Risk and Vulnerability Analyst

PeratonWashington, DC
6d$80,000 - $128,000

About The Position

Peraton is currently seeking a Risk and Vulnerability Analyst. This role ensures continuous visibility, compliance, and timely remediation to reduce operational and mission risk. You will: Support 24x7 SOC operations by performing continuous vulnerability monitoring and risk analysis. Execute vulnerability assessments using industry-standard scanning tools across networks, systems, cloud, and APIs. Conduct cloud compliance, ISVM, and API security scanning, validating findings and false positives. Correlate vulnerability data with SOC alerts, threat intelligence, and active incidents. Automate vulnerability reporting, risk scoring, and remediation tracking workflows. Track and enforce remediation timelines in coordination with SOC, IR, and engineering teams. Ensure compliance with DHS 4300A, NIST SP 800-115, and CISA BOD 23-01 requirements. Provide operational risk summaries, metrics, and reports to SOC leadership and stakeholders.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Technology, or related field. An additional 4 years will be considered in lieu of the degree requirement.
  • Minimum of 2 years of experience in security operations, vulnerability management, or risk analysis.
  • Hands-on experience with industry vulnerability scanning tools, cloud compliance platforms, ISVM, and API scanning.
  • Experience supporting automation of vulnerability analysis and reporting.
  • Familiarity with DHS 4300A, NIST SP 800-115, and CISA BOD 23-01 compliance.
  • U.S. citizenship required.
  • Active Secret security clearance required.

Nice To Haves

  • 3-5 years of experience in security operations, vulnerability management, or risk analysis.

Responsibilities

  • Support 24x7 SOC operations by performing continuous vulnerability monitoring and risk analysis.
  • Execute vulnerability assessments using industry-standard scanning tools across networks, systems, cloud, and APIs.
  • Conduct cloud compliance, ISVM, and API security scanning, validating findings and false positives.
  • Correlate vulnerability data with SOC alerts, threat intelligence, and active incidents.
  • Automate vulnerability reporting, risk scoring, and remediation tracking workflows.
  • Track and enforce remediation timelines in coordination with SOC, IR, and engineering teams.
  • Ensure compliance with DHS 4300A, NIST SP 800-115, and CISA BOD 23-01 requirements.
  • Provide operational risk summaries, metrics, and reports to SOC leadership and stakeholders.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service