Search

Cyber Vulnerability Assessment Analyst - Intermediate

PublishedPublished: 6/14/2022
Technology

Job Description

Job Description

POSITION SUMMARY

NewSat is seeking an Intermediate-level Vulnerability Assessment Analyst to support our U.S. Space Force (USSF) customer. This position performs vulnerability assessment and remediation-tracking activities across a platform spanning more than 42 deployed environments across approximately 900 servers at multiple classification levels.


Working with only periodic high-level guidance, the Intermediate VAA executes recurring and ad hoc assessments, validates findings, and supports remediation and continuous monitoring activities in non-routine and sometimes complicated situations. This role supports the task order’s Continuous Cyber Monitoring, Threat Assessment and Risk Mitigation, and Body of Evidence artifact management service areas.

KEY RESPONSIBILITIES

• Execute scheduled and ad hoc vulnerability scans across the existing environment and during assessment of new connections using ACAS/Nessus and DoD-approved assessment tooling.

• Apply DISA STIGs and SCAP benchmarks; validate compliance results and research findings to confirm or dismiss false positives.

• Analyze scan output, correlate findings across environments, and document results in standardized assessment reports.

• Track remediation actions to closure with system owners; support POA&M entry, updates, and supporting evidence.

• Assemble Body of Evidence (BoE) artifacts supporting Certificate to Field (CtF), Authority to Connect (ATC) and continuous monitoring requirements.

• Support assessment of cloud and container workloads, including AWS tenant spaces and EKS-hosted services.

• Escalate complex, high-risk, or disputed findings to the Advanced VAA or Security Architect for adjudication.

• Maintain assessment documentation, scan configurations, and reporting cadence in accordance with program procedures.

REQUIRED QUALIFICATIONS

• Active TS clearance with SCI eligibility; ability to meet program-directed access requirements.

• Minimum 4 years of cybersecurity experience with direct vulnerability assessment or vulnerability management responsibility.

• Security+ CE or equivalent DoD 8140 / 8570 baseline certification current at time of hire.

• Hands-on experience with ACAS/Nessus or comparable scanning platforms and with STIG/SCAP compliance checking.

• Familiarity with RMF, NIST SP 800-53 control families, and POA&M processes.

• Ability to work non-routine assessment tasks with only periodic high-level supervision.

PREFERRED QUALIFICATIONS

• Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or a related field.

• Experience supporting DoD, IC, or space ground system programs.

• Certifications such as CySA+, CEH, GCIH, or GSEC.

• Exposure to containerized or cloud environments (Kubernetes/EKS, AWS).

• Scripting familiarity (Python, PowerShell, Bash) for reporting and data reduction.

\nCompany Description

NewSat provides cost-competitive, best-of-breed, global C5ISR solutions to ensure mission success for our customers. Our small business provides solutions to many industry partners, both as a prime contractor and value-added subcontractor.

Company Description

NewSat provides cost-competitive, best-of-breed, global C5ISR solutions to ensure mission success for our customers. Our small business provides solutions to many industry partners, both as a prime contractor and value-added subcontractor.

Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...