See all roles

[Remote] Vulnerability Management Analyst

Work from home Full-time role Hiring

Note: The job is a remote job and is open to candidates in USA. Dragonfli Group is an award-winning cybersecurity advisory firm that provides high-impact security solutions to federal agencies and enterprise clients. The Senior Vulnerability Management Analyst will own and operate vulnerability management programs for a large federal client, leading scanning operations and managing stakeholder relationships while driving remediation efforts to closure.

Responsibilities

  • Lead and manage end-to-end vulnerability disclosure programs (VDP), including coordination with ethical hackers, system owners, and agency stakeholders
  • Own attack surface management programs (e.g., CISA FAST), including scheduling, scope management, findings coordination, and POA&M documentation
  • Manage and update Standard Operating Procedures (SOPs), SharePoint repositories, and program tracking documentation
  • Lead recurring stakeholder syncs (weekly vulnerability management meetings, DMZ syncs, Security Report presentations)
  • Operate and maintain enterprise vulnerability scanning platforms including Tenable.sc, Tenable.io, and web application scanning tools (OpenText ScanCentral or equivalent)
  • Scope, schedule, execute, and report on vulnerability scans across large, complex federal environments
  • Analyze scan results to identify critical and high-severity findings; triage false positives; prioritize remediation activities
  • Manage hardware/software certification pipelines; process ServiceNow tickets within defined SLAs
  • Support transition from legacy tools to modernized scanning platforms with minimal operational disruption
  • Track and drive remediation of critical, high, and all severity-tiered vulnerabilities to closure within program SLAs
  • Maintain accurate POA&M records for all open findings across program scope
  • Produce and present vulnerability dashboards, compliance reports, and executive-level status briefings
  • Validate remediation effectiveness through post-remediation scanning and analysis
  • Monitor HTTPS/HSTS compliance and other BOD requirements (BOD 18-01, BOD 20-01, and others as applicable)
  • Build and maintain working relationships with CISA contacts, agency system owners, SOC personnel, and contractor teams
  • Communicate vulnerability risks and remediation recommendations clearly to both technical and non-technical audiences
  • Serve as subject matter expert and primary point of contact for assigned programs
  • Provide backfill coverage across vulnerability management workstreams as needed

Skills

  • 3+ years of hands-on vulnerability management experience within a federal agency environment
  • Demonstrated program ownership: VDP, attack surface management, or equivalent independently managed programs
  • Proficiency with Tenable.sc and/or Tenable.io (scan configuration, report generation, false positive management)
  • Experience with CISA programs (VDP, FAST, BOD compliance) or equivalent federal cybersecurity initiatives
  • Working knowledge of ServiceNow or equivalent ITSM platforms for ticket management
  • Ability to produce clean, accurate SOPs, POA&Ms, and stakeholder-facing documentation
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or equivalent practical experience
  • Active security clearance or eligibility to obtain one preferred
  • Experience operating WebInspect, OpenText ScanCentral, or equivalent DAST/web application scanning tools
  • Familiarity with Bugcrowd or other managed bug bounty platforms
  • Experience with HSTS/HTTPS compliance monitoring aligned to BOD 18-01
  • Active certifications: Security+, CEH, CISSP, CISM, or Certified Vulnerability Assessor (CVA)
  • Experience leading or co-leading standing meetings with federal stakeholders

Benefits

  • Health, Dental, and Vision Insurance
  • PTO
  • 401(k)
  • Remote work flexibility
  • Exposure to high-impact federal cybersecurity programs
  • Direct access to firm leadership and career development opportunities

Company Overview

  • The Dragonfli Group is a Washington, DC based LLC specializing in management and technology consulting. It was founded in 2008, and is headquartered in Washington, District of Columbia, USA, with a workforce of 11-50 employees. Its website is https://www.dragonfligroup.com/.
  • Apply To This Job

    You might like

    [Remote] Account Coordinator

    Work from home Full-time role

    [Remote] Automotive Digital Marketing Sales Executive (REMOTE)

    Work from home Full-time role

    [Remote] Data Analytics & Engineering - Data Analyst IV-Remote

    Work from home Full-time role

    [Remote] Loss Prevention Safety Operations Coordinator - The Langham, Pasadena

    Work from home Full-time role

    [Remote] Vice President of Channel Sales

    Work from home Full-time role

    [Remote] Creative Director, Experiential Marketing

    Work from home Full-time role

    [Remote] Growth Marketing Manager

    Work from home Full-time role

    [Remote] Full Stack Engineer

    Work from home Full-time role

    [Remote] Enterprise Account Executive

    Work from home Full-time role

    [Remote] Human Resources Operations Specialist - Remote

    Work from home Full-time role

    Integrated Justice Architect - Government Sector - Manager - Consulting - Location Open

    Work from home Full-time role

    [Remote] IT Support Analyst (West Coast)

    Work from home Full-time role

    Remote Jobs Product Tester at Amazon

    Work from home Full-time role

    SIU Investigator I - P&C

    Work from home Full-time role

    Psychiatric Mental Health Nurse Practitioner

    Work from home Full-time role

    SAS in Food Lion - Traveling Reset Merchandiser in Burlington, NC

    Work from home Full-time role

    Audiologist - 1099 Contract

    Work from home Full-time role

    SAP BASIS SERVER MANAGEMENT ADMIN (REMOTE) (Mexico, MEX, MX)

    Work from home Full-time role

    Power BI Developer/Lead Analytics Consultant

    Work from home Full-time role

    Remote Contract Children's Piano Teacher

    Work from home Full-time role