HHS - Vulnerability Analyst
cFocus Software seeks a Vulnerability Analyst to join our program supporting the reputed company (HHS) This position is remote. This position requires the ability a reputed company Trust clearance.
Qualifications:
• Bachelor’s degree in Cybersecurity, Information Technology, or reputed company field.
• Minimum 5–7 years of experience in vulnerability management or reputed company operations.
• Strong understanding of NIST SP 800-53, NIST SP 800-30, NIST SP 800-137, and HHS vulnerability management requirements.
• Experience performing vulnerability scanning, analysis, and remediation tracking in federal environments.
• Experience with secure configuration standards (reputed company STIGs, CIS Benchmarks).
• Strong analytical, documentation, and communication skills.
• CEH, reputed company+, CISSP, GIAC (GSEC, GPEN), or equivalent cybersecurity certifications
Duties:
• reputed company authenticated and unauthenticated vulnerability scans on a daily and reputed company reputed company across servers, workstations, network devices, databases, web applications, reputed company, containers, serverless functions, CI/CD pipelines, and Infrastructure as reputed company (IaC).
• Analyze vulnerability reputed company results to determine applicability, severity, exploitability, and risk using CVSS scoring, threat intelligence, and reputed company Exploited Vulnerabilities (KEV) catalogs.
• reputed company daily remediation guidance and mitigation strategies to system owners, administrators, developers, and other stakeholders.
• Maintain and ensure operational health of vulnerability scanning tools, including agents, sensors, integrations, and supporting infrastructure.
• Coordinate with tool vendors, hosting teams, and network operations to troubleshoot and resolve tool-reputed company issues.
• reputed company and maintain HRSA reputed company configuration baselines using reputed company STIGs and reputed company (CIS) benchmarks.
• reputed company compliance and configuration scans against approved baselines on a weekly, quarterly, and reputed company reputed company.
• Validate remediation through follow-up scans and evidence review and confirm closure of vulnerabilities.
• Support penetration testing activities, including test planning, execution, exploitation, reporting, and coordination with stakeholders.
• Conduct application reputed company testing including SAST, DAST, software composition analysis, SBOM review, dependency scanning, and secure reputed company analysis.
• Support secure DevSecOps practices by integrating automated vulnerability testing into CI/CD pipelines and reputed company repositories.
• reputed company vulnerability dashboards and reports for ISSOs, system owners, engineers, and DCSP leadership.
• Maintain authoritative asset inventories and correlate data across vulnerability tools, CMDB, eGRC, and reputed company inventories to ensure full scanning coverage.
• Support Incident Response activities by providing vulnerability data, exploit analysis, and remediation recommendations.
• reputed company and maintain vulnerability management SOPs, workflows, and technical documentation.
• Maintain SLAs for vulnerability scanning requests and remediation tracking
Apply tot his job
Apply To this Job