The Risk and Vulnerability Threat Analyst I evaluates enterprise networks, systems, and applications to identify technical vulnerabilities and assess their impact on mission?critical operations. This entry? to mid?level role uses scanning tools, configuration reviews, and basic threat modeling to detect weaknesses, estimate risk, and support remediation planning in a highly regulated government environment. The analyst contributes to formal risk and vulnerability assessments, documenting findings and recommendations in clear terms for both technical and non?technical stakeholders while aligning work to organizational cyber defense and compliance requirements.
**Key Responsibilities**
+ p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Conduct vulnerability scans of servers, endpoints, cloud workloads, and network devices using common assessment platforms (such as Nessus, Qualys, or OpenVAS) and interpret results to identify exploitable weaknesses.
+ p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Review system and network configurations, access controls, and patch levels against security baselines and policies, documenting deviations and articulating risk impact and likelihood in clear, actionable language.
+ p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Apply foundational risk analysis and threat modeling concepts to prioritize remediation activities based on asset criticality, exploitability, and current threat intelligence for mission?critical systems.
+ p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Support formal risk and vulnerability assessments and audits by gathering technical evidence, validating findings, and contributing to structured reports and remediation recommendations suitable for highly regulated government environments.
+ p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Collaborate with security operations and infrastructure teams to track remediation tasks, verify closure of findings, and refine vulnerability management processes, SLAs, and metrics over time.
+ p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Utilize basic scripting or automation (for example, Python or PowerShell) to normalize, correlate, and summarize vulnerability data from multiple tools and repositories for dashboards and executive reporting.
+ p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Maintain awareness of emerging vulnerabilities, common exploitation techniques, and security best practices in order to advise on control improvements and defense?in?depth strategies.
**Required Qualifications**
+ p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Bachelor's Degree in Computer Science or a related field, or equivalent relevant experience.
+ p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Typically 2-4 years of hands?on experience in cybersecurity, information security, or IT systems administration, including exposure to vulnerability assessment and risk analysis activities.
+ p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Demonstrated experience using vulnerability scanning tools and interpreting results to support remediation in an enterprise environment.
+ p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Ability to communicate technical findings, risk implications, and remediation recommendations clearly to both technical and non?technical audiences in a structured, documentation?driven environment.
+ p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Ability to obtain and maintain any required background investigation associated with supporting highly regulated government environments.
+ p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> U.S. Citizenship.
**Preferred Qualifications**
+ p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Foundational security certification such as CompTIA Security+ or equivalent.
+ p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Intermediate cybersecurity certification such as CompTIA CySA+, CEH, or similar analysis or ethical?hacking?focused credential.
+ p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Experience supporting risk and vulnerability assessments in federal or other highly regulated government environments requiring U.S. citizenship.
+ p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Experience automating security or vulnerability?management workflows using scripts, APIs, or BI/reporting tools.
**Compensation Ranges**
Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.
**EEO Requirements**
It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.
All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment.
Physical Requirements
The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, "light office duties' or "lifting up to 50 pounds" or "some travel" required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions.
**Disclaimer**
The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.
66,900-87,000
EEO Requirements
It is the policy of ASM that an individual's race, color, religion, sex, disability, age, gender identity, veteran status, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.
All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, veteran status, disability, gender identity, or age. All decisions on employment are made to abide by the principle of equal employment.
Job #NLX294640617