Vulnerability Management Analyst
Quick Summary
Perform vulnerability assessments and analysis across NIH information systems and infrastructure. Perform threat-informed prioritization using exploitability, threat intelligence,
Perform vulnerability assessments and analysis across NIH information systems and infrastructure. Perform threat-informed prioritization using exploitability, threat intelligence,
Responsibilities
~1 min read- →Perform vulnerability assessments and analysis across NIH information systems and infrastructure.
- →Perform threat-informed prioritization using exploitability, threat intelligence, CISA Known Exploited Vulnerabilities (KEV), mission criticality, system exposure, and compensating controls.
- →Assess vulnerability risk within the context of system criticality, data sensitivity, and organizational risk tolerance.
- →Develop vulnerability dashboards, remediation metrics, trend analyses, and executive reporting products.
- →Review and analyze vulnerability scan results from enterprise security tools.
- →Validate findings to determine severity, exploitability, and potential impact.
- →Conduct risk-based prioritization of vulnerabilities and security weaknesses.
- →Coordinate with technical teams to assess remediation requirements and timelines.
- →Manage the full lifecycle of vulnerability identification, remediation, and closure.
- →Track vulnerabilities from discovery through remediation and validation.
- →Maintain vulnerability repositories, remediation records, and status reporting.
- →Monitor remediation progress and escalate overdue findings as appropriate.
- →Verify corrective actions and document closure activities.
- →Support continuous monitoring activities across NIH systems and applications.
- →Analyze vulnerability trends and identify recurring issues.
- →Evaluate security risks associated with discovered vulnerabilities.
- →Collaborate with RMF/A&A teams to support Authorization to Operate (ATO) activities.
- →Assist with the management and tracking of Plans of Action and Milestones (POA&Ms).
- →Provide vulnerability-related evidence and documentation for audits, assessments, and authorization activities.
Requirements
~3 min read- Minimum 5 years of experience in cybersecurity, vulnerability management, information assurance, or security operations supporting Federal environments.
- Experience supporting POA&M development, remediation tracking, corrective action validation, or vulnerability closure activities.
- Experience conducting vulnerability assessments and remediation tracking.
- Familiarity with:
- NIST RMF (SP 800-37)
- NIST SP 800-53 Rev. 5
- FISMA
- Federal cybersecurity compliance requirements
- Risk assessment methodologies
- Experience analyzing vulnerability data and developing remediation recommendations.
- Strong analytical, problem-solving, and communication skills.
- Ability to obtain and maintain an NIH Public Trust.
- One or more of the following certifications:
-
- Security+
- Certified Ethical Hacker (CEH)
- CISSP
- GIAC Vulnerability Assessment (GVA)
- GIAC Information Security Fundamentals (GISF)
- GSEC
- CAP (Certified Authorization Professional)
- CISM
- CRISC
- Experience supporting NIH, HHS, or other Federal civilian agencies.
- Experience working within FISMA-compliant environments.
- Knowledge of cloud security and vulnerability management practices.
- Experience supporting continuous diagnostics and mitigation (CDM) initiatives.
- Understanding of FedRAMP and Zero Trust security principles.
- Experience coordinating remediation activities across multiple stakeholders.
About Copper River & The Native Village of Eyak:
Owned by the Native Village of Eyak (NVE), a federally recognized Alaska Native Tribe, the Copper River Family of Companies are a collection of entities that deliver a complementary set of solutions and services to support the diverse missions and requirements of our clients. Proud participants of the Small Business Administration’s (SBA) 8(a) Business Development Program since 2006, our companies consist of both current and graduation SBA 8(a) entities. It is our collective purpose to support the Tribe and diversify the NVE’s ability to facilitate economic advancement.
The income generated from our companies helps the Native Village of Eyak fund health and social services, economic development, natural resource/environmental education, jobs, job training, and other benefits to the NVE in a manner that is consistent with Alaskan Native cultural values and traditions.
Copper River’s Culture
The Copper River Family of Companies has a positive, supportive, and thriving culture. At the foundation of our culture is a focus on collaboration. No matter your role or which operating company you work for, we are ONE TEAM working toward the same goals for our customers and for our collective owner- The Native Village of Eyak. How we treat each other is just as important as the work we deliver.
Benefits
- Comprehensive medical, dental, and vision coverage
- Flexible Spending Account - healthcare and dependent care
- Health Savings Account - high deductible medical plan
- Retirement 401(k) with employer match
- Open leave policy and paid holidays
- Additional benefits including tuition reimbursement, transportation expense account, employee assistance program, and more!
Note: Benefits are offered based on employment classification and applicable contract requirements. Eligibility may vary by position.
Disclaimer:
The Copper River Family of Companies provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws.
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field
Location & Eligibility
Listing Details
- Posted
- August 12, 2026
- First seen
- August 13, 2026
- Last seen
- August 13, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 80%
- Scored at
- August 13, 2026
Signal breakdown
Please let Crfamilyofcompanies know you found this job on Jobera.
3 other jobs at Crfamilyofcompanies
View all →Explore open roles at Crfamilyofcompanies.
Similar Vulnerability Management Analyst jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.