DFC - Vulnerability Management Analyst
Remote
Full Time
DFC - ISSO
Experienced
cFocus Software seeks a Vulnerability Management Analyst to join our program supporting the United States International Defense Finance Agency (DFC). This position is remote. This position requires an Active Public Trust clearance.
Qualifications:
Duties:
Qualifications:
- Active Public Trust clearance
- B.S. Computer Science, Information Technology, or a related field
- 5+ years of cybersecurity experience, including three or more years in vulnerability management, security compliance, POA&M management, or a closely related function.
- Hands-on experience analyzing authenticated scan results and validating vulnerabilities using Tenable Nessus, Qualys, Microsoft Defender, or comparable enterprise platforms.
- Demonstrated ability to assess vulnerability risk using CVSS, exploitability, CISA KEV status, asset criticality, exposure, mission impact, threat intelligence, and compensating controls.
- Experience creating and maintaining POA&M records, tracking remediation milestones, reconciling GRC and ticketing systems, validating closure evidence, and documenting false-positive determinations.
- Working knowledge of FISMA, the NIST Risk Management Framework, NIST SP 800-53 controls, NIST SP 800-40 vulnerability and patch-management principles, CISA KEV/BOD 22-01 requirements, and federal continuous-monitoring expectations.
- Ability to communicate technical risk clearly to federal cybersecurity leaders, System Owners, engineers, administrators, auditors, and nontechnical stakeholders.
- Strong analytical writing, data-quality, documentation, prioritization, and time-management skills in a deadline-driven environment.
- Active Security+, CySA+, CEH, GCVA, CISSP or other relevant security certifications preferred.
Duties:
- Coordinate authenticated vulnerability scans with DFC stakeholders at frequencies aligned with policy, system criticality, exposure, threat conditions, and Government direction.
- Analyze output from Tenable, Qualys, Microsoft Defender, and other Government-approved vulnerability, endpoint, configuration, and posture-management platforms.
- Validate scanner findings against the operational environment and distinguish valid findings from false positives using documented rationale and supporting evidence.
- Assess and assign severity using CVSS, DFC policy, exploitability, known-exploitation status, asset criticality, external exposure, mission impact, and relevant threat intelligence.
- Recommend risk-informed remediation priorities, actions, timelines, evidence requirements, and closure criteria.
- Coordinate with engineering, operations, application, cloud, endpoint, and system administration teams to establish remediation ownership, dependencies, and target completion dates
- Provide rapid analysis and coordination for CISA Known Exploited Vulnerabilities (KEV), Binding Operational Directive 22-01 requirements, CISA Emergency Directives, vendor-declared zero-days, and vulnerabilities with active exploitation.
- Notify the ISSM within four hours of applicable CISA notification, vendor disclosure, Government notification, or Contractor identification.
- Verify exposure across applicable CSAM authorization boundaries and deliver a written impact assessment within one business day.
- Document affected systems, boundaries and assets; severity; exposure; exploitability; known exploitation; mission impact; remediation ownership; required timelines; recommended action; and residual-risk considerations.
- Track emergency remediation against CISA-, DFC-, or Government-directed deadlines and provide written confirmation of remediation status, compliance status, residual risk, and closure evidence.
- Use CSAM as the authoritative POA&M and compliance ledger and ServiceNow as the operational remediation ticketing record.
- Create complete POA&M items in CSAM within three business days after finding identification or Government direction, unless the Government establishes another deadline.
- Populate and maintain required fields, including identifier, weakness description, affected system and control, severity, source, responsible owner, required resources, scheduled completion date, milestones, status, residual risk, and closure evidence.
- Maintain bidirectional traceability so each applicable ServiceNow remediation ticket links to its CSAM POA&M item and each CSAM POA&M record references the appropriate ServiceNow ticket.
- Track remediation through closure, monitor milestone integrity and aging, and coordinate scheduled-completion-date changes only after federal authorization.
- Conduct monthly ServiceNow-to-CSAM reconciliation; identify stale or duplicate records, missing links or evidence, inconsistent status, inaccurate dates, and other data-quality issues; issue a written discrepancy log and track gaps to resolution.
- Prepare risk-acceptance or exception recommendation packages when remediation cannot be completed within applicable timelines or scheduled-completion-date constraints.
- Document the affected system and weakness, operational and mission impacts, exploitability, exposure, residual risk, compensating controls, remediation constraints, proposed duration and expiration, review interval, and conditions for continued acceptance.
- Route recommendation packages to the AODR through the COR and ISSM for federal decision and accurately record approved decisions in CSAM.
- Clearly preserve federal authority: do not accept risk for DFC, approve exceptions, extend POA&M dates without authorization, or make final closure decisions.
Apply for this position
Required*