ARS is seeking a highly skilled Cloud Vulnerability & Patch Analyst to support the continuous monitoring, assessment, patching and hardening of a modern DevSecOps cloud environment. The analyst will play a critical role in identifying, validating, and mitigating vulnerabilities across Azure-based infrastructure and containerized workloads while ensuring alignment with DoD Risk Management Framework (RMF) controls defined in NIST SP 800-53 Rev. 5 and the CMMC 2.0 requirements derived from NIST SP 800-171. This role will leverage enterprise-grade security tools, including ACAS, Tenable Nessus, Microsoft Defender for Cloud, and Microsoft Sentinel, to perform vulnerability scanning, log correlation, threat hunting, and compliance reporting. The analyst will also contribute to secure DevSecOps pipelines by integrating automated security checks, ensuring misconfigurations are addressed early, and maintaining hardened baselines consistent with DoD and industry cybersecurity best practices. In addition, the Cloud Vulnerability & Patch Analyst will help shape and enforce proactive cloud security strategies by analyzing threat intelligence, validating remediation actions, and collaborating with engineering teams to eliminate systemic risks. The role requires strong knowledge of Azure security architecture, cloud access control models, vulnerability lifecycle management, and the technical controls necessary for FedRAMP-high-equivalent and DoD cloud deployments. The analyst will be responsible for developing documentation, dashboards, and continuous improvement recommendations that enhance situational awareness and strengthen security posture. Ultimately, the position ensures that ARS’s cloud environment remains resilient, compliant, and aligned with the evolving landscape of DoD cybersecurity expectations and modern cloud security best practices.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level