Find Jobs
Find Jobs Near You – Available Work in Your Location
Vulnerability Management
Career Insights for Vulnerability Analyst / Penetration Tester
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Maryland data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Vulnerability Analyst or Penetration Tester probes for and exploits security vulnerabilities in web-based applications, networks and systems. Penetration Tests are designed to achieve a specific, attacker-simulated goal and should be requested by customers who are already at their desired security posture. A typical goal could be to access the contents of the prized customer database on the internal network, or to modify a record in an HR system. Vulnerability Assessments are designed to yield a prioritized list of vulnerabilities and are generally for clients who already understand they are not where they want to be in terms of security. The customer already knows they have issues and simply need help identifying and prioritizing them.
$121,766 / year median in Maryland
+3% projected growth
Job Description
NIST SP 800-53
Technical documentation DoD 8570 Vulnerability managementIAT RMF IAT
Level II IT risk management Full Job Description We are seeking a Vulnerability Management to join our team supporting at Joint Base Andrews, MD. Vulnerability Management to support the Air Force National Capital Region IT Services program. TheAFNCR IT
Services program provides support services for information systems for Headquarters Air Force (HAF), Air Force District of Washington (AFDW), Office of the Secretary of Defense (OSD), Joint Chiefs of Staff, and other Air Force activities within the AFNCR, missions to include the Pentagon, Joint Base Andrews (JBA), Joint Base Anacostia-Bolling (JBAB), and other locations, leased spaces, and alternate sites. The major support areas required are IT Operations and Maintenance; Plans, Projects, and Engineering and National Military Command Center (NMCC). TekSynap is a fast-growing high-tech company that understands both the pace of technology today and the need to have a comprehensive well planned information management environment. "Technology moving at the speed of thought" embodies these principles - the need to nimbly utilize the best that information technology offers to meet the business needs of our Federal Government customers. We offer our full-time employees a competitive benefits package to include health, dental, vision, 401K, life insurance, short-term and long-term disability plans, vacation time and holidays. Visit us at www.TekSynap.com. Apply now to explore jobs with us! The safety and health of our employees is of the utmost importance. Employees are required to comply with any vaccination requirements mandated by contract, applicable law or regulation. By applying to a role at TekSynap you are providing consent to receive text messages regarding your interview and employment status. If at any time you would like to opt out of text messaging, respond "STOP". As part of the application process, you agree that TekSynap Corporation may retain and use your name, e-mail, and contact information for purposes related to employment consideration.
RESPONSIBILITIES
Manage the POAM process for Vulnerabilities and STIG violations. Analyze scan results to identifyCAT I/II/III
findings, false positives, and configuration errors. Track and document remediation actions, POA&Ms, and exceptions in alignment with RMF guidance. Validate and interpretDISA STIG
checklists, collaborate with system admins and engineers to ensure secure configurations. Prepare and deliver vulnerability reports, compliance dashboards, and metrics for leadership and inspection readiness (e.g., CCRI/CORA). Support the development and maintenance of asset groupings, scan zones, credentialed scanning, and scan tuning strategies. Work closely with Queue Managers, ISSOs, and Engineering teams to prioritize and close critical vulnerabilities. Maintain data hygiene within ACAS, ensuring consistent tagging, grouping, and reporting structures.REQUIRED QUALIFICATIONS
Active DoD Secret clearance required. CompTIA Security+CE or higher DoD 8570 IAT Level II certification must meet 8140 ISSM role qualification. Bachelors Degree and 2-4 years of experience. Additional years of experience or certifications may be considered in lieu of a degree. 3 years of cybersecurity or system administration experience, with at least 1 year of direct ACAS or Tenable experience. Working knowledge of DISA STIGs, vulnerability risk levels, and POA&M remediation strategies.Familiarity with
NIST SP 800-53, RMF
compliance, and Air Force cybersecurity policy (AFMAN 17-130). Strong attention to detail, documentation skills, and the ability to interpret technical vulnerability data.PREFERRED QUALIFICATIONS
Experience supporting USAF, DISA, or other DoD mission systems.Familiarity with