Cybersecurity Analyst (Vulnerability Management & Continuous Monitoring)
$120,000–$120,000 year
On-siteOakton, Virginia, United States
Job Summary
Execute vulnerability scanning using ACAS (Tenable.sc/Nessus) and analyze results to identify misconfigurations and compliance gaps against DISA STIGs. Validate findings, correlate with IAVA/IAVM notices, and develop Plan of Action and Milestones (POA&M) documentation for DoD risk management. Conduct manual and automated STIG compliance checks across operating systems, maintain golden images for RHEL and Windows, and support system hardening efforts. Monitor security controls for Continuous Monitoring (ConMon) effectiveness, assess RMF artifacts including SSP and SAR, and generate risk-based reports for leadership and Authorizing Officials.
Required Qualifications
- High school diploma or GED equivalent
- 5+ years of experience in DoD cybersecurity or RMF-based environments
- Hands-on experience with ACAS (Nessus / Tenable.sc)
- STIG implementation and validation
- IAVA/IAVM processes
- Experience with vulnerability assessment, risk analysis, and remediation tracking
- DoD 8570/8140 Compliance: Must meet IAT Level II requirements (e.g., Security+)
- Active DoD Top Secret clearance with SCI eligibility
- Strong understanding of DoD RMF (DoDI 8510.01)
- Strong understanding of NIST SP 800-53 security controls
- Ability to manage multiple systems and priorities in a regulated environment
- Strong analytical and problem-solving skills
- Attention to detail and compliance rigor
- Ability to translate technical risk into mission impact
- Effective communication with technical and non-technical stakeholders
- Certified Information Systems Security Professional (CISSP)
- Certified Ethical Hacker (CEH) or equivalent
- DISA ACAS Training Certificate
- Experience with SCAP Compliance Checker (SCC) / Evaluate-STIG
- Experience with STIG Viewer
- Experience with eMASS, Xacta
- Experience with Trellix, MDE
- Experience with Splunk, Elastic
- Familiarity with scripting (e.g., PowerShell, Python) for automation
- Experience in enterprise-level ConMon programs or NOSC/SOC environments
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.