Jobs and Careers
SM

Vulnerability Analyst (4274) (TS/SCI) (Ft. Belvoir, VA)

SMX
Fort Belvoir, United Statesfull_timeVerifiedPosted 27 May 2025
💰 $184,800/yr($110,900/yr$184,800/yr)

About the role

SMX is seeking a Vulnerability Analyst to perform regular vulnerability assessments and scans of networks, systems, and applications in both on-premises and cloud environments and identify where those systems/networks deviate from acceptable configurations, enclave policy, or local policy. This role involves analyzing assessment results, evaluating risk levels, and collaborating with IT and security teams to develop and implement effective remediation strategies. The Vulnerability Analyst ensures compliance with DoD, Army, and Intelligence Community (IC) regulations while educating stakeholders about the importance of vulnerability management and security best practices. This position requires technical expertise, a thorough understanding of cybersecurity principles, and strong communication skills to enhance the overall security posture of the Army Intelligence Enterprise (AIE). This is a full-time onsite position.

Essential Duties & Responsibilities

  • Vulnerability Assessment and Analysis:
    • Identify systems, services, and applications that pose exceptional risk to Army IC.
    • Using security tools, perform regular vulnerability assessments on networks, systems, and applications in on-premises and cloud environments.
    • Perform vulnerability assessments based on DoD, Army, and IC Policies and
    • Examine vulnerability assessment results to determine the severity, risk levels, and possible impact of identified vulnerabilities.
    • Continuously monitor systems and networks for new threats and vulnerabilities, adjusting processes as needed to ensure compliance with Army and IC regulations.
    • Identify gaps in coverage of security tools required by DoD, Army, and IC.
    • Manage and support Army IC quarantine process in collaboration with IT Operations.
  • Remediation and Collaboration:
    • Coordinate with IT and security teams to create and implement remediation plans, which may involve applying patches, making configuration changes, or introducing other security measures.
    • Offer expertise on vulnerability issues during security incidents and assist with incident response activities.
    • Collaborate closely with ISSOs and ISSMs throughout the Army Intelligence Enterprise (AIE) to encourage best practices and swiftly address security issues.
    • Develop relevant vulnerability, threat, and risk metrics.
  • Tools Management and Reporting:
    • Manage and maintain vulnerability assessment tools to ensure they remain up-to-date and effective at identifying security weaknesses.
    • Create detailed reports on vulnerability assessment outcomes, risk evaluations, and mitigation progress to share with stakeholders, including management and regulatory agencies.
    • Develop and manage vulnerability and risk dashboards for consumption by system administrators, cybersecurity analysts, ISSOs, ISSMs, ISOs, major commands, and executive leadership.
  • Training and Awareness:
    • Educate and train ISSM, ISSO, and other cybersecurity analysts on the use of vulnerability assessment tools, security best practices, and compliance requirements.
    • Contribute to security awareness initiatives and develop enhanced vulnerability scanning methodologies and tools.
  • Compliance and Standards:
    • Ensure compliance with DoD, Army, and IC regulations, including task orders, bulletins, National Security Memorandums (NSM).
    • Stay updated on the latest cybersecurity threats, technologies, and emerging vulnerabilities to ensure compliance and improve vulnerability assessment processes.
  • Threat Research and Mitigation:
    • Research and report on new threats, attack vectors, and exploitation methods, demonstrating a thorough understanding of cyber threat actor tactics, techniques, and procedures (TTPs).
    • Assess, plan, and improve cybersecurity architecture, detection signatures, and tool configurations to protect systems from breaches.
    • Perform cyber threat intelligence analysis, correlate actionable cybersecurity events, and create correlation techniques for identifying threats.
  • Vulnerability Assessments:
    • Conduct and/or support authorized penetration testing on enterprise network assets.
    • Prepare audit reports that identify technical and procedural findings, and provide recommended remediation strategies/solutions
    • Analyze organization's cyber defense policies and configurations and evaluate compliance with regulations and organizational directives
    • Maintain knowledge of applicable cyber defense policies, regulations, and compliance documents specifically related to cyber defense auditing.

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

SMX

View company profile →