Vulnerability Assessment Analyst
Who we are:
ShorePoint is a fast-growing, industry recognized and award-winning cybersecurity services firm with a focus on high-profile, high-threat, private and public-sector customers who demand experience and proven security models to protect their data. ShorePoint subscribes to a “work hard, play hard” mentality and celebrates individual and company successes. We are passionate about our mission and going above and beyond to deliver for our customers. We are equally passionate about an environment that supports creativity, accountability, diversity, inclusion and a focus on giving back to our community.
The Perks:
As recognized members of the Cyber Elite, we work together in partnership to defend our nation’s critical infrastructure while building meaningful and exciting career development opportunities in a culture tailored to the individuals technical and professional growth. We are committed to the belief that our team members do their best work when they are happy and well cared for. In support of this philosophy, we offer a comprehensive benefits package, including major carriers for health care providers. Highlighted benefits offered: 144 hours of PTO, 11 holidays, 85% of insurance premium covered, 401k, continued education, certifications maintenance and reimbursement and more.
Who we’re looking for:
We are seeking a detail-oriented Vulnerability Assessment Analyst for a potential opportunity with experience identifying, assessing and tracking vulnerabilities across enterprise Information Technology (IT) and Operational Technology (OT) assets. The ideal candidate will possess a solid understanding of risk assessment methodologies, vulnerability management processes, automated scanning workflows and the documentation needed to support federal cybersecurity compliance and reporting. The Vulnerability Assessment Analyst role performs risk and vulnerability evaluations, manages enterprise asset and exposure data and collaborates with engineering and Risk Management Framework (RMF) teams to support secure mission operations. This is a unique opportunity to shape the growth, development and culture of an exciting and fast-growing company in the cybersecurity market. Employment for this position is dependent on the successful award of the contract.
What you’ll be doing:
- Conduct vulnerability assessments, support analysis of threats and residual risks and evaluate control effectiveness through authorized defensive security exercises.
- Assist in recommending and applying risk assessment methodologies aligned with federally recognized controls and agency standards.
- Manage and input vulnerability data, asset information and scanning results into enterprise governance and risk databases to support reporting and data calls.
- Support continuous monitoring activities, security control validation and technical protection workflows to maintain system authorizations.
- Support self-assessments, control validation activities and technical evaluation efforts.
- Coordinate with engineering, RMF and operations staff to track, document and remediate identified security gaps.
- Contribute data and tracking information toward metrics related to vulnerabilities, security gaps, data coverage and control effectiveness.
What you need to know:
- Experience in vulnerability management, risk assessment, vulnerability scanning and security control evaluation.
- Familiarity with federal compliance environments, Authorization to Operate (ATO) support and cybersecurity reporting requirements.
- Strong analytical and problem-solving abilities with a focus on remediation tracking and risk reduction.
- Ability to document findings, technical recommendations and risk impacts clearly.
- Experience working collaboratively with technical, operational and compliance stakeholders.
Must have’s:
- Bachelor’s degree from an accredited university in a related field.
- 5+ years of relevant work experience.
- Proven ability to analyze complex requirements and translate them into clear, actionable tasks and processes through critical thinking.
- Applicants must currently be a U.S. citizen and eligible to obtain and maintain a security clearance, in compliance with federal contract requirements.
Beneficial to have:
- Active DOE Q or equivalent DoD Top Secret clearance.
Where it’s done:
- Onsite (Albuquerque, NM).