About The Position

The Risk and Vulnerability Threat Analyst I evaluates enterprise networks, systems, and applications to identify technical vulnerabilities and assess their impact on mission‑critical operations. This entry‑ to mid‑level role uses scanning tools, configuration reviews, and basic threat modeling to detect weaknesses, estimate risk, and support remediation planning in a highly regulated government environment. The analyst contributes to formal risk and vulnerability assessments, documenting findings and recommendations in clear terms for both technical and non‑technical stakeholders while aligning work to organizational cyber defense and compliance requirements.

Requirements

  • Bachelor’s Degree in Computer Science or a related field, or equivalent relevant experience.
  • Typically 2–4 years of hands‑on experience in cybersecurity, information security, or IT systems administration, including exposure to vulnerability assessment and risk analysis activities.
  • Demonstrated experience using vulnerability scanning tools and interpreting results to support remediation in an enterprise environment.
  • Ability to communicate technical findings, risk implications, and remediation recommendations clearly to both technical and non‑technical audiences in a structured, documentation‑driven environment.
  • Ability to obtain and maintain any required background investigation associated with supporting highly regulated government environments.
  • U.S. Citizenship.

Nice To Haves

  • Foundational security certification such as CompTIA Security+ or equivalent.
  • Intermediate cybersecurity certification such as CompTIA CySA+, CEH, or similar analysis or ethical‑hacking‑focused credential.
  • Experience supporting risk and vulnerability assessments in federal or other highly regulated government environments requiring U.S. citizenship.
  • Experience automating security or vulnerability‑management workflows using scripts, APIs, or BI/reporting tools.

Responsibilities

  • Conduct vulnerability scans of servers, endpoints, cloud workloads, and network devices using common assessment platforms (such as Nessus, Qualys, or OpenVAS) and interpret results to identify exploitable weaknesses.
  • Review system and network configurations, access controls, and patch levels against security baselines and policies, documenting deviations and articulating risk impact and likelihood in clear, actionable language.
  • Apply foundational risk analysis and threat modeling concepts to prioritize remediation activities based on asset criticality, exploitability, and current threat intelligence for mission‑critical systems.
  • Support formal risk and vulnerability assessments and audits by gathering technical evidence, validating findings, and contributing to structured reports and remediation recommendations suitable for highly regulated government environments.
  • Collaborate with security operations and infrastructure teams to track remediation tasks, verify closure of findings, and refine vulnerability management processes, SLAs, and metrics over time.
  • Utilize basic scripting or automation (for example, Python or PowerShell) to normalize, correlate, and summarize vulnerability data from multiple tools and repositories for dashboards and executive reporting.
  • Maintain awareness of emerging vulnerabilities, common exploitation techniques, and security best practices in order to advise on control improvements and defense‑in‑depth strategies.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service