ASM Research

Risk and Vulnerability Threat Analyst I

ASM Research  •  United States (Remote)  •  6 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

The Risk and Vulnerability Threat Analyst I evaluates enterprise networks, systems, and applications to identify technical vulnerabilities and assess their impact on mission‑critical operations. This entry‑ to mid‑level role uses scanning tools, configuration reviews, and basic threat modeling to detect weaknesses, estimate risk, and support remediation planning in a highly regulated government environment. The analyst contributes to formal risk and vulnerability assessments, documenting findings and recommendations in clear terms for both technical and non‑technical stakeholders while aligning work to organizational cyber defense and compliance requirements.

Key Responsibilities

  • Conduct vulnerability scans of servers, endpoints, cloud workloads, and network devices using common assessment platforms (such as Nessus, Qualys, or OpenVAS) and interpret results to identify exploitable weaknesses.

  • Review system and network configurations, access controls, and patch levels against security baselines and policies, documenting deviations and articulating risk impact and likelihood in clear, actionable language.

  • Apply foundational risk analysis and threat modeling concepts to prioritize remediation activities based on asset criticality, exploitability, and current threat intelligence for mission‑critical systems.

  • Support formal risk and vulnerability assessments and audits by gathering technical evidence, validating findings, and contributing to structured reports and remediation recommendations suitable for highly regulated government environments.

  • Collaborate with security operations and infrastructure teams to track remediation tasks, verify closure of findings, and refine vulnerability management processes, SLAs, and metrics over time.

  • Utilize basic scripting or automation (for example, Python or PowerShell) to normalize, correlate, and summarize vulnerability data from multiple tools and repositories for dashboards and executive reporting.

  • Maintain awareness of emerging vulnerabilities, common exploitation techniques, and security best practices in order to advise on control improvements and defense‑in‑depth strategies.

Required Qualifications

  • Bachelor’s Degree in Computer Science or a related field, or equivalent relevant experience.

  • Typically 2–4 years of hands‑on experience in cybersecurity, information security, or IT systems administration, including exposure to vulnerability assessment and risk analysis activities.

  • Demonstrated experience using vulnerability scanning tools and interpreting results to support remediation in an enterprise environment.

  • Ability to communicate technical findings, risk implications, and remediation recommendations clearly to both technical and non‑technical audiences in a structured, documentation‑driven environment.

  • Ability to obtain and maintain any required background investigation associated with supporting highly regulated government environments.

  • U.S. Citizenship.

Preferred Qualifications

  • Foundational security certification such as CompTIA Security+ or equivalent.

  • Intermediate cybersecurity certification such as CompTIA CySA+, CEH, or similar analysis or ethical‑hacking‑focused credential.

  • Experience supporting risk and vulnerability assessments in federal or other highly regulated government environments requiring U.S. citizenship.

  • Experience automating security or vulnerability‑management workflows using scripts, APIs, or BI/reporting tools.

Qualifications

Compensation Ranges

Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.

EEO Requirements

It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.

All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment.

Physical Requirements

The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, "light office duties' or "lifting up to 50 pounds" or "some travel" required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions.

Disclaimer

The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.

ASM Research

About ASM Research

ASM Research, an Accenture Federal Services Company, is an information solutions integrator and a leading provider of innovative technology solutions and advanced analytical services for the Federal government. Headquartered in Fairfax, Virginia, ASM has over 30 years of experience providing application, software, system, network, database, and reporting solutions. Our extraordinary commitment and unique insight into clients’ information technology (IT), program management, security, healthcare / medical management, education and training management consistently produce extraordinary results.

We are always seeking quality individuals to join our team. We offer an employee-friendly work environment, outstanding benefits, and a level of stability rarely found in the government contracting world. We have ongoing needs for Web Applications Developers (ASP.Net), SharePoint Developers, Cyber Security Analysts, QA Analysts, Helpdesk Analysts and Oracle DBAs. You can see a full list of our current openings at http://asmr.com/Opportunities.aspx or send your resume to hr@asmr.com. You can also connect with our corporate recruiter, Chris Gibbons, http://www.linkedin.com/pub/chris-gibbons/0/635/213 or Erik Thompson, https://www.linkedin.com/in/erikthompsonitt.

Privacy Policy: https://www.asmr.com/privacy-policy/

Industry
IT & Software
Company Size
1,001-5,000 employees
Headquarters
Fairfax, Virginia
Year Founded
1978
Website
asmr.com
Social Media