Hiring.Camp

Vulnerability Management Analyst

Crfamilyofcompanies

·

Today

Location
Remote
Workplace
Remote
Department
Copper River Cyber Solutions
Experience
5+ years
Education
Bachelor
Source
Greenhouse

Description

Copper River Cyber Solutions is seeking a highly motivated The Vulnerability Management Analyst to support the NIH cybersecurity program by identifying, analyzing, tracking, and reporting security vulnerabilities across enterprise systems, applications, databases, cloud environments, and network infrastructure. The Analyst collaborates with system owners, security engineers, RMF personnel, and operational teams to ensure vulnerabilities are properly assessed, prioritized, remediated, and verified in accordance with NIH, HHS, and Federal cybersecurity requirements.

The position plays a key role in maintaining a strong security posture through continuous monitoring, risk analysis, remediation tracking, and compliance reporting.

Responsibilities (include but are not limited to):

  • Perform vulnerability assessments and analysis across NIH information systems and infrastructure.
  • Perform threat-informed prioritization using exploitability, threat intelligence, CISA Known Exploited Vulnerabilities (KEV), mission criticality, system exposure, and compensating controls.
  • Assess vulnerability risk within the context of system criticality, data sensitivity, and organizational risk tolerance.
  • Develop vulnerability dashboards, remediation metrics, trend analyses, and executive reporting products.
  • Review and analyze vulnerability scan results from enterprise security tools.
  • Validate findings to determine severity, exploitability, and potential impact.
  • Conduct risk-based prioritization of vulnerabilities and security weaknesses.
  • Coordinate with technical teams to assess remediation requirements and timelines.
  • Manage the full lifecycle of vulnerability identification, remediation, and closure.
  • Track vulnerabilities from discovery through remediation and validation.
  • Maintain vulnerability repositories, remediation records, and status reporting.
  • Monitor remediation progress and escalate overdue findings as appropriate.
  • Verify corrective actions and document closure activities.
  • Support continuous monitoring activities across NIH systems and applications.
  • Analyze vulnerability trends and identify recurring issues.
  • Evaluate security risks associated with discovered vulnerabilities.
  • Collaborate with RMF/A&A teams to support Authorization to Operate (ATO) activities.
  • Assist with the management and tracking of Plans of Action and Milestones (POA&Ms).
  • Provide vulnerability-related evidence and documentation for audits, assessments, and authorization activities.

Essential Job Qualifications and Requirements:

Education:

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field

Required Qualifications:

  • Minimum 5 years of experience in cybersecurity, vulnerability management, information assurance, or security operations supporting Federal environments.
  • Experience supporting POA&M development, remediation tracking, corrective action validation, or vulnerability closure activities.
  • Experience conducting vulnerability assessments and remediation tracking.
  • Familiarity with:
    • NIST RMF (SP 800-37)
    • NIST SP 800-53 Rev. 5
    • FISMA
    • Federal cybersecurity compliance requirements
    • Risk assessment methodologies
  • Experience analyzing vulnerability data and developing remediation recommendations.
  • Strong analytical, problem-solving, and communication skills.
  • Ability to obtain and maintain an NIH Public Trust.

Preferred Qualifications:

  • One or more of the following certifications:
    • Security+
    • Certified Ethical Hacker (CEH)
    • CISSP
    • GIAC Vulnerability Assessment (GVA)
    • GIAC Information Security Fundamentals (GISF)
    • GSEC
    • CAP (Certified Authorization Professional)
    • CISM
    • CRISC
  • Experience supporting NIH, HHS, or other Federal civilian agencies.
  • Experience working within FISMA-compliant environments.
  • Knowledge of cloud security and vulnerability management practices.
  • Experience supporting continuous diagnostics and mitigation (CDM) initiatives.
  • Understanding of FedRAMP and Zero Trust security principles.
  • Experience coordinating remediation activities across multiple stakeholders.
Position Pay Range
$125,000$131,000 USD

About Copper River & The Native Village of Eyak:

Owned by the Native Village of Eyak (NVE), a federally recognized Alaska Native Tribe, the Copper River Family of Companies are a collection of entities that deliver a complementary set of solutions and services to support the diverse missions and requirements of our clients. Proud participants of the Small Business Administration’s (SBA) 8(a) Business Development Program since 2006, our companies consist of both current and graduation SBA 8(a) entities. It is our collective purpose to support the Tribe and diversify the NVE’s ability to facilitate economic advancement.

The income generated from our companies helps the Native Village of Eyak fund health and social services, economic development, natural resource/environmental education, jobs, job training, and other benefits to the NVE in a manner that is consistent with Alaskan Native cultural values and traditions.

Copper River’s Culture

The Copper River Family of Companies has a positive, supportive, and thriving culture. At the foundation of our culture is a focus on collaboration. No matter your role or which operating company you work for, we are ONE TEAM working toward the same goals for our customers and for our collective owner- The Native Village of Eyak. How we treat each other is just as important as the work we deliver.

Benefits

  • Comprehensive medical, dental, and vision coverage
  • Flexible Spending Account - healthcare and dependent care
  • Health Savings Account - high deductible medical plan
  • Retirement 401(k) with employer match
  • Open leave policy and paid holidays
  • Additional benefits including tuition reimbursement, transportation expense account, employee assistance program, and more! 

Note: Benefits are offered based on employment classification and applicable contract requirements. Eligibility may vary by position.

Disclaimer:

The Copper River Family of Companies provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws.

Skills

CybersecurityComplianceCISSP

Similar Jobs

27

Vulnerability Management Analyst

LON3 London - 51 Lime Street · Taguig, National Capital, Philippines

1 month ago

Vulnerability Management Analyst

Hapag-Lloyd · Chennai, India · Hybrid

7 months ago

Vulnerability Management Analyst

Decisionpointcorp · , US · Remote

1+ year ago

Information Security Analyst, Vulnerability Management

bet365 · Manchester, England, United Kingdom · Hybrid

Today

Information Security Analyst, Vulnerability Management

bet365 · Stoke-on-Trent, England, United Kingdom · Hybrid

Today

Cyber Security Analyst & Vulnerability Management Engineer

Loenbro · Westminster, CO

Today

Information Security Analyst (Vulnerability Management)

Jda · BYDS Dallas, United States of America · Remote, Hybrid, Onsite

Yesterday

Sr. Analyst Vulnerability Management

Mattel · Hyderabad, India

2 days ago

Vulnerability Management Security Analyst

University of Notre Dame · Notre Dame, IN, United States

6 days ago

Lead Cyber Security Analyst - Vulnerability Management

Scottish Government Recruitment · Glasgow, United Kingdom, GB · Hybrid

6 days ago

Vulnerability Management I Analyst II

Vertiv · Mandaluyong City, Philippines

1 week ago

DFC - Vulnerability Management Analyst

cFocus Software Incorporated · Washington, DC · Remote

2 weeks ago

Senior Cybersecurity Analyst – Vulnerability Management

Digital Realty Global · LONDON, United Kingdom, GB · Onsite

4 weeks ago

Vulnerability Management & Offensive Security Analyst

Gulf Coast Automation Group · Chicago

1 month ago

Threat Intelligence & Vulnerability Management Analyst

Duplo · Lagos, Lagos, Nigeria

1 month ago

Vulnerability Management Analyst 2

Us Nyu · New York, NY, US

1 month ago

Vulnerability Management Analyst 2

New York University · New York, NY, US

1 month ago

Threat and Vulnerability Management Analyst

Centrica · UK - Windsor - Millstream, United Kingdom +1 · Hybrid

2 months ago

Senior Vulnerability Management Analyst

Advisorgroup · Scottsdale, AZ, United States of America · Hybrid

2 months ago

Vulnerability and Cybersecurity Operations Management Analyst

Lam Research · Bengaluru, KA,IN, IN

3 months ago

Vulnerability Management Analyst & Automation specialist

Euroclear · Poland, PL

3 months ago

Mustang: Senior Analyst Vulnerability Management

Continental · Bengaluru, KA, India

9 months ago

Mustang: Senior Analyst Vulnerability Management

Continental · Bengaluru, KA, India

10 months ago

IS Analyst- Vulnerability Management

Milliman · Gurgaon, India

1+ year ago

Cloud Vulnerability Management Analyst

Rockwell Automation · Mexico Mexico City (remote) +3 · Hybrid

1+ year ago

Cloud Vulnerability Management Analyst

Rockwellautomation · Mexico Mexico City (remote) +3 · Hybrid

1+ year ago

Security Vulnerability Management Analyst

Qmulos · Washington, DC, United States

1+ year ago