HHS - Vulnerability Analyst

Remote Full-time
cFocus Software seeks a Vulnerability Analyst to join our program supporting the Department of Health and Human Services (HHS) This position is remote. This position requires the ability a Public Trust clearance. Qualifications: • Bachelor’s degree in Cybersecurity, Information Technology, or related field. • Minimum 5–7 years of experience in vulnerability management or security operations. • Strong understanding of NIST SP 800-53, NIST SP 800-30, NIST SP 800-137, and HHS vulnerability management requirements. • Experience performing vulnerability scanning, analysis, and remediation tracking in federal environments. • Experience with secure configuration standards (DISA STIGs, CIS Benchmarks). • Strong analytical, documentation, and communication skills. • CEH, Security+, CISSP, GIAC (GSEC, GPEN), or equivalent cybersecurity certifications Duties: • Perform authenticated and unauthenticated vulnerability scans on a daily and ad hoc basis across servers, workstations, network devices, databases, web applications, APIs, containers, serverless functions, CI/CD pipelines, and Infrastructure as Code (IaC). • Analyze vulnerability scan results to determine applicability, severity, exploitability, and risk using CVSS scoring, threat intelligence, and Known Exploited Vulnerabilities (KEV) catalogs. • Provide daily remediation guidance and mitigation strategies to system owners, administrators, developers, and other stakeholders. • Maintain and ensure operational health of vulnerability scanning tools, including agents, sensors, integrations, and supporting infrastructure. • Coordinate with tool vendors, hosting teams, and network operations to troubleshoot and resolve tool-related issues. • Develop and maintain HRSA security configuration baselines using DISA STIGs and Center for Internet Security (CIS) benchmarks. • Perform compliance and configuration scans against approved baselines on a weekly, quarterly, and ad hoc basis. • Validate remediation through follow-up scans and evidence review and confirm closure of vulnerabilities. • Support penetration testing activities, including test planning, execution, exploitation, reporting, and coordination with stakeholders. • Conduct application security testing including SAST, DAST, software composition analysis, SBOM review, dependency scanning, and secure code analysis. • Support secure DevSecOps practices by integrating automated vulnerability testing into CI/CD pipelines and code repositories. • Develop vulnerability dashboards and reports for ISSOs, system owners, engineers, and DCSP leadership. • Maintain authoritative asset inventories and correlate data across vulnerability tools, CMDB, eGRC, and cloud inventories to ensure full scanning coverage. • Support Incident Response activities by providing vulnerability data, exploit analysis, and remediation recommendations. • Develop and maintain vulnerability management SOPs, workflows, and technical documentation. • Maintain SLAs for vulnerability scanning requests and remediation tracking Apply tot his job
Apply Now

Similar Opportunities

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote Full-time

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote Full-time

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote Full-time

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote Full-time

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote Full-time

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote Full-time

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote Full-time

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote Full-time

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote Full-time

USPS Office Helper

Remote Full-time

Manager, Financial Planning - Remote

Remote Full-time

Experienced Virtual Assistant for Remote Teams - Full-Time Work from Home Opportunity with Walmart, Offering a Competitive Salary of $75,000 Per Year and Comprehensive Benefits Package

Remote Full-time

**Experienced Remote Data Entry Clerk – Flexible Part-Time Opportunity with Competitive Hourly Rate**

Remote Full-time

**Experienced Remote Customer Service Representative – Deliver Exceptional Guest Experiences from the Comfort of Your Own Home at arenaflex**

Remote Full-time

Production Associate, Model Y, Seats & Subassem...

Remote Full-time

Clinical Territory Associate

Remote Full-time

Customer Support Specialist

Remote Full-time

SAP MM with SAP MDG

Remote Full-time

Entry-Level Remote Data Entry Opportunities for Teens: Flexible and Supportive Career Start at blithequark

Remote Full-time

Senior Manager - Operations Governance & Effectiveness: Driving Business Excellence at American Express

Remote Full-time
← Back to Home