Enter a job title or keyword

Vulnerability Analyst II


Job Location:

Washington, DC - USA

Monthly Salary: Not provided by the employer
Posted: 17 July 2026 (30+ days ago)
Application Deadline: 14 October 2026
Vacancies: 1 Vacancy

Job Summary

Koniag Data Solutions LLC a Koniag Government Services company is seeking a Vulnerability Analyst II to support KDS and our government customer in Washington DC. This position requires the candidate to be able to obtain a Public offer competitive compensation and an extraordinary benefits package including health dental and vision insurance 401K with company matching flexible spending accounts paid holidays three weeks paid time off and Data Solutions a Koniag Government Services company is seeking a skilled and experienced Vulnerability Analyst II to support the U.S. Small Business Administration (SBA). The ideal candidate is a mid-level cybersecurity professional with solid experience in vulnerability management security assessment and risk analysis within federal government IT environments. This individual will play a key role in identifying analyzing and tracking vulnerabilities across SBAs enterprise IT environment working closely with system owners IT operations teams and the broader cybersecurity program to ensure timely and effective remediation of security weaknesses and maintenance of a strong security Vulnerability Analyst II will serve as a mid-level vulnerability management professional responsible for conducting vulnerability assessments analyzing scan results tracking remediation activities and supporting the continuous improvement of SBAs vulnerability management program. Principal responsibilities will include but are not limited to:Plan configure and execute vulnerability scans across SBAs enterprise IT environment including network infrastructure servers workstations web applications databases and cloud-hosted assets using enterprise vulnerability scanning platforms such as Tenable Nessus Qualys or equivalent and interpret vulnerability scan results applying knowledge of common vulnerability scoring systems (CVSS) exploit availability asset criticality and threat context to accurately assess the real-world risk posed by identified vulnerabilities and prioritize remediation activities and maintain comprehensive vulnerability management reports dashboards and metrics providing SBA leadership system owners and IT operations teams with clear visibility into the current vulnerability posture remediation progress and trending risk levels across SBAs enterprise with system owners IT operations teams and application teams to communicate identified vulnerabilities provide technical remediation guidance track remediation activities and validate the effectiveness of applied patches configuration changes and the development and maintenance of SBAs vulnerability management program documentation including vulnerability management policies procedures scanning methodologies and remediation tracking processes ensuring alignment with NIST SP 800-40 federal vulnerability management guidance and CISA BODs and in the integration of vulnerability management activities with SBAs POA&M program ensuring identified vulnerabilities are accurately documented tracked and reported within the POA&M framework in accordance with FISMA and SBA security configuration compliance assessments using security configuration baselines such as CIS Benchmarks and DISA STIGs identifying configuration weaknesses and deviations from approved baselines across SBAs system portfolio and coordinating remediation activities with IT operations the assessment and documentation of vulnerability risk exceptions and remediation deadline extension requests evaluating the technical justification and compensating controls proposed by system owners and preparing risk acceptance documentation for review by senior security and analyze vulnerability and threat intelligence from government and commercial sources including CISA KEV (Known Exploited Vulnerabilities) catalog NVD US-CERT advisories and commercial threat intelligence feeds to identify emerging vulnerabilities and active exploit campaigns relevant to SBAs technology environment and prioritize response activities with the SOC team to correlate vulnerability data with threat intelligence and active security monitoring findings supporting a risk-informed approach to vulnerability prioritization and enabling more effective detection and response to exploitation penetration testing activities by providing vulnerability data scan results and asset inventory information to support scoping and planning of penetration test engagements and assisting in the validation of penetration test findings against known vulnerability in the development and maintenance of SBAs asset inventory and asset management program ensuring accurate and current records of SBAs IT assets system configurations and software inventory to support comprehensive vulnerability scanning coverage and risk and deliver vulnerability management briefings status reports and technical presentations to SBA stakeholders clearly communicating vulnerability findings remediation status risk levels and program performance vulnerability management activities for cloud-hosted assets and services including the configuration and execution of cloud vulnerability scans and the assessment of cloud-specific security misconfigurations and vulnerabilities across AWS Azure and/or GCP to the continuous improvement of SBAs vulnerability management program identifying opportunities to enhance scanning coverage remediation tracking efficiency reporting quality and overall program and Experience:Required:Bachelors degree in Cybersecurity Information Technology Computer Science or a related field from an accredited college or university.3 years of progressive experience in vulnerability management security assessment or a closely related cybersecurity field with demonstrated hands-on experience conducting vulnerability assessments and supporting vulnerability management programs within a federal government or large enterprise IT experience using enterprise vulnerability scanning platforms such as Tenable Nessus Qualys or equivalent tools to conduct vulnerability assessments across diverse IT or more of the following certifications:CompTIA SecurityCompTIA CySAGIAC Security Essentials (GSEC)Tenable Certified Security Engineer (TCSE) or CertificationCertified Information Systems Security Professional (CISSP)GIAC Certified Enterprise Defender (GCED)Desired:5 years of vulnerability management experience with a strong background supporting federal civilian agency vulnerability management experience supporting SBA or other federal civilian agency vulnerability management Ethical Hacker (CEH) or equivalent offensive security certification demonstrating foundational penetration testing Skills and Competencies:Strong communication skills in English both written and oral with the ability to clearly communicate vulnerability findings risk assessments remediation recommendations and program status to diverse audiences including technical staff system owners program managers and senior SBA hands-on experience planning configuring and executing vulnerability scans across diverse IT environments using enterprise vulnerability scanning platforms with demonstrated ability to interpret scan results accurately and assess real-world vulnerability understanding of common vulnerability scoring systems including CVSS v3.x and the ability to apply CVSS scores in conjunction with threat context asset criticality and exploit availability to develop risk-informed vulnerability prioritization of common vulnerability types affecting enterprise IT environments including operating system vulnerabilities application vulnerabilities web application vulnerabilities network device vulnerabilities database vulnerabilities and cloud service conducting configuration compliance assessments using CIS Benchmarks DISA STIGs and other security configuration baselines with the ability to identify configuration weaknesses and develop practical remediation with federal vulnerability management frameworks guidelines and compliance requirements including NIST SP 800-40 NIST SP 800-53 FISMA and applicable CISA BODs and EDs governing vulnerability management and patch management developing vulnerability management reports dashboards and metrics that effectively communicate vulnerability posture remediation progress and risk trends to diverse stakeholder to coordinate effectively with system owners IT operations teams and application teams to communicate vulnerability findings provide remediation guidance track remediation progress and validate remediation with POA&M management concepts and experience supporting the integration of vulnerability management findings into POA&M tracking and reporting processes within a federal government of patch management concepts and processes including an understanding of common patching tools and methodologies used in enterprise IT environments to remediate identified familiarity with threat intelligence concepts and the ability to incorporate vulnerability-relevant threat intelligence including the CISA KEV catalog and NVD data into vulnerability prioritization and remediation planning organizational skills and attention to detail with the ability to manage multiple concurrent vulnerability assessment and remediation tracking activities accurately and efficiently in a fast-paced federal to obtain and maintain a Public Trust Skills and Competencies:Prior experience supporting SBA or other federal civilian agency vulnerability management programs with demonstrated knowledge of agency-specific vulnerability management processes tools and reporting conducting vulnerability assessments and configuration compliance assessments for cloud-hosted assets and services in AWS Azure or GCP environments including familiarity with cloud-native security assessment tools and cloud-specific vulnerability types and with web application vulnerability assessment concepts and tools including OWASP Top 10 vulnerability categories and basic web application scanning tools such as Burp Suite OWASP ZAP or with vulnerability management automation including proficiency in scripting languages such as Python or PowerShell for automating scan scheduling result parsing reporting and remediation tracking of the CDM (Continuous Diagnostics and Mitigation) program tools and data requirements and the integration of CDM vulnerability management capabilities into agency vulnerability management with asset management and asset discovery tools and their integration with vulnerability management platforms to ensure comprehensive scanning coverage across complex enterprise IT with container and Kubernetes security assessment concepts including common container vulnerabilities and misconfigurations and tools used to assess container image and runtime supporting FedRAMP authorized cloud environments and familiarity with FedRAMP vulnerability scanning requirements and continuous monitoring obligations as they apply to cloud-hosted systems and of supply chain risk management (SCRM) concepts and their relationship to vulnerability management including awareness of software bill of materials (SBOM) concepts and their application in identifying and managing software supply chain with threat modeling methodologies and their application in informing vulnerability prioritization and risk assessment activities within a federal agency vulnerability management developing and delivering vulnerability management training materials and briefings to system owners IT operations staff and other stakeholders to build organizational awareness and capability in vulnerability remediation and risk Equal Employment Opportunity PolicyThe company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race color religion creed ethnicity sex sexual orientation gender or gender identity (except where gender is a bona fide occupational qualification) national origin or ancestry age disability citizenship military/veteran status marital status genetic information or any other characteristic protected by applicable federal state or local law. We are committed to equal employment opportunity in all decisions related to employment promotion wages benefits and all other privileges terms and conditions of company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website please get in touch with Heaven Wood via e-mail by calling to request Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical professional and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers employees and native communities. For more information please Opportunity Employer/Veterans/ Preference in accordance with Public Law 88-352

Required Experience:

IC


About Company

Company Logo

What We Do Koniag Government Services (KGS) is an Alaska Native Corporation comprised of multiple wholly owned subsidiary companies that deliver Enterprise Solutions, Professional Services, and Operations Management to Federal Government agencies. With an agile employee and corporate ... View more

View Profile View Profile