SME Cyber Vulnerability Management
Listed on 2026-08-12
-
IT/Tech
Cybersecurity
Responsibilities for this Position
Location: USA NC Fort Bragg
Full Part/Time: Full time
Job Req: RQ225923
Type of Requisition: Regular
Clearance Level Must Currently Possess: Top Secret/SCI
Clearance Level Must Be Able to Obtain: Top Secret/SCI
Public Trust/Other
Required:
None
Job Family: Cyber and IT Risk Management
Job Qualifications:
Skills: Information Assurance, Scanning, Security Policies, Threat Detection
Certifications: None
Experience: 8 + years of related experience
US Citizenship
Required:
Yes
Job Description:
The SME Information Security Analyst (Vulnerability Management) serves as the technical lead for deploying, configuring, and maintaining the enterprise vulnerability management environment. This position focuses on optimizing Tenable Security Center within Linux/Red Hat infrastructures and ensuring compliance with DISA STIGs, NSA guidelines, and organizational cybersecurity policies. The analyst supports Enterprise Communications and hybrid environments across AWS, Microsoft Azure, and Google Cloud.
This role requires deep technical expertise, strong analytical skills, and collaboration with engineering, cybersecurity, and leadership teams across the command.
Vulnerability Management Operations
- Install, configure, and maintain Tenable Security Center and scanning components on Linux/Red Hat platforms.
- Ensure vulnerability management systems meet DISA STIG, NSA, and cybersecurity policy requirements.
- Manage credentialed and non-credentialed scans, schedules, asset groups, and plugin updates.
- Troubleshoot scanner/system issues to ensure accurate and continuous vulnerability detection.
- Analyze scan results to identify weaknesses, misconfigurations, and emerging threats.
- Validate findings, assess severity, and prioritize remediation based on mission needs.
- Produce recurring reports, dashboards, and metrics for Command Leadership.
- Translate complex technical findings into clear remediation guidance for engineering teams.
- Provide expert guidance on mitigation, configuration hardening, and patching strategies.
- Support development and maintenance of POA&Ms for unresolved vulnerabilities.
- Track remediation progress to ensure compliance with published cyber directives.
- Support enterprise communications systems and services to ensure secure hybrid operations.
- Assist with monitoring and securing cloud/on-prem workloads using enterprise security tools.
- Collaborate with cloud, network, and communications teams to ensure secure configurations and continuous monitoring.
- Support threat detection using Microsoft Defender for Endpoint and cloud environments including AWS, Azure, and Google Cloud.
- Conduct log analysis, event correlation, and investigation of suspicious activity.
- Assist with incident reporting, documentation, and escalation procedures.
- Contribute to detection rule tuning, alert fidelity improvements, and endpoint hardening.
- Identify coverage gaps and recommend improvements; document findings in After-Action Reports with SOC, EPT, and CTI partners.
- Develop guardrails, configuration baselines, and automation artifacts to reduce vulnerability recurrence.
- Support surge response activities through rapid scanning, validation, and remediation assistance.
Skills & Experience:
- Splunk or Elastic for Cloud
- Endpoint Detection & Response (EDR) tools
- Antivirus platforms
- Service Now, Remedy, or similar ticketing systems
- DoD 8570 / 8140 compliant certification
- CompTIA Security+
- CySA+
- Network+
- CASP+
- GIAC certifications (GCIH, GCFA, etc.)
- TS/SCI Required
- On Customer Site
- US citizenship
At GDIT, the mission is our purpose, and our people are at the center of everything we do.
Growth: AI-powered career tool that identifies career steps and learning opportunities
Support:
An internal mobility team focused on helping you achieve your career goals
Rewards:
Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
Community:
Award-winning culture of…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).