×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Vulnerability MGMT Analyst Security Clearance

Job in Falls Church, Fairfax County, Virginia, 22040, USA
Listing for: ARETE ASSOCIATES, INC.
Full Time position
Listed on 2026-08-31
Job specializations:
  • IT/Tech
    Cybersecurity
Job Description & How to Apply Below
Position: VULNERABILITY MGMT ANALYST with Security Clearance
Areté is looking for the person who makes sure vulnerabilities actually get closed - not just found. As our Vulnerability Management Analyst in Falls Church, VA, you will own the end-to-end remediation cycle - scanning, prioritization, patch qualification, deployment, and verification - across desktops, servers, network devices, and standalone systems on multiple sites and networks, working closely with Areté's Cyber Security staff.

This is a hands-on execution role, and you will be measured on whether vulnerabilities close on a recurring, risk-prioritized cadence. Equally important is doing so without breaking the business: qualifying patches before they are pushed, understanding which applications depend on pinned or vendor-locked component versions, coordinating maintenance windows with system owners, and having a tested rollback path when a patch goes wrong.

The selected candidate must hold an active Top Secret clearance and be able to maintain it. This position is onsite at our Falls Church, VA facility. The candidate may be required to travel occasionally and provide some after hours support. This is an exempt non-supervisory full-time position.

Primary Responsibilities:

• Conduct regular vulnerability assessments and serve as the technical expert with primary responsibility for vulnerability scanning and remediation of desktops, servers, network devices, and other systems across multiple sites, networks, and standalone environments.
• Analyze scan results from Rapid7 and Tenable Security Center (ACAS) and produce a risk-prioritized remediation plan that accounts for severity, exploitability, exposure, asset criticality, and known-exploited-vulnerability status - not raw CVSS alone.
• Execute continuous, recurring patching schedules against that prioritization, within maintenance windows authorized by the appropriate change control board.
• Qualify patches before deployment: test in a representative environment, identify dependencies on pinned or vendor-supported component versions, assess impact to line-of-business and server applications, and document a rollback plan.
• Identify vulnerabilities that cannot be resolved by patching alone - pinned application dependencies, end-of-life software, vendor-locked systems - and develop compensating controls, mitigation strategies, or upgrade recommendations in coordination with system owners and Cyber Security.
• Coordinate with system owners and end users on upcoming patches and projected impacts, including reboots, service interruptions, and network-wide effects.
• Verify remediation through rescanning and closure validation; track exceptions, deviations, and accepted risks through to resolution or formal acceptance.
• Automate recurring scanning, patching, reporting, and remediation workflows to reduce manual effort and improve consistency.
• Maintain vulnerability management processes and standard operating procedures, and maintain and report metrics for the function - remediation timeliness, aging, coverage, patch success and failure rates, and recurring problem areas.
• Prepare and present reports on vulnerability management activities to IT and senior management, communicating complex technical information to non-technical stakeholders.
• Stay current on emerging threats, actively exploited vulnerabilities, and vendor advisories, and recommend proactive measures.
• Other duties, as assigned. Experiences and Background We Look For:
• Active Top Secret clearance, with the ability to maintain it.
• Must have or be able to obtain a CompTIA Security+ CE certification within 120 days of employment, in accordance with DoDM 8140.03 and DFARS .
• Minimum of 3 years working as a System Administrator, Systems Engineer, Network Administrator, Vulnerability Analyst, or similar role.
• Proficient understanding of computer hardware, software, and operating systems - primarily Microsoft Windows Server and Red Hat Enterprise Linux - with strong system troubleshooting skills across both.
• Working knowledge of vulnerability scanning products such as Rapid7 (preferred), Tenable Security Center/Nessus (ACAS), or Qualys.
• Experience with patch management…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary