Quick Overview
Job Description
Vulnerability Management Analyst
Location: Richmond, VA
Work Arrangement: Hybrid – 2–3 days onsite per week
Employment Type: Contract
Position Overview
We are looking for an experienced Vulnerability Management Analyst to support enterprise vulnerability assessment, security scanning, compliance, and risk analysis activities.
The selected candidate will perform vulnerability assessments across operating systems, databases, web applications, cloud environments, and enterprise infrastructure. The role will also support vulnerability remediation, scanning operations, compliance activities, automation, and integration of vulnerability assessment data with third-party security tools.
Key Responsibilities
- Perform vulnerability assessments and security scans across operating systems, databases, web applications, cloud environments, and enterprise infrastructure.
- Support Information System Vulnerability Management (ISVM) scans and compliance activities.
- Analyze identified vulnerabilities and assist with remediation recommendations and risk analysis.
- Manage and support software vulnerability management activities.
- Troubleshoot vulnerability scanning tools, scan configurations, consoles, and related issues.
- Support automated and scheduled vulnerability scanning activities, including planning, execution, monitoring, and reporting.
- Perform ad hoc and emergency vulnerability scans to support incident investigation and response.
- Create and maintain vulnerability scan reports, data feeds, scan policies, repositories, and assessment-tool user access/roles.
- Support cloud compliance scans and security assessment activities.
- Support API discovery and security scanning.
- Assist with integration of vulnerability assessment data into third-party security tools.
- Support maintenance and configuration of vulnerability scanning tools and platforms.
- Collaborate with the SCC Security Operations team on vulnerability management, tool operations, testing, and security assessment activities.
- Identify opportunities to improve enterprise visibility into security weaknesses, vulnerabilities, and cyber risks.
- Prepare documentation, reports, and analysis for security and compliance stakeholders.
Required Qualifications
- 5+ years of Information Security experience
- 3+ years of Software Vulnerability Management experience
- 3+ years of experience supporting ISVM scans and compliance activities
- 3+ years of experience troubleshooting vulnerability scanning tools and scan configurations
- 3+ years of experience with automation supporting vulnerability assessment operations
- 3+ years of experience with API discovery and security scanning
- 5+ years of experience with Microsoft technologies, SharePoint, and Power BI
- Strong analytical and problem-solving skills
- Excellent verbal and written communication skills
- Ability to work independently with minimal direction and effectively collaborate with a team
- Highly motivated, self-directed, and detail-oriented
Important Requirement
Candidates must have demonstrable experience with:
Information System Vulnerability Management (ISVM) scans and compliance activities
Software Vulnerability Management
Please clearly highlight these experiences on your resume.
Work Location
Richmond, VA – Hybrid
The position requires the selected contractor to work onsite 2–3 days per week. Local Richmond-area candidates will be given preference.
Similar jobs
- JM
AI Tech Risk & Controls Lead
NewJ.P. Morgan
Palo Alto, California🇺🇸On-site9 minutes agoRisk ManagementFinance - AT
Security Engineer
NewAivanta Tech Inc
Seattle, WA🇺🇸Hybrid17 hours agoMicroservicesBashLLM+2Technology - SO
Senior Vulnerability Management Analyst
NewSystem One
Birmingham, Alabama🇺🇸Hybrid32 minutes agoAWSComplianceMicrosoft Excel+2Technology - AO
Cybersecurity Lead
NewAmerican Operations Corporation
Montgomery, Alabama🇺🇸Hybrid35 minutes agoAgileZero TrustTechnology - VE
Security Software Engineer, IAM
NewAuto ApplyVercel
Remote - United States🇺🇸$208k - $312k/yrRemote10 hours agoGCPNode.jsAWS+9Technology - TN
Senior Engineer, Cybersecurity
NewAuto ApplyThe New York Times
New York🇺🇸Hybrid1 hour agoGCPPackerAWS+7Technology - ST
Security Analyst
NewAuto ApplyStripe
US Remote🇺🇸Remote3 hours agoGCPSQLAWS+5Technology - VC
IT Security Specialist Threat & Intrusion Detection
NewVST Consulting, Inc
Addison, TX🇺🇸$80/hrOn-site17 hours agoSplunkActive DirectoryApacheTechnology - ZT
Security Analyst - Entry
NewZolon Tech Solutions Inc
Blythewood, SC🇺🇸On-site17 hours agoPowerShellTechnology - SY
Penetration Engineer only w2
NewSymphony Corporation
Dallas, TX🇺🇸Hybrid17 hours agoEngineering - MC
Security Engineer (Product & Business Enablement)
NewAuto ApplyMariner Careers
United States🇺🇸Remote8 hours agoEncryptionLESSOnboarding+1Technology - LA
Staff Security Architect
NewAuto ApplyLambda
Bellevue Office🇺🇸Hybrid1 hour agoEncryptionMachine LearningSOC 2+7Technology