{"schemaVersion":"jobsearcher.job.v1","id":"5a7de50982cc23bf9ff2edab","url":"https://jobsearcher.com/jobs/5a7de50982cc23bf9ff2edab","canonicalUrl":"https://jobsearcher.com/jobs/5a7de50982cc23bf9ff2edab","title":"Vulnerability Analyst","description":"Job Summary\nThe Vulnerability Analyst will play an important role to identify, assess, prioritize, report, and assist others in mitigating vulnerabilities within an organization's information systems. This engagement will free up other cybersecurity resources to work in other critical Argonne areas. This contract position is for a full-time position at 40 hours per week for 1 year. The ideal candidate will need to:\nPossess a working level expertise with the National Institute of Standards and Technologies (NIST) Cybersecurity Framework (CSF) and the NIST 800-53 series of control families and approaches.\nUsing automated tools and manual techniques to Client security weaknesses (i.e. Tenable Security Center, Nucleus Security, etc...)\nConducting regular scans and assessments of systems, applications, and networks to identify potential vulnerabilities.\nAnalyzing the identified vulnerabilities to determine their potential impact on the organization.\nPrioritizing vulnerabilities based on their severity and the risk they pose to the organization.\nPerforming routine assignment of tickets to IT and other teams to address vulnerabilities as part of a 'cyber hygiene' process.\nRecommending mitigation strategies to address identified vulnerabilities.\nWorking with IT and development teams to apply patches, configure systems securely, and implement other remediation measures. This position is not expected to perform patching activities.\nCreating detailed reports on the findings of vulnerability assessments and risk analyses.\nDocumenting the status of vulnerabilities and the actions taken to mitigate them.\nCommunicating the results of vulnerability assessments, risk analyses, and other cyber hygiene work to stakeholders, including management and technical teams.\nStaying up to date with the latest cybersecurity threats, vulnerabilities, and best practices.\nContinuously improving the organization's vulnerability management processes and tools.\nAttend online/Teams meetings with team and others as appropriate\nWork with team to provide status on current task, suggest improvements, discuss implementation, etc.\nManagement and Remediation Plan:\nCollaborate with IT and system administrators to create a patch management policy.\nProvide a prioritization of vulnerabilities for remediation based on risk assessment.\nRun \"Hygiene Improvement Process” (HIP) vulnerability tasks (e.g., generating prioritized list of systems or vulnerabilities to remediate, creating and assigning tickets, follow-up on tickets, enforcing mitigation requirements, reporting).\nDevelop a schedule, aligned with existing policy, for applying patches and updates to systems and applications.\nMonitor the effectiveness of patching efforts and adjust the plan as needed.\nProvide bi-weekly, monthly, and quarterly reports of vulnerability and patching efforts to various stakeholders.\nCloud, Container, and DevSecOps\nCloud posture and vulnerabilities:\nImplement CSPM/agent-based scanning for IaaS/PaaS; cover images, VMs, serverless, and managed services.\nEnsure tagging/ownership standards in cloud for routing remediation.\nContainers and Images:\nScan images in registries and at build time; block critical vulns from promotion.\nApplication Dependencies:\nIntroduce SCA for third-party libraries; integrate auto-dependency updates.\nAdd SAST/DAST where applicable; tune to reduce false positives.\nIaC hygiene:\nScan Terraform/CloudFormation/Kubernetes manifests; enforce guardrails in CI.\nExpectation/Deliverables:\nAssisting and guiding business units with their vulnerability remediation as well as technical debt cleanup.\nCreate and update Vulnerability risk acceptance/modification review/analysis and approval/non-approval\nDocument entire workflow of current system in current state and future state\nProvide opportunities for automation within current and future state processes (i.e. python, bash, etc.)\nAssist in vulnerability tool review/tuning\nQualifications:\nTechnical Skills—\nVulnerability Assessment Tools:\nProficiency in using vulnerability scanning tools such as Tenable, Nessus, Qualys, OpenVAS, and Nexpose.\nFamiliarity with penetration testing tools like Metasploit, Burp Suite, and Nmap.\nOperating Systems:\nStrong knowledge of various operating systems, including Windows, Linux, and macOS.\nUnderstanding of system administration and security configurations.\nNetworking:\nIn-depth understanding of network protocols, architecture, and security.\nExperience with network scanning and monitoring tools.\nScripting and Programming:\nAbility to write scripts in languages such as Python, Bash, or PowerShell to automate tasks and analyze data.\nBasic programming skills to understand and analyze code for vulnerabilities.\nSecurity Frameworks and Standards:\nFamiliarity with cybersecurity frameworks and standards such as NIST, ISO 27001, CIS Controls, and OWASP.\nUnderstanding of the Cybersecurity Framework (CSF) and NIST 800-53 controls.\nCertifications (Optional):\nCertified Information Systems Security Professional (CISSP):\nCertified Ethical Hacker (CEH):\nCompTIA Security+:\nCertified Information Security Manager (CISM):\nOffensive Security Certified Professional (OSCP):\nGIAC Security Essentials (GSEC):\nExperience—\nPractical experience in conducting vulnerability assessments and/or penetration tests.\nExperience in system and network administration.\nFamiliarity with security concerns and vulnerabilities common in an enterprise environment, including application development, IT/OT environments, virtualization, containers, etc.\nStaying up to date with the latest cybersecurity threats, vulnerabilities, and best practices.\nStrong analytical and problem-solving skills to identify and assess vulnerabilities.\nMeticulous attention to detail to ensure thorough assessments and accurate reporting.\nExcellent written and verbal communication skills to effectively convey findings and recommendations to technical and non-technical stakeholders.\nAbility to work collaboratively with other cybersecurity professionals, IT staff, and external vendors.\nConsiderable knowledge/experience of assessing security controls.\nExperience and skill in conducting audits or reviews of technical systems.\nExperience working in a government environment.\nExperience working in a distributed IT environment.\nAbility to obtain HSPD-12 card for use in two-factor authentication.\nAble to work both independently and as a contributing member of a small technical team\nAble to disseminate knowledge to current staff.\nJob Type: Contract\nPay: $50.00 - $60.00 per hour\nExpected hours: 40 per week\nBenefits:\nLife insurance\nWork Location: Remote","company":"Tech Army","rawCompany":"tech army","city":"Remote","state":"OR","isRemote":false,"isActive":false,"createdAt":"2026-08-06T12:51:37.710Z","occupations":[{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1299.04","title":"Penetration Testers","slug":"penetration-testers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"},{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Vulnerability Analyst","description":"Job Summary\nThe Vulnerability Analyst will play an important role to identify, assess, prioritize, report, and assist others in mitigating vulnerabilities within an organization's information systems. This engagement will free up other cybersecurity resources to work in other critical Argonne areas. This contract position is for a full-time position at 40 hours per week for 1 year. The ideal candidate will need to:\nPossess a working level expertise with the National Institute of Standards and Technologies (NIST) Cybersecurity Framework (CSF) and the NIST 800-53 series of control families and approaches.\nUsing automated tools and manual techniques to Client security weaknesses (i.e. Tenable Security Center, Nucleus Security, etc...)\nConducting regular scans and assessments of systems, applications, and networks to identify potential vulnerabilities.\nAnalyzing the identified vulnerabilities to determine their potential impact on the organization.\nPrioritizing vulnerabilities based on their severity and the risk they pose to the organization.\nPerforming routine assignment of tickets to IT and other teams to address vulnerabilities as part of a 'cyber hygiene' process.\nRecommending mitigation strategies to address identified vulnerabilities.\nWorking with IT and development teams to apply patches, configure systems securely, and implement other remediation measures. This position is not expected to perform patching activities.\nCreating detailed reports on the findings of vulnerability assessments and risk analyses.\nDocumenting the status of vulnerabilities and the actions taken to mitigate them.\nCommunicating the results of vulnerability assessments, risk analyses, and other cyber hygiene work to stakeholders, including management and technical teams.\nStaying up to date with the latest cybersecurity threats, vulnerabilities, and best practices.\nContinuously improving the organization's vulnerability management processes and tools.\nAttend online/Teams meetings with team and others as appropriate\nWork with team to provide status on current task, suggest improvements, discuss implementation, etc.\nManagement and Remediation Plan:\nCollaborate with IT and system administrators to create a patch management policy.\nProvide a prioritization of vulnerabilities for remediation based on risk assessment.\nRun \"Hygiene Improvement Process” (HIP) vulnerability tasks (e.g., generating prioritized list of systems or vulnerabilities to remediate, creating and assigning tickets, follow-up on tickets, enforcing mitigation requirements, reporting).\nDevelop a schedule, aligned with existing policy, for applying patches and updates to systems and applications.\nMonitor the effectiveness of patching efforts and adjust the plan as needed.\nProvide bi-weekly, monthly, and quarterly reports of vulnerability and patching efforts to various stakeholders.\nCloud, Container, and DevSecOps\nCloud posture and vulnerabilities:\nImplement CSPM/agent-based scanning for IaaS/PaaS; cover images, VMs, serverless, and managed services.\nEnsure tagging/ownership standards in cloud for routing remediation.\nContainers and Images:\nScan images in registries and at build time; block critical vulns from promotion.\nApplication Dependencies:\nIntroduce SCA for third-party libraries; integrate auto-dependency updates.\nAdd SAST/DAST where applicable; tune to reduce false positives.\nIaC hygiene:\nScan Terraform/CloudFormation/Kubernetes manifests; enforce guardrails in CI.\nExpectation/Deliverables:\nAssisting and guiding business units with their vulnerability remediation as well as technical debt cleanup.\nCreate and update Vulnerability risk acceptance/modification review/analysis and approval/non-approval\nDocument entire workflow of current system in current state and future state\nProvide opportunities for automation within current and future state processes (i.e. python, bash, etc.)\nAssist in vulnerability tool review/tuning\nQualifications:\nTechnical Skills—\nVulnerability Assessment Tools:\nProficiency in using vulnerability scanning tools such as Tenable, Nessus, Qualys, OpenVAS, and Nexpose.\nFamiliarity with penetration testing tools like Metasploit, Burp Suite, and Nmap.\nOperating Systems:\nStrong knowledge of various operating systems, including Windows, Linux, and macOS.\nUnderstanding of system administration and security configurations.\nNetworking:\nIn-depth understanding of network protocols, architecture, and security.\nExperience with network scanning and monitoring tools.\nScripting and Programming:\nAbility to write scripts in languages such as Python, Bash, or PowerShell to automate tasks and analyze data.\nBasic programming skills to understand and analyze code for vulnerabilities.\nSecurity Frameworks and Standards:\nFamiliarity with cybersecurity frameworks and standards such as NIST, ISO 27001, CIS Controls, and OWASP.\nUnderstanding of the Cybersecurity Framework (CSF) and NIST 800-53 controls.\nCertifications (Optional):\nCertified Information Systems Security Professional (CISSP):\nCertified Ethical Hacker (CEH):\nCompTIA Security+:\nCertified Information Security Manager (CISM):\nOffensive Security Certified Professional (OSCP):\nGIAC Security Essentials (GSEC):\nExperience—\nPractical experience in conducting vulnerability assessments and/or penetration tests.\nExperience in system and network administration.\nFamiliarity with security concerns and vulnerabilities common in an enterprise environment, including application development, IT/OT environments, virtualization, containers, etc.\nStaying up to date with the latest cybersecurity threats, vulnerabilities, and best practices.\nStrong analytical and problem-solving skills to identify and assess vulnerabilities.\nMeticulous attention to detail to ensure thorough assessments and accurate reporting.\nExcellent written and verbal communication skills to effectively convey findings and recommendations to technical and non-technical stakeholders.\nAbility to work collaboratively with other cybersecurity professionals, IT staff, and external vendors.\nConsiderable knowledge/experience of assessing security controls.\nExperience and skill in conducting audits or reviews of technical systems.\nExperience working in a government environment.\nExperience working in a distributed IT environment.\nAbility to obtain HSPD-12 card for use in two-factor authentication.\nAble to work both independently and as a contributing member of a small technical team\nAble to disseminate knowledge to current staff.\nJob Type: Contract\nPay: $50.00 - $60.00 per hour\nExpected hours: 40 per week\nBenefits:\nLife insurance\nWork Location: Remote","datePosted":"2026-08-06T12:51:37.710Z","dateModified":"2026-08-06T12:51:37.710Z","hiringOrganization":{"@type":"Organization","name":"Tech Army","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Remote","addressRegion":"OR","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"5a7de50982cc23bf9ff2edab"},"url":"https://jobsearcher.com/jobs/5a7de50982cc23bf9ff2edab"}}