Cyber Triage Analyst

Booz Allen HamiltonUsa, MD
$61,900 - $141,000Remote

About The Position

As a cybersecurity vulnerability analyst, you will support a Vulnerability Disclosure Program (VDP) within the federal government and be responsible for reviewing and vetting security vulnerability reports submitted to the DoD VDP from outside hackers. You will evaluate the reports to ensure the vulnerability is reproducible and therefore valuable to the customer. You will assess each vulnerability for severity and assign an associated risk statement. The HackerOne Triage console tool will be utilized to assist in assigning and prioritizing reports. It will also assist you in helping identify duplicate submissions. Valid reports will be written in a DoD approved format and sent to the Vulnerability Management Analyst team for system owner coordination and mitigation. You will be a VDP liaison with the hacker community.

Requirements

  • Experience operating in a professional IT or cybersecurity environment
  • Experience investigating security events, threats, or vulnerabilities
  • Knowledge of information security principles and practices
  • Knowledge of web exploitation concepts and techniques
  • Knowledge of the Open Web Application Security Project (OWASP) top 10
  • Knowledge of information security principles, technologies, and practices
  • Ability to utilize MITRE ATT&CK, CVSS, and NIST frameworks to assess vulnerability severity and risk impact
  • Secret clearance
  • HS diploma or GED and 9+ years of experience with vulnerability assessment, Bachelor’s degree and 5+ years of experience with vulnerability assessment, Master’s degree and 3+ years of experience with vulnerability assessment, or Doctorate degree
  • DoD IAT Level II Certification such as CompTIA Security+ Certification

Nice To Haves

  • Experience with multiple Hack-The-Box penetration testing labs and challenges, developing hands-on expertise in vulnerability enumeration, exploitation, privilege escalation, and post-exploitation techniques within realistic, adversarial environments
  • Experience in one or more programming languages
  • Experience in HTLM / CSS or SQL
  • Experience with one or more scripting languages such as PowerShell, Bash, Python or Perl
  • Knowledge of penetration testing methodology, including recon, exploit, or persistence
  • Knowledge of networking protocols, their uses, and their potential misuses
  • Possession of excellent customer service skills
  • Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, Information Systems, Software Engineering, or Data Science preferred; Master’s degree in Information Technology, Computer Science, Cybersecurity, Information Systems, Software Engineering, or Data Science a plus
  • CEH, CCNA-Security, CySA+, OSCP, PenTest+, or similar Certification

Responsibilities

  • Utilize offensive tool sets such as Kali Linux to safely analyze production networks and systems, documenting steps and procedures to produce usable vulnerability assessments for the customer.
  • Identify and investigate vulnerabilities, assess exploit potential, and document findings and remedies for presentation to facilitate mitigations on customer systems.
  • Conduct web application vulnerability assessment testing using both automated tools and manual web exploitation techniques, using tools such as Burp Suite and open-source toolsets.
  • Utilize a variety of industry standard security tools to conduct automated scans against systems and applications.
  • Develop and execute proof-of-concept exploits to demonstrate the real-world impact of identified vulnerabilities, utilizing various web exploitation methods.

Benefits

  • health, life, disability, financial, and retirement benefits
  • paid leave
  • professional development
  • tuition assistance
  • work-life programs
  • dependent care
  • recognition awards program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service