Vulnerability Analyst
Listed on 2026-07-23
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Vulnerability Analyst
Location: Oak Ridge, TN
Career Level: Associate to Senior Specialist
Job Specialty: Cyber Security
What You'll DoThe Vulnerability Analyst is responsible for analyzing key data streams and interpreting threats, vulnerabilities, impacts, and likelihood of asset exposure. The aggregation of ingested data informs analysis with key identifiers to generate a holistic view of the enterprise and provide recommended mitigations and/or remediation of possible exploitable assets. The analyst also assists Vulnerability and Compliance Assessment Management with cyber analysis to support requested exception requests.
Responsible for cybersecurity assessment/analysis and provides recommendations for enterprise‑level systems and applications designs. Involved in a wide range of cybersecurity areas, including system architectures, firewalls, inspection and analysis tools, encryption components and networking architectures. Involved in security reporting and analysis to regulatory agencies.
- Identify systemic security issues based on the analysis of vulnerability and configuration data.
- Share meaningful insights about the context of an organization’s threat environment that improve its risk management posture.
- Apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, and non‑repudiation).
- Host/network access control mechanisms (e.g., access control list, capabilities lists).
- Conduct vulnerability scans and recognize vulnerabilities in security systems.
- Assess the robustness of security systems and designs.
- Detect host and network‑based intrusions via intrusion detection technologies (e.g., Snort).
- Ability to mimic threat behaviors.
- Support penetration testing tools and techniques.
- Use social engineering techniques (e.g., phishing, baiting, tailgating).
- Support network analysis tools to identify vulnerabilities (e.g., fuzzing, nmap).
- Review logs to identify evidence of past intrusions.
- Conduct application vulnerability assessments.
- Perform impact/risk assessments.
- Develop insights about the context of an organization’s threat environment.
- Analyze organization's cyber defense policies and configurations and evaluate compliance with regulations and organizational directives.
- Maintain knowledge of applicable cyber defense policies, regulations, and compliance documents specifically related to cyber defense auditing.
- Meaningful work and unique opportunities to support missions vital to national and global security.
- Top‑notch, dedicated colleagues.
- Generous pay and benefits with a stable organization.
- Career advancement and professional development programs.
- Work‑life balance fostered through flexible work options and wellness initiatives.
Job Requirements
- Bachelor's degree in engineering/science/information technology discipline.
- Master's degree in engineering/science/information technology discipline.
- Eight or more years of education and/or relevant experience may be considered to satisfy educational and years‑of‑experience requirements for this posting.
Job Requirements
- Knowledge of computer networking concepts and protocols, and network security methodologies.
- Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.
- Knowledge of cybersecurity threats and vulnerabilities.
- Knowledge of risk management processes (e.g., methods for assessing and mitigating risk).
- Knowledge of cryptography and cryptographic key management concepts.
- Knowledge of cybersecurity specific operational impacts of cybersecurity lapses.
- Knowledge of cybersecurity application vulnerabilities.
- Knowledge of network access, identity, and access management (e.g., public key infrastructure, Oauth, OpenID, SAML, SPML).
- Knowledge of how traffic flows across the network (e.g., TCP, IP, OSI, ITIL).
- Knowledge of programming language structures and logic.
- Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross‑site scripting, PL/SQL injections, race conditions, covert channel, replay, return‑oriented attacks,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).