Cybersecurity Vulnerability Analyst Job at Peraton, Linthicum, MD

dkNiR2dSYmZFbTNoWlNSYTd5V0xTMTg9
  • Peraton
  • Linthicum, MD

Job Description

Program Overview

About The Role

This Cybersecurity Vulnerability Analyst supports the Vulnerability Disclosure Program (VDP) within the Defense Cyber Crime Center (DC3) and is responsible for reviewing and vetting security vulnerability reports submitted to the DoD VDP from outside hackers. The Analyst will evaluate the reports to ensure the vulnerability is reproducible and therefore valuable to the customer. They will assess each vulnerability for severity and assign an associated risk statement. The HackerOne Triage console tool will be utilized to assist in assigning and prioritizing reports. It will also assist the Analyst in helping identify duplicate submissions. Valid reports will be written in a DOD approved format and sent to the Vulnerability Management Analyst team for system owner coordination and mitigation. The Vulnerability Analyst will be a VDP liaison with the hacker community.  

The Vulnerability Analyst will also:

  • Utilize offensive toolsets such as Kali Linux to safely analyze production networks and systems, documenting steps and procedures to produce usable vulnerability assessments for the customer.
  • Identify and investigate vulnerabilities, asses exploit potential, and document findings and remedies for presentation to facilitate mitigations on customer systems. 
  • Conduct web application vulnerability assessment testing using both automated tools and manual web exploitation techniques, using tools such as Burp Suite and open-source toolsets. 
  • Utilize a variety of industry standard security tools to conduct automated scans against systems and applications. 
  • Develop and execute proof-of-concept exploits to demonstrate the real-world impact of identified vulnerabilities, utilizing various web exploitation methods. 

Qualifications

Qualifications

  • Minimum Bachelor’s degree and 5+ years of experience; OR Master’s Degree and 3+ years of experience; OR 0 years with PhD. Bachelor's degree must be one of the following fields: Information Technology, Cybersecurity, Computer Science, Information Systems, Data Science, or Software Engineering.

  • Strong understanding of information security principles and practices,  

  • Understand basic IDS/IPS rules to identify and prevent malicious activity.

  • Utilize MITRE ATT&CK, CVSS, and NIST frameworks to assess vulnerability severity and risk impact. 

  • Basic understanding of web exploitation concepts and techniques. 

  • Knowledge and understanding of the Open Web Application Security Project (OWASP) top 10. 

  • Experience operating in a professional IT or cybersecurity environment.   

  • Experience investigating security events, threats and/or vulnerabilities.  

  • Understand information security principles, technologies and practices.  

  • Excellent customer service skills.

  • IAT Level II certification required. 

  • Active Secret security clearance required.

Preferred Additional Skills

  • CEH, CCNA-Security, CySA+, GCIH, GICSP, PenTest+ or similar certification a plus.

SCA / Union / Intern Rate or Range

Details

Target Salary Range: $80,000 - $128,000. This represents the typical salary range for this position based on experience and other factors.

EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

Job Tags

Internship,

Similar Jobs

Certerra

Front Desk Scheduler/Dispatcher (Carson City Office) Job at Certerra

 ...delivery, and engineered solutions for asset management. We are passionate about contributing to...  ...development of world-class laboratory facilities, and interactive management technologies...  ...Front Desk Scheduler/Dispatcher (Carson City Office) Black Eagle Consulting, LLC a... 

Delta-T Group Inc.

School RN - Up to $50/hr Job at Delta-T Group Inc.

 ...opportunities. COMPENSATION * Up to $50/hr. depending on contractor's qualifications, availability, and skill. Compensation...  ...allied health and special education fields, for the betterment of independent behavioral health professionals seeking new opportunities and... 

Amentum

Helicopter Pilot (Instructor) Job at Amentum

We are currently accepting applications for the position of INSTRUCTOR PILOT.**IMPORTANT:**Applicants for employment are subject to Government...  ...no flying experience. Fort Rucker is the largest rotary wing flight school in the world, not just for the Army but also for the Air... 

Middlebury College

Instructor of Japanese - Invitation Only (Summer 2025 LSJ002) Job at Middlebury College

 ...the Instructor of Japanese opening . Middlebury Colleges Summer School of Japanese (SoJ) is pleased to announce a vacancy for a...  ...person program begins around June 19 and ends on August 16, 2025. Online orientation and/or workshops maybe required before the starting... 

Get It Recruit - Educational Services

Editing Instructor - Remote | WFH Job at Get It Recruit - Educational Services

 ...and knowledgeable Editing Instructor to join our faculty for the Summer 2024 semester. This role offers an opportunity to work with...  ...workflows, including HD and 4K footage. Is comfortable with online teaching and willing to collaborate with our online learning specialist...