Demo

HHS - Vulnerability Analyst

cFocus Software Incorporated
Rockville, MD Full Time
POSTED ON 1/28/2026 CLOSED ON 4/27/2026

What are the responsibilities and job description for the HHS - Vulnerability Analyst position at cFocus Software Incorporated?

cFocus Software seeks a Vulnerability Analyst to join our program supporting the Department of Health and Human Services (HHS) This position is remote. This position requires the ability a Public Trust clearance.
Qualifications:
  • Bachelor’s degree in Cybersecurity, Information Technology, or related field.
  • Minimum 5–7 years of experience in vulnerability management or security operations.
  • Strong understanding of NIST SP 800-53, NIST SP 800-30, NIST SP 800-137, and HHS vulnerability management requirements.
  • Experience performing vulnerability scanning, analysis, and remediation tracking in federal environments.
  • Experience with secure configuration standards (DISA STIGs, CIS Benchmarks).
  • Strong analytical, documentation, and communication skills.
  • CEH, Security , CISSP, GIAC (GSEC, GPEN), or equivalent cybersecurity certifications
Duties:
  • Perform authenticated and unauthenticated vulnerability scans on a daily and ad hoc basis across servers, workstations, network devices, databases, web applications, APIs, containers, serverless functions, CI/CD pipelines, and Infrastructure as Code (IaC).
  • Analyze vulnerability scan results to determine applicability, severity, exploitability, and risk using CVSS scoring, threat intelligence, and Known Exploited Vulnerabilities (KEV) catalogs.
  • Provide daily remediation guidance and mitigation strategies to system owners, administrators, developers, and other stakeholders.
  • Maintain and ensure operational health of vulnerability scanning tools, including agents, sensors, integrations, and supporting infrastructure.
  • Coordinate with tool vendors, hosting teams, and network operations to troubleshoot and resolve tool-related issues.
  • Develop and maintain HRSA security configuration baselines using DISA STIGs and Center for Internet Security (CIS) benchmarks.
  • Perform compliance and configuration scans against approved baselines on a weekly, quarterly, and ad hoc basis.
  • Validate remediation through follow-up scans and evidence review and confirm closure of vulnerabilities.
  • Support penetration testing activities, including test planning, execution, exploitation, reporting, and coordination with stakeholders.
  • Conduct application security testing including SAST, DAST, software composition analysis, SBOM review, dependency scanning, and secure code analysis.
  • Support secure DevSecOps practices by integrating automated vulnerability testing into CI/CD pipelines and code repositories.
  • Develop vulnerability dashboards and reports for ISSOs, system owners, engineers, and DCSP leadership.
  • Maintain authoritative asset inventories and correlate data across vulnerability tools, CMDB, eGRC, and cloud inventories to ensure full scanning coverage.
  • Support Incident Response activities by providing vulnerability data, exploit analysis, and remediation recommendations.
  • Develop and maintain vulnerability management SOPs, workflows, and technical documentation.
  • Maintain SLAs for vulnerability scanning requests and remediation tracking

Salary.com Estimation for HHS - Vulnerability Analyst in Rockville, MD
$144,271 to $182,581
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a HHS - Vulnerability Analyst?

Sign up to receive alerts about other jobs on the HHS - Vulnerability Analyst career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
This job has expired.
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at cFocus Software Incorporated

  • cFocus Software Incorporated Rockville, MD
  • cFocus Software seeks a Program Manager to join our program supporting the Department of Health and Human Services (HHS) This position is remote. This posi... more
  • 4 Months Ago

  • cFocus Software Incorporated Rockville, MD
  • cFocus Software seeks a Security Control Assessor to join our program supporting the Department of Health and Human Services (HHS) This position is remote.... more
  • 4 Months Ago

  • cFocus Software Incorporated Rockville, MD
  • cFocus Software seeks a Application Security Engineer to join our program supporting the Department of Health and Human Services (HHS) This position is rem... more
  • 4 Months Ago

  • cFocus Software Incorporated Rockville, MD
  • cFocus Software seeks a Cloud Security Engineer/Architect to join our program supporting the Department of Health and Human Services (HHS) This position is... more
  • 4 Months Ago


Not the job you're looking for? Here are some other HHS - Vulnerability Analyst jobs in the Rockville, MD area that may be a better fit.

AI Assistant is available now!

Feel free to start your new journey!