highly motivated The Vulnerability Management Analyst to support the NIH cybersecurity program by identifying, analyzing, tracking, and reporting security vulnerabilities across enterprise systems, applications, databases, cloud environments, and network infrastructure. The Analyst collaborates with system owners, security engineers, RMF personnel, and operational teams to ensure vulnerabilities are properly assessed, prioritized, remediated, and verified in accordance with NIH, HHS, and Federal cybersecurity requirements. The position plays a key role in maintaining a strong security posture through continuous monitoring, risk analysis, remediation tracking, and compliance reporting. Responsibilities (include but are not limited to): Perform vulnerability assessments and analysis across NIH information systems and infrastructure. Perform threat-informed prioritization using exploitability, threat intelligence, CISA Known Exploited Vulnerabilities (KEV), mission criticality, system exposure, and compensating controls. Assess vulnerability risk within the context of system criticality, data sensitivity, and organizational risk tolerance. Develop vulnerability dashboards, remediation metrics, trend analyses, and executive reporting products. Review and analyze vulnerability scan results from enterprise security tools. Validate findings to determine severity, exploitability, and potential impact. Conduct risk-based prioritization of vulnerabilities and security weaknesses. Coordinate with technical teams to assess remediation requirements and timelines. Manage the full lifecycle of vulnerability identification, remediation, and closure. Track vulnerabilities from discovery through remediation and validation. Maintain vulnerability repositories, remediation records, and status reporting. Monitor remediation progress and escalate overdue findings as appropriate. Verify corrective actions and document closure activities. Support continuous monitoring activities across NIH systems and applications. Analyze vulnerability trends and identify recurring issues. Evaluate security risks associated with discovered vulnerabilities. Collaborate with RMF/A&A teams to support Authorization to Operate (ATO) activities. Assist with the management and tracking of Plans of Action and Milestones (POA&Ms). Provide vulnerability-related evidence and documentation for audits, assessments, and authorization activities. Essential Job Qualifications and Requirements: Education: Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field Required Qualifications: Minimum 5 years of experience in cybersecurity, vulnerability management, information assurance, or security operations supporting Federal environments. Experience supporting POA&M development, remediation tracking, corrective action validation, or vulnerability closure activities. Experience conducting vulnerability assessments and remediation tracking. Familiarity with: NIST RMF (SP 800-37) NIST SP 800-53 Rev. 5 FISMA Federal cybersecurity compliance requirements Risk assessment methodologies Experience analyzing vulnerability data and developing remediation recommendations. Strong analytical, problem-solving, and communication skills. Ability to obtain and maintain an NIH Public Trust. Preferred Qualifications: One or more of the following certifications: Security+ Certified Ethical Hacker (CEH) CISSP GIAC Vulnerability Assessment (GVA) GIAC Information Security Fundamentals (GISF) GSEC CAP (Certified Authorization Professional) CISM CRISC Experience supporting NIH, HHS, or other Federal civilian agencies. Experience working within FISMA-compliant environments. Knowledge of cloud security and vulnerability management practices. Experience supporting continuous diagnostics and mitigation (CDM) initiatives. Understanding of FedRAMP and Zero Trust security principles. Experience coordinating remediation act…

Salary estimate

$111,000 – $150,000/yr
Provided by the employer.

Skills for this role

CommunicationSecurity

Resume tips for Vulnerability Management Analyst applicants

Interview preparation

Prepare concrete STAR-format stories that show Vulnerability Management Analyst outcomes you drove.

Research the employer's product and recent news before the interview.

Be ready to explain how you'd approach a typical Vulnerability Management Analyst problem end to end.

Have thoughtful questions ready about the team, tools and success metrics.

About The Copper River Family of Companies

The Copper River Family of Companies is actively hiring on Jobedly. Explore their open roles and what it's like to work there.

Apply on Jobedly ⚡ One-click AI Apply

Similar jobs

Companies hiring for similar roles