Cyber Vulnerability Assessment Analyst - Intermediate
Listed on 2026-09-22
-
IT/Tech
Cybersecurity
Job Description
POSITION SUMMARY
New Sat is seeking an Intermediate-level Vulnerability Assessment Analyst to support our U.S. Space Force (USSF) customer. This position performs vulnerability assessment and remediation-tracking activities across a platform spanning more than 42 deployed environments across approximately 900 servers at multiple classification levels.
Working with only periodic high-level guidance, the Intermediate VAA executes recurring and ad hoc assessments, validates findings, and supports remediation and continuous monitoring activities in non-routine and sometimes complicated situations. This role supports the task order’s Continuous Cyber Monitoring, Threat Assessment and Risk Mitigation, and Body of Evidence artifact management service areas.
KEY RESPONSIBILITIES- Execute scheduled and ad hoc vulnerability scans across the existing environment and during assessment of new connections using ACAS/Nessus and DoD-approved assessment tooling.
- Apply DISA STIGs and SCAP benchmarks; validate compliance results and research findings to confirm or dismiss false positives.
- Analyze scan output, correlate findings across environments, and document results in standardized assessment reports.
- Track remediation actions to closure with system owners; support POA&M entry, updates, and supporting evidence.
- Assemble Body of Evidence (BoE) artifacts supporting Certificate to Field (CtF), Authority to Connect (ATC) and continuous monitoring requirements.
- Support assessment of cloud and container workloads, including AWS tenant spaces and EKS-hosted services.
- Escalate complex, high-risk, or disputed findings to the Advanced VAA or Security Architect for adjudication.
- Maintain assessment documentation, scan configurations, and reporting cadence in accordance with program procedures.
- Active TS clearance with SCI eligibility; ability to meet program-directed access requirements.
- Minimum 4 years of cybersecurity experience with direct vulnerability assessment or vulnerability management responsibility.
- Security+ CE or equivalent DoD 8140 / 8570 baseline certification current at time of hire.
- Hands‑on experience with ACAS/Nessus or comparable scanning platforms and with STIG/SCAP compliance checking.
- Familiarity with RMF, NIST SP 800-53 control families, and POA&M processes.
- Ability to work non-routine assessment tasks with only periodic high‑level supervision.
- Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or a related field.
- Experience supporting DoD, IC, or space ground system programs.
- Certifications such as CySA+, CEH, GCIH, or GSEC.
- Exposure to containerized or cloud environments (Kubernetes/EKS, AWS).
- Scripting familiarity (Python, Power Shell, Bash) for reporting and data reduction.
New Sat provides cost-competitive, best-of-breed, global C5
ISR solutions to ensure mission success for our customers. Our small business provides solutions to many industry partners, both as a prime contractor and value‑added subcontractor.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).