Vulnerability Management Analyst II

Chenega CorpRedstone Arsenal, AL
Onsite

About The Position

Chenega Military, Intelligence & Operations Support (MIOS) is seeking a Vulnerability Management Specialist II to support cyber defense analysis and remediation tracking across enterprise systems. This entry-to-mid level role assists in analyzing results and coordinating basic remediation activities under the guidance of senior team members. The specialist contributes to reporting, tool maintenance, and stakeholder coordination to ensure timely and accurate vulnerability management.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science or related field with 3+ years of experience in vulnerability tracking and reporting, with 2+ years in IT or cybersecurity roles OR Master’s degree in Cybersecurity, Information Technology, Computer Science or related field with 1+ years of experience in vulnerability tracking and reporting.
  • Certifications: Security +
  • Must have active Top Secret Clearance with SCI eligibility.
  • Successfully pass background and drug screening
  • Foundational IT & OS: Basic understanding of networking fundamentals (TCP/IP, common ports/protocols) and core OS environments (Windows and Linux).
  • Cybersecurity Frameworks: Basic understanding of DoD vulnerability management processes (DoDI 8530.01, NIST SP 800-40, CJCSM 6510.01B)
  • Vulnerability Standards: Familiarity with DoD vulnerability management concepts (IAVA/IAVM process, CVEs, CVSS scoring).
  • Working knowledge of DoD vulnerability scanning and compliance management tools, including ACAS (Tenable Security Center / Nessus), SCAP Compliance Checker (SCC), and eMASS.
  • Data & Office Tools: Working proficiency in Microsoft Excel (data sorting, filtering, basic formulas) for metrics and status tracking
  • Scanning Platforms: Familiarity with vulnerability scanning platforms such as Tenable Nessus or ACAS
  • Ability to meet minimum clearance requirements.
  • Ability to work nights, weekends, and holidays on occasion.

Nice To Haves

  • Additional Cyber related certifications (CSSP Analyst / Infrastructure Support (CEH, GCIA, GCIH)
  • 6–12 months of prior IT helpdesk, system administration, or SOC experience.
  • Familiarity with DISA STIGs and SCAP compliance validation tools.
  • OT/ICS Experience: Familiarity with Industrial Control Systems (ICS), Operational Technology (OT), or specialized monitoring tools (e.g., Dragos).
  • Hands-on experience with DISA ACAS (Tenable SecurityCenter/Nessus), SCAP compliance validation tools (SCC), and eMASS package maintenance.
  • Exposure to DoD cybersecurity frameworks and RMF processes preferred.
  • Experience supporting POA&M documentation and audit preparation preferred.

Responsibilities

  • Assist in reviewing basic scan outputs, filtering known false-positives against baseline configurations, and escalating anomalies per established SOPs
  • Assist in scheduling and executing vulnerability scans using tools such as Nessus, Tenable, or other approved platforms.
  • Collect asset compliance data, missing patch reports, and endpoint scan diagnostics for senior analyst review.
  • Document daily scanning and tracking status in ticketing/tracking registers and support regular team status briefings.
  • Perform data entry and generate reports using Gabriel Nimbus, Foundry/Vantage, Excel and other reporting tools.
  • Coordinate with stakeholders to support remediation activities and ensure timely resolution.
  • Contribute to audit responses and documentation efforts as directed by senior staff.
  • Stay current with emerging threats, vulnerabilities, and mitigation strategies.
  • Assist in ingesting operational taskings (e.g., CTOs, OPORDs, FRAGOs, TASKORDs, IAVMs) into central tracking registers.
  • Coordinate with system administrators and network engineering teams to gather evidence of remediation and mitigation implementation.
  • Cross-reference scheduled Authorized Service Interruptions (ASIs) and maintenance windows to schedule and deconflict active vulnerability scanning.
  • Support priority mitigation workflows and track emergency patching actions associated with critical Zero-Day/IAVA taskings.
  • Other duties as assigned

Benefits

  • professional development is embedded in their employer’s core culture
  • opportunities to help sharpen skills in addition to hands-on experience in the global, fast-changing business world
  • on-the-job learning experiences
  • formal development programs
  • well-being programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service