Vulnerability Scan Analyst

Job Location US
ID
2025-3020
Job Type
Contingent Upon Prime/Customer Acceptance
Category
Cyber and Information Security

Overview

 

SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure and Operations, and Applications Development and Maintenance IT service provider headquartered in Dulles, Virginia with operations across the U.S. We provide innovative enterprise-wide solutions as well as targeted services addressing the complex challenges faced by our federal government clients. Our focus is on enabling our clients to deliver their mission most efficiently and effectively – anytime, anywhere, securely. We combine technical expertise, mission awareness, and an empowered workforce to produce meaningful results.

 

Join the SkyePoint team and become part of a highly skilled, professional workforce dedicated to delivering mission-critical solutions. Our exceptional technical experts provide innovative services and solutions to federal agencies, making a meaningful impact every day. At SkyePoint, we value top talent and foster an environment where your ideas and contributions truly matter. Be part of a team that values excellence and rewards innovation—your future starts here!

 

This is a contingent position based upon customer approval.

 

Responsibilities

SkyePoint Decisions, Inc. is seeking a highly motivated team member to fill the role of a Vulnerability Scan Analyst to join our team supporting the Department of Education’s (DoED) Federal Student Aid (FSA) Cybersecurity and Privacy Support Services (CPSS) in Washington, DC. The Vulnerability Scan Analyst assists in ensuring that appropriate vulnerability is scheduled, conducted, analyzed, and presented to the system owner ad information systems security officer (ISSO)

 

This is a remote position. 

 

Responsibilities:

  • Ensure that appropriate vulnerability is scheduled, conducted, analyzed, and presented to the system owner ad information systems security officer (ISSO). 
  • Populate an FSA’s vulnerability tracking tool injection template for all security deficiencies found during a test cycle, per system and ensuring appropriate content is included in all required fields. 
  • Review and provide advice based on analysis for Third Party Website and Applications (TPWA). 
  • Assist with the creation of a monthly OSA report that itemizes and describes the OSA scheduled assessment activities (controls, scans, etc.); Production Readiness Reviews (PRRs), scorecards, audits, CM, other tests completed during the past month, and any residual risks added. 
  • Provide a risk rating, based on the risk profiles of all systems in the OSA program, identify trends, and provides recommendations for improving security across the enterprise. This report shall provide sufficient granularity to provide subordinate reports to systems, principal offices (FSA) and individuals. 
  • Develops, researches and maintains proficiency in tools, techniques, countermeasures, and trends in computer and network vulnerabilities, data hiding, and encryption. 
  • Provide knowledge in vulnerability management and POAM support. 
  • Provide support in maintaining and annually (or as needed) updating a Vulnerability Management Standard Operating Procedure document. 
  • Support security operations, assessments, and POAM development. 

Qualifications

Required Qualifications:

  • Must be able to obtain a DoED Level 6 High Risk/Public Trust Security Clearance. 
  • Bachelor’s degree or equivalent and at least ten (10) years related experience. 
  • Senior industry professional certification such as a CISSP or equivalent. 
  • Excellent communications and interpersonal skills.
  • Ability to conducting vulnerability scans and recognizing vulnerabilities in security systems. 
  • Assessing the robustness of security systems and designs. 
  • Conducting application vulnerability assessments. 
  • Ability to perform impact risk assessments. 
  • Working experience with and tenable security center and Core Vulnerability Insight. 
  • Good familiarity with and understanding of all relevant government and agency policies and procedures to ensure system documentation is compliance with relevant guidelines, e.g., FedRAMP, RMF, FISMA, FIPS-II, NIST, etc. 
  • Familiarity with NIST SP 800-40, Creating a Patch and Vulnerability Management Program.
  • Must be a U.S. citizen.  

Preferred Qualifications:

  • Active Top Secret security clearance.
  • 10+ years’ experience.

 

What We Can Offer You:

  • At SkyePoint, we go B.I.G. (beginning in GRATITUDE) by recognizing all we have and giving back to our employees, families, and communities. It instills a positive mindset that permeates all we do. By beginning in gratitude, SkyePoint can continue to spread living in gratitude each day.
  • Great Benefits: Several insurance options including HMO and High Deductible plans with Health Savings Accounts [HSAs], Flex Spending Accounts [FSAs], Full Dental Plans, ST/LT Disability, Life Insurance, floating federal holiday options, and 401k matched
  • Certificate Incentive Program: To promote professional development, we recognize and reward employees who obtain new certifications aligned with business needs.
  • Flexible Work Environment

Compensation:

Salary Range: TBD

The SkyePoint Decisions salary range for this position is a general guideline only. It represents an estimated range for this position and is just one piece of our total compensation package. 

Salary at SkyePoint is determined by various factors, including but not limited to location, work schedule, the candidate’s combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability, market data and business considerations.

 

In addition to a competitive salary, SkyePoint offers benefits including a certification incentive program, PTO, floating federal holiday options, several insurance options including HMO and High Deductible plans with Health Savings Accounts [HSAs], Flex Spending Accounts [FSAs], Full Dental Plans, Vision, ST/LT Disability, Life Insurance, and 401k matched.

 

SkyePoint Decisions is an established ISO 9001:2015 and ISO/IEC 27001:2013 certified small business and appraised at CMMI Level 3 for Services and Development. We possess a common vision of excellence and foster a collaborative team culture built upon individual performance and accountability. We invest in our people and systems to create value for our clients. It is the SkyePoint Way. We are grateful for the opportunity to work with exceptional people and give back to the communities we serve. Our employees value the flexibility at SkyePoint that allows them to balance quality work and their personal lives.

Please be aware of recruiting scams and people claiming to be from SkyePoint Decisions. For more information, please see the Welcome Page of our Careers site.

Skyepoint Decisions is a participating E-Verify Employer. 

U.S. Citizenship is required for most positions.

Equal Opportunity Employer/Veterans/Disabled.

Options

Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.
Share on your newsfeed