VULNERABILITY MGMT ANALYST

Posted Yesterday
Be an Early Applicant
Falls Church, VA, USA
In-Office
90K-120K Annually
Mid level
Defense • Defense Technology
The Role
Own end-to-end vulnerability remediation across diverse systems and networks, including scanning, risk prioritization, patch qualification, deployment, rollback planning, rescanning, and closure validation. Coordinate maintenance windows and remediation timelines with system owners, manage exceptions and accepted risks, automate scanning and reporting workflows, maintain procedures and metrics, and communicate status to technical and nontechnical stakeholders. The role requires active Top Secret clearance, onsite work in Falls Church, occasional travel, and after-hours support.
Summary Generated by Built In

Areté is looking for the person who makes sure vulnerabilities actually get closed — not just found. As our Vulnerability Management Analyst in Falls Church, VA, you will own the end-to-end remediation cycle — scanning, prioritization, patch qualification, deployment, and verification — across desktops, servers, network devices, and standalone systems on multiple sites and networks, working closely with Areté's Cyber Security staff.

This is a hands-on execution role, and you will be measured on whether vulnerabilities close on a recurring, risk-prioritized cadence. Equally important is doing so without breaking the business: qualifying patches before they are pushed, understanding which applications depend on pinned or vendor-locked component versions, coordinating maintenance windows with system owners, and having a tested rollback path when a patch goes wrong.

The selected candidate must hold an active Top Secret clearance and be able to maintain it. This position is onsite at our Falls Church, VA facility. The candidate may be required to travel occasionally and provide some afterhours support. This is an exempt non-supervisory full-time position.

Primary Responsibilities:

•    Conduct regular vulnerability assessments and serve as the technical expert with primary responsibility for vulnerability scanning and remediation of desktops, servers, network devices, and other systems across multiple sites, networks, and standalone environments.

•    Analyze scan results from Rapid7 and Tenable Security Center (ACAS) and produce a risk-prioritized remediation plan that accounts for severity, exploitability, exposure, asset criticality, and known-exploited-vulnerability status — not raw CVSS alone.

•    Execute continuous, recurring patching schedules against that prioritization, within maintenance windows authorized by the appropriate change control board.

•    Qualify patches before deployment: test in a representative environment, identify dependencies on pinned or vendor-supported component versions, assess impact to line-of-business and server applications, and document a rollback plan.

•    Identify vulnerabilities that cannot be resolved by patching alone — pinned application dependencies, end-of-life software, vendor-locked systems — and develop compensating controls, mitigation strategies, or upgrade recommendations in coordination with system owners and Cyber Security.

•    Coordinate with system owners and end users on upcoming patches and projected impacts, including reboots, service interruptions, and network-wide effects.

•    Verify remediation through rescanning and closure validation; track exceptions, deviations, and accepted risks through to resolution or formal acceptance.

•    Automate recurring scanning, patching, reporting, and remediation workflows to reduce manual effort and improve consistency.

•    Maintain vulnerability management processes and standard operating procedures, and maintain and report metrics for the function — remediation timeliness, aging, coverage, patch success and failure rates, and recurring problem areas.

•    Prepare and present reports on vulnerability management activities to IT and senior management, communicating complex technical information to non-technical stakeholders.

•    Stay current on emerging threats, actively exploited vulnerabilities, and vendor advisories, and recommend proactive measures.

•    Other duties, as assigned.

Experiences and Background We Look For:

•    Active Top Secret clearance, with the ability to maintain it.

•    Must have or be able to obtain a CompTIA Security+ CE certification within 120 days of employment, in accordance with DoDM 8140.03 and DFARS 252.239-7001.

•    Minimum of 3 years working as a System Administrator, Systems Engineer, Network Administrator, Vulnerability Analyst, or similar role.

•    Proficient understanding of computer hardware, software, and operating systems — primarily Microsoft Windows Server and Red Hat Enterprise Linux — with strong system troubleshooting skills across both.

•    Working knowledge of vulnerability scanning products such as Rapid7 (preferred), Tenable Security Center/Nessus (ACAS), or Qualys.

•    Experience with patch management tools such as PDQ Deploy, SCCM/MECM, WSUS, YUM/DNF, or Red Hat Satellite — including testing and qualifying patches prior to deployment, coordinating change-managed maintenance windows, and executing rollback when required.

•    Working scripting ability in PowerShell, Bash, or Python sufficient to automate recurring scan parsing, patch orchestration, and reporting tasks.

•    Strong interpersonal and written communication skills, with the ability to work autonomously, produce technical documentation, and negotiate remediation timelines with system owners who have competing priorities.

Nice to Have:

•    TS/SCI access with polygraph.

•    Advanced automation experience building patch orchestration or vulnerability reporting tooling.

•    Experience patching and maintaining airgapped, standalone, or classified systems, including offline content management and update ingestion.

•    Familiarity with DISA STIGs, SCAP Compliance Checker, and DoD or federal compliance frameworks (NIST 800-53, NIST 800-171, RMF).

•    Experience with container and application dependency scanning, and with SBOM-based vulnerability identification.

•    Experience managing vulnerabilities in third-party and line-of-business applications where a vendor pins supported runtime or library versions.

•    Industry certifications such as CySA+, Network+, CCNA, RHCSA, Microsoft AZ-800/801 or MD-102, GIAC GCED/GEVA, or vendor certifications in Rapid7 or Tenable/ACAS.

•    Bachelor's Degree in an Information Technology related discipline.

We have an impressive range of benefits, programs, and perks that we offer:

Generous PTO and Leave Times

•    Flextime Scheduling

•    Bereavement

•    Paid Time Off (PTO)

•    Paid Parental Leave

Financial Benefits

•    Company-funded 5% contribution to your 401(k) retirement plan

•    Company-funded 5% contribution to your Employee Stock Ownership Plan

•    Continuing Education Assistance

Health, Medical, and Wellness Benefits

•    Medical Insurance

•    Dental & Vision Insurance

•    Life Insurance and Long-Term Disability (LTD)

•    Vision Reimbursement

Skills Required

  • Active Top Secret security clearance with ability to maintain it
  • Have or obtain CompTIA Security+ CE certification within 120 days of employment
  • Minimum of 3 years of experience as a System Administrator, Systems Engineer, Network Administrator, Vulnerability Analyst, or similar
  • Proficiency with computer hardware, software, operating systems, Microsoft Windows Server, and Red Hat Enterprise Linux
  • Working knowledge of Rapid7, Tenable Security Center/Nessus, ACAS, or Qualys
  • Experience with PDQ Deploy, SCCM/MECM, WSUS, YUM/DNF, or Red Hat Satellite patch management tools
  • Experience testing and qualifying patches, coordinating maintenance windows, and executing rollback procedures
  • Working scripting ability in PowerShell, Bash, or Python
  • Strong interpersonal, written communication, technical documentation, autonomous work, and remediation negotiation skills
  • TS/SCI access with polygraph
  • Advanced automation experience building patch orchestration or vulnerability reporting tools
  • Experience patching airgapped, standalone, or classified systems, including offline content management
  • Familiarity with DISA STIGs, SCAP Compliance Checker, NIST 800-53, NIST 800-171, or RMF
  • Experience with container and application dependency scanning or SBOM-based vulnerability identification
  • Experience managing vulnerabilities in third-party and line-of-business applications with vendor-pinned dependencies
  • Industry certifications including CySA+, Network+, CCNA, RHCSA, Microsoft AZ-800/801, MD-102, GIAC GCED/GEVA, Rapid7, or Tenable/ACAS certifications
  • Bachelor's degree in an Information Technology-related discipline
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: North Belridge, California
468 Employees
Year Founded: 1976

What We Do

Areté, an employee-owned company, is an advanced science and engineering company that provides innovative solutions to the most challenging technical problems faced by the United States Defense and Intelligence agencies. Areté is derived from the Greek word “ἀρέτη”, meaning the pursuit of excellence and the achievement of maximum performance. Areté was founded in 1976 by five scientists, tasked by the DoD to help solve the challenge of detecting weak signals in heavy clutter over very wide areas. The signatures involved in this work were so weak that any advancement in signal processing algorithms demanded a new approach and understanding of the underlying fundamentals affecting the sensors and signal phenomena in the environments of interest. This first-principles-of-physics approach has been a hallmark of Areté’s development programs for the past 40 years Areté now works across the electromagnetic spectrum. We develop sensors and the associated signal processing algorithms necessary for the extraction and interpretation of data for systems operating under water, in the atmosphere, and in space. With our emphasis on enhanced signal processing and real-time executable software, Areté is able to improve the performance of existing sensor systems at fractions of the cost and time to operations of replacement systems. We work directly with customers and partners seeking maximum performance. Building on our expertise in detection theory we will continue to exploit the contextual, spatial, spectral, and temporal characteristics of data, incorporating them into our signal processing algorithms. These robust algorithms will continue to enable Areté to rapidly deliver innovative solutions to the ever evolving challenges of our customers.

Similar Jobs

Lowe’s Logo Lowe’s

Senior WMS Analyst

Consumer Web • eCommerce • Information Technology • Retail • Software • Analytics • App development
Hybrid
Richmond, VA, USA
300000 Employees

PNC Bank Logo PNC Bank

Product Owner

Machine Learning • Payments • Security • Software • Financial Services
Remote or Hybrid
USA
55000 Employees
91K-203K Annually

Boeing Logo Boeing

Audio Visual Programmer Analyst (Experienced, Senior or Lead)

Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
In-Office
Herndon, VA, USA
170000 Employees
116K-231K Annually

Boeing Logo Boeing

Audiovisual Design & Integration Specialist (Experienced or Senior)

Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
In-Office
Herndon, VA, USA
170000 Employees
120K-198K Annually

Similar Companies Hiring

Onebrief Thumbnail
Software • Defense
US
350 Employees
Rangeview Thumbnail
Manufacturing • Defense • Aerospace
Berkeley, CA
25 Employees
Outpost Space Thumbnail
Aerospace • Defense
US
24 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account