Description of Task to be Performed:
AnaVation is searching for a Vulnerability Manager to assist client leadership with the enterprise vulnerability management program, administering scanning platforms (Tenable and/or Qualys), driving vulnerability analysis and risk prioritization, and delivering reporting to leadership and compliance stakeholders.
Responsibilities:
- Administer and maintain scanning platforms such as Tenable.SC, Qualys and/or application-based scanners, which may include activities such as scan policies, asset groups, credentials scanning, and agent deployment.
- Lead enterprise-wide vulnerability scanning cadence across the network, systems, applications and other dependent assets.
- Analyze scan data, validate findings and false positives, and prioritize based on CVSS, exploitability, and business risk.
- Own and manage POA&M lifecycle, tracking remediation timelines, risk acceptance documentation, and closure validation.
- Develop and deliver weekly vulnerability metrics/dashboards and executive reporting (trend analysis, SLA compliance, risk posture).
- Support ATO and continuous monitoring activities in alignment with NIST 800-53.
- Coordinate remediation with system owners, IT operations, and patch management teams.
- Manage scanner tuning, plugin/signature updates, and platform health.
- Support FISMA reporting requirements. · Interacting with GRC tool (e.g., CSAM) to perform daily/weekly vulnerability analysis.
- Flexible with other security related tasks as needed by the customer.
Required Qualifications:
- Bachelor's degree in a related field or equivalent demonstrated experience and knowledge.
- 6 years of experience as a Security Administrator, Vulnerability Manager or equivalent knowledge.
- Hands-on administration experience with Tenable or Qualys.
- Performing vulnerability scans with tools such as Tenable, Qualys, Burpsuite.
- Deep familiarity with CVSS scoring, risk based prioritization methodologies.
- Excellent oral and written communication skills.
- Familiarity with multi-tiered network applications, common ports and protocols used in those communications, the Common Vulnerability System (CVS) and the exploitation mechanisms of common vulnerability types (e.g., buffer overflows, cross-site-scripting, SQL injection).
- Certifications: Security + required
Preferred Qualifications:
- Self-Starter – ability to quickly become competent with new security-related tools and processes.
- Ability to conduct Deep Dive analysis to determine root cause assessment of various network scanning agents’ scanning or communication failures.
- Ability to coordinate remediation strategies with agency’s department technical staff through completion.
- Familiarity with the various use cases and alignment of data from each tool to various security disciplines in configuration management, vulnerability management, risk management and incident management.
- Understanding of the role of interactive training such as phishing exercises for assessment of organizational abilities.
- Familiarity with the use of data analysis tools, including the use of Microsoft Excel or PowerBI to combine data from multiple sources.
- Familiarity with information security terminology and being able to develop or select technical training in the discipline of information security geared to an organization.
- Familiarity with data management and reporting of training data and statistics using common tools such as Microsoft Excel and Word.
- Certifications: CISSP
- Generous cost sharing for medical insurance for the employee and dependents
- 100% company paid dental insurance for employees and dependents
- 100% company paid long-term and short-term disability insurance
- 100% company paid vision insurance for employees and dependents
- 401k plan with generous match and 100% immediate vesting
- Competitive Pay
- Generous paid leave and holiday package
- Tuition and training reimbursement
- Life and AD&D Insurance