Chenega logo
ChenegaPosted 25 months ago

Cybersecurity Analyst (Vulnerability Management & Continuous Monitoring)

$120,000–$120,000 year

On-siteOakton, Virginia, United States

Full TimeLarge

Job Summary

Execute vulnerability scanning using ACAS (Tenable.sc/Nessus) and analyze results to identify misconfigurations and compliance gaps against DISA STIGs. Validate findings, correlate with IAVA/IAVM notices, and develop Plan of Action and Milestones (POA&M) documentation for DoD risk management. Conduct manual and automated STIG compliance checks across operating systems, maintain golden images for RHEL and Windows, and support system hardening efforts. Monitor security controls for Continuous Monitoring (ConMon) effectiveness, assess RMF artifacts including SSP and SAR, and generate risk-based reports for leadership and Authorizing Officials.

Required Qualifications

  • High school diploma or GED equivalent
  • 5+ years of experience in DoD cybersecurity or RMF-based environments
  • Hands-on experience with ACAS (Nessus / Tenable.sc)
  • STIG implementation and validation
  • IAVA/IAVM processes
  • Experience with vulnerability assessment, risk analysis, and remediation tracking
  • DoD 8570/8140 Compliance: Must meet IAT Level II requirements (e.g., Security+)
  • Active DoD Top Secret clearance with SCI eligibility
  • Strong understanding of DoD RMF (DoDI 8510.01)
  • Strong understanding of NIST SP 800-53 security controls
  • Ability to manage multiple systems and priorities in a regulated environment
  • Strong analytical and problem-solving skills
  • Attention to detail and compliance rigor
  • Ability to translate technical risk into mission impact
  • Effective communication with technical and non-technical stakeholders
  • Certified Information Systems Security Professional (CISSP)
  • Certified Ethical Hacker (CEH) or equivalent
  • DISA ACAS Training Certificate
  • Experience with SCAP Compliance Checker (SCC) / Evaluate-STIG
  • Experience with STIG Viewer
  • Experience with eMASS, Xacta
  • Experience with Trellix, MDE
  • Experience with Splunk, Elastic
  • Familiarity with scripting (e.g., PowerShell, Python) for automation
  • Experience in enterprise-level ConMon programs or NOSC/SOC environments

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce