DFC - Vulnerability Management Analyst

Posted 6 Days Ago
Be an Early Applicant
Washington, DC, USA
In-Office
Senior level
Software
The Role
Provide vulnerability management for DFC: run and validate authenticated scans, assess severity using CVSS and threat intel, manage POA&Ms in CSAM, reconcile ServiceNow tickets, coordinate remediation, handle CISA KEV and emergency vulnerabilities, prepare exception/risk-acceptance packages, and communicate risk to federal stakeholders.
Summary Generated by Built In
cFocus Software seeks a Vulnerability Management Analyst to join our program supporting the United States International Defense Finance Agency (DFC). This position is remote. This position requires an Active Public Trust clearance.
Qualifications:
  • Active Public Trust clearance
  • B.S. Computer Science, Information Technology, or a related field
  • 5+ years of cybersecurity experience, including three or more years in vulnerability management, security compliance, POA&M management, or a closely related function.
  • Hands-on experience analyzing authenticated scan results and validating vulnerabilities using Tenable Nessus, Qualys, Microsoft Defender, or comparable enterprise platforms.
  • Demonstrated ability to assess vulnerability risk using CVSS, exploitability, CISA KEV status, asset criticality, exposure, mission impact, threat intelligence, and compensating controls.
  • Experience creating and maintaining POA&M records, tracking remediation milestones, reconciling GRC and ticketing systems, validating closure evidence, and documenting false-positive determinations.
  • Working knowledge of FISMA, the NIST Risk Management Framework, NIST SP 800-53 controls, NIST SP 800-40 vulnerability and patch-management principles, CISA KEV/BOD 22-01 requirements, and federal continuous-monitoring expectations.
  • Ability to communicate technical risk clearly to federal cybersecurity leaders, System Owners, engineers, administrators, auditors, and nontechnical stakeholders.
  • Strong analytical writing, data-quality, documentation, prioritization, and time-management skills in a deadline-driven environment.
  • Active Security+, CySA+, CEH, GCVA, CISSP or other relevant security certifications preferred.

Duties:
  • Coordinate authenticated vulnerability scans with DFC stakeholders at frequencies aligned with policy, system criticality, exposure, threat conditions, and Government direction.
  • Analyze output from Tenable, Qualys, Microsoft Defender, and other Government-approved vulnerability, endpoint, configuration, and posture-management platforms.
  • Validate scanner findings against the operational environment and distinguish valid findings from false positives using documented rationale and supporting evidence.
  • Assess and assign severity using CVSS, DFC policy, exploitability, known-exploitation status, asset criticality, external exposure, mission impact, and relevant threat intelligence.
  • Recommend risk-informed remediation priorities, actions, timelines, evidence requirements, and closure criteria.
  • Coordinate with engineering, operations, application, cloud, endpoint, and system administration teams to establish remediation ownership, dependencies, and target completion dates
  • Provide rapid analysis and coordination for CISA Known Exploited Vulnerabilities (KEV), Binding Operational Directive 22-01 requirements, CISA Emergency Directives, vendor-declared zero-days, and vulnerabilities with active exploitation.
  • Notify the ISSM within four hours of applicable CISA notification, vendor disclosure, Government notification, or Contractor identification.
  • Verify exposure across applicable CSAM authorization boundaries and deliver a written impact assessment within one business day.
  • Document affected systems, boundaries and assets; severity; exposure; exploitability; known exploitation; mission impact; remediation ownership; required timelines; recommended action; and residual-risk considerations.
  • Track emergency remediation against CISA-, DFC-, or Government-directed deadlines and provide written confirmation of remediation status, compliance status, residual risk, and closure evidence.
  • Use CSAM as the authoritative POA&M and compliance ledger and ServiceNow as the operational remediation ticketing record.
  • Create complete POA&M items in CSAM within three business days after finding identification or Government direction, unless the Government establishes another deadline.
  • Populate and maintain required fields, including identifier, weakness description, affected system and control, severity, source, responsible owner, required resources, scheduled completion date, milestones, status, residual risk, and closure evidence.
  • Maintain bidirectional traceability so each applicable ServiceNow remediation ticket links to its CSAM POA&M item and each CSAM POA&M record references the appropriate ServiceNow ticket.
  • Track remediation through closure, monitor milestone integrity and aging, and coordinate scheduled-completion-date changes only after federal authorization.
  • Conduct monthly ServiceNow-to-CSAM reconciliation; identify stale or duplicate records, missing links or evidence, inconsistent status, inaccurate dates, and other data-quality issues; issue a written discrepancy log and track gaps to resolution.
  • Prepare risk-acceptance or exception recommendation packages when remediation cannot be completed within applicable timelines or scheduled-completion-date constraints.
  • Document the affected system and weakness, operational and mission impacts, exploitability, exposure, residual risk, compensating controls, remediation constraints, proposed duration and expiration, review interval, and conditions for continued acceptance.
  • Route recommendation packages to the AODR through the COR and ISSM for federal decision and accurately record approved decisions in CSAM.
  • Clearly preserve federal authority: do not accept risk for DFC, approve exceptions, extend POA&M dates without authorization, or make final closure decisions.

Skills Required

  • Active Public Trust clearance
  • B.S. in Computer Science, Information Technology, or related field
  • 5+ years of cybersecurity experience, including 3+ years in vulnerability management, security compliance, or POA&M management
  • Hands-on experience analyzing authenticated scan results and validating vulnerabilities using Tenable Nessus, Qualys, Microsoft Defender, or comparable enterprise platforms
  • Ability to assess vulnerability risk using CVSS, exploitability, CISA KEV status, asset criticality, exposure, mission impact, threat intelligence, and compensating controls
  • Experience creating and maintaining POA&M records, tracking remediation milestones, reconciling GRC and ticketing systems, validating closure evidence, and documenting false positives
  • Working knowledge of FISMA, NIST Risk Management Framework, NIST SP 800-53, NIST SP 800-40, CISA KEV/BOD 22-01, and federal continuous-monitoring expectations
  • Ability to communicate technical risk clearly to federal cybersecurity leaders, system owners, engineers, administrators, auditors, and nontechnical stakeholders
  • Strong analytical writing, data-quality, documentation, prioritization, and time-management skills in a deadline-driven environment
  • Active Security+, CySA+, CEH, GCVA, CISSP or other relevant security certifications
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Largo, MD
25 Employees
Year Founded: 2006

What We Do

Established in 2006, cFocus Software automates FedRAMP compliance and develops government chatbots for the Azure Government Cloud, Office 365, and SharePoint. cFocus Software is the exclusive vendor of ATO (Authority To Operate) as a Service™, which automates FedRAMP compliance for the Azure Government Cloud and Office 365. Contact Us for a demo of ATO as a Service™ or a FREE government chatbot proof of concept project today!

Similar Jobs

Wipfli Logo Wipfli

Architect

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
3000 Employees
117K-158K Annually

CrowdStrike Logo CrowdStrike

Regional Sales Manager

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
3 Locations
11000 Employees
130K-175K Annually

Pluralsight Logo Pluralsight

Solutions Portfolio Lead, Cloud and Security

Edtech • Information Technology • Software
Remote or Hybrid
USA
1000 Employees
110K-145K Annually

Granted Logo Granted

Back-end Engineer

Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
In-Office or Remote
2 Locations
23 Employees
150K-225K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account