HHS - Vulnerability Analyst

Remote, USA Full-time
cFocus Software seeks a Vulnerability Analyst to join our program supporting the Department of Health and Human Services (HHS) This position is remote. This position requires the ability a Public Trust clearance. Qualifications: • Bachelor’s degree in Cybersecurity, Information Technology, or related field. • Minimum 5–7 years of experience in vulnerability management or security operations. • Strong understanding of NIST SP 800-53, NIST SP 800-30, NIST SP 800-137, and HHS vulnerability management requirements. • Experience performing vulnerability scanning, analysis, and remediation tracking in federal environments. • Experience with secure configuration standards (DISA STIGs, CIS Benchmarks). • Strong analytical, documentation, and communication skills. • CEH, Security+, CISSP, GIAC (GSEC, GPEN), or equivalent cybersecurity certifications Duties: • Perform authenticated and unauthenticated vulnerability scans on a daily and ad hoc basis across servers, workstations, network devices, databases, web applications, APIs, containers, serverless functions, CI/CD pipelines, and Infrastructure as Code (IaC). • Analyze vulnerability scan results to determine applicability, severity, exploitability, and risk using CVSS scoring, threat intelligence, and Known Exploited Vulnerabilities (KEV) catalogs. • Provide daily remediation guidance and mitigation strategies to system owners, administrators, developers, and other stakeholders. • Maintain and ensure operational health of vulnerability scanning tools, including agents, sensors, integrations, and supporting infrastructure. • Coordinate with tool vendors, hosting teams, and network operations to troubleshoot and resolve tool-related issues. • Develop and maintain HRSA security configuration baselines using DISA STIGs and Center for Internet Security (CIS) benchmarks. • Perform compliance and configuration scans against approved baselines on a weekly, quarterly, and ad hoc basis. • Validate remediation through follow-up scans and evidence review and confirm closure of vulnerabilities. • Support penetration testing activities, including test planning, execution, exploitation, reporting, and coordination with stakeholders. • Conduct application security testing including SAST, DAST, software composition analysis, SBOM review, dependency scanning, and secure code analysis. • Support secure DevSecOps practices by integrating automated vulnerability testing into CI/CD pipelines and code repositories. • Develop vulnerability dashboards and reports for ISSOs, system owners, engineers, and DCSP leadership. • Maintain authoritative asset inventories and correlate data across vulnerability tools, CMDB, eGRC, and cloud inventories to ensure full scanning coverage. • Support Incident Response activities by providing vulnerability data, exploit analysis, and remediation recommendations. • Develop and maintain vulnerability management SOPs, workflows, and technical documentation. • Maintain SLAs for vulnerability scanning requests and remediation tracking Apply tot his job
Apply Now

Similar Jobs

QA Analyst, Enterprise Console

Remote, USA Full-time

Junior SEM Manager

Remote, USA Full-time

Manager, SEM

Remote, USA Full-time

SEM Specialist

Remote, USA Full-time

Tax and Consulting Senior Accountant job at Yeo & Yeo in Alma, MI

Remote, USA Full-time

Senior Creative Project Manager (Remote)

Remote, USA Full-time

Sr Coverage Counsel- Specialty (REMOTE)

Remote, USA Full-time

[Remote] Vice President, Corporate Controller

Remote, USA Full-time

Vice President / Senior Vice President, Business Development

Remote, USA Full-time

[Remote] Senior Accountant, Client Finance

Remote, USA Full-time

Sales Support Specialist – K&M Manufacturing – Renville, MN

Remote, USA Full-time

**Experienced Data Entry Specialist – Part Time Remote Position at arenaflex**

Remote, USA Full-time

Experienced Data Entry Specialist – Remote Work Opportunity for Career Growth and Development in E-commerce Industry at arenaflex

Remote, USA Full-time

Movies Features Writer Intern Unpaid Remote – Amazon Store

Remote, USA Full-time

**Senior Customer Experience Engineer – Cloud Application Development and Customer Obsession**

Remote, USA Full-time

Customer Service and Sales Representative Remot...

Remote, USA Full-time

Remote Disney Vacation Travel Specialist – Home‑Based Expert in Magical Trip Planning, Client Experience & Sales Excellence

Remote, USA Full-time

Experienced Full Stack Software Engineer – Web & Cloud Application Development

Remote, USA Full-time

District Manager

Remote, USA Full-time

Experienced Remote Customer Service Representative – Delivering Exceptional Support and Solutions from the Comfort of Your Own Home at blithequark

Remote, USA Full-time
Back to Home