Vulnerability Management Analyst
Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
Copper River Cyber Solutions is seeking a highly motivated Vulnerability Management Analyst to support the NIH cybersecurity program by identifying, analyzing, tracking, and reporting security vulnerabilities across enterprise systems, applications, databases, cloud environments, and network infrastructure. The Analyst collaborates with system owners, security engineers, RMF personnel, and operational teams to ensure vulnerabilities are properly assessed, prioritized, remediated, and verified in accordance with NIH, HHS, and Federal cybersecurity requirements.
The position plays a key role in maintaining a strong security posture through continuous monitoring, risk analysis, remediation tracking, and compliance reporting.
Responsibilities (include but are not limited to):
- Perform vulnerability assessments and analysis across NIH information systems and infrastructure.
- Perform threat-informed prioritization using exploitability, threat intelligence, CISA Known Exploited Vulnerabilities (KEV), mission criticality, system exposure, and compensating controls.
- Assess vulnerability risk within the context of system criticality, data sensitivity, and organizational risk tolerance.
- Develop vulnerability dashboards, remediation metrics, trend analyses, and executive reporting products.
- Review and analyze vulnerability scan results from enterprise security tools.
- Validate findings to determine severity, exploitability, and potential impact.
- Conduct risk-based prioritization of vulnerabilities and security weaknesses.
- Coordinate with technical teams to assess remediation requirements and timelines.
- Manage the full lifecycle of vulnerability identification, remediation, and closure.
- Track vulnerabilities from discovery through remediation and validation.
- Maintain vulnerability repositories, remediation records, and status reporting.
- Monitor remediation progress and escalate overdue findings as appropriate.
- Verify corrective actions and document closure activities.
- Support continuous monitoring activities across NIH systems and applications.
- Analyze vulnerability trends and identify recurring issues.
- Evaluate security risks associated with discovered vulnerabilities.
- Collaborate with RMF/A&A teams to support Authorization to Operate (ATO) activities.
- Assist with the management and tracking of Plans of Action and Milestones (POA&Ms).
- Provide vulnerability-related evidence and documentation for audits, assessments, and authorization activities.
Essential Job Qualifications and Requirements:
Education:
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field
Required Qualifications:
- Minimum 5 years of experience in cybersecurity, vulnerability management, information assurance, or security operations supporting Federal environments.
- Experience supporting POA&M development, remediation tracking, corrective action validation, or vulnerability closure activities.
- Experience conducting vulnerability assessments and remediation tracking.
- Familiarity with:
- NIST RMF (SP 800-37)
- NIST SP 800-53 Rev. 5
- FISMA
- Federal cybersecurity compliance requirements
- Risk assessment methodologies
- Experience analyzing vulnerability data and developing remediation recommendations.
- Strong analytical, problem-solving, and communication skills.
- Ability to obtain and maintain an NIH Public Trust.
Preferred Qualifications:
- One or more of the following certifications:
- Security+
- Certified Ethical Hacker (CEH)
- CISSP
- GIAC Vulnerability Assessment (GVA)
- GIAC Information Security Fundamentals (GISF)
- GSEC
- CAP (Certified Authorization Professional)
- CISM
- CRISC
- Experience supporting NIH, HHS, or other Federal civilian agencies.
- Experience working within FISMA-compliant environments.
- Knowledge of cloud security and vulnerability management practices.
- Experience supporting continuous diagnostics and mitigation (CDM) initiatives.
- Understanding of FedRAMP and Zero Trust security principles.
- Experience coordinating remediation activities across multiple stakeholders.
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
More Openings at Copper River Management Co.
Explore Top Companies in this Space
Copper River Management Co.
View Company ProfileCopper River Management Co. (operating at copperrivermc.com) is a federal government contracting platform/engineered for specialized services. Founded in 2006 by unknown founders and headquartered in Chantilly, VA, Copper River Management Co. specializes in federal and healthcare sectors instead of general contracting. Under the hood, the company leverages its expertise and workforce to deliver high-quality services. This allows clients to access critical health and social services, natural resource/environmental education, jobs, job training, and other essential programs. Backed by revenues between 100 million and 250 million dollars.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.
