Demo

SBA - Vulnerability Analyst II

cFocus Software Incorporated
Washington, DC Full Time
POSTED ON 5/11/2026
AVAILABLE BEFORE 8/6/2026

Vulnerability Analyst II – Job Description

Position Title: Vulnerability Analyst II
Program: SBA Enterprise Cybersecurity Services (ECS)

Position Summary

The Vulnerability Analyst II provides cybersecurity risk, vulnerability management, and compliance support services in alignment with the SBA Enterprise Cybersecurity Services (ECS) RFQ Task Area 3.5.2. The position supports the SBA Risk Management Framework (RMF), FISMA compliance initiatives, Information System Continuous Monitoring (ISCM), vulnerability management, controls assessment activities, audit support, and continuous monitoring operations across enterprise systems and cloud environments. The analyst performs vulnerability assessments, supports POA&M development, validates security controls, coordinates remediation efforts, and assists Information System Security Officers (ISSOs) and system owners with maintaining compliant and secure systems.

Essential Duties and Responsibilities

  • Perform enterprise vulnerability assessments and compliance scans using SBA-approved tools such as Tenable Security Center (SC), Nessus, and Microsoft TVM.
  • Review identified vulnerabilities, assess impact and risk, and provide remediation recommendations for operating systems, applications, network devices, and cloud environments.
  • Support continuous monitoring and Risk Management Framework (RMF) activities in accordance with NIST SP 800-37, NIST SP 800-53 Rev. 5, and NIST SP 800-53A.
  • Assist with the creation, maintenance, and review of cybersecurity documentation including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), Configuration Management Plans (CMPs), and contingency documentation.
  • Support control assessments and validation activities by documenting NIST 800-53A Determine If Statements (DISs) and mapping vulnerabilities to applicable controls.
  • Conduct vulnerability scanning activities every 72 hours across workstations, servers, routers, switches, and cloud-based assets in accordance with SBA requirements.
  • Monitor CISA Known Exploited Vulnerabilities (KEV) listings and Binding Operational Directives (BODs) to identify and report emerging risks.
  • Track zero-day vulnerabilities, coordinate remediation activities, and provide ad hoc reporting to leadership and stakeholders.
  • Generate weekly vulnerability reports, dashboards, and briefing materials for ISSOs, system owners, and management.
  • Assist with audit preparation and support activities involving IG, GAO, internal auditors, and external assessors.
  • Maintain scanning infrastructure including scanner deployment, configuration, plugin updates, scan repositories, and vulnerability management SOPs.
  • Support FedRAMP Continuous Monitoring (CONMON) activities by reviewing vulnerability reports and assessing vendor remediation activities.
  • Participate in change management, security operations meetings, and enterprise cybersecurity coordination activities.
  • Ensure all deliverables are complete, accurate, aligned with agency templates, and delivered within required timeframes.

Minimum Qualifications

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Assurance, or related discipline. Additional years of experience may substitute for degree requirements.
  • 3–6 years of experience supporting vulnerability management, cybersecurity compliance, RMF, or information assurance activities in a federal environment.
  • Experience performing vulnerability assessments and remediation activities using Tenable SC/Nessus or equivalent tools.
  • Knowledge of FISMA, NIST RMF, NIST SP 800-53 Rev. 5, NIST SP 800-53A, NIST SP 800-137, and related federal cybersecurity standards.
  • Experience supporting POA&M management, security assessments, continuous monitoring, and audit response activities.
  • Working knowledge of Windows, Linux/Unix, network infrastructure, cloud platforms, and enterprise security technologies.
  • Strong written and verbal communication skills with the ability to produce technical documentation and executive-level reports.
  • Ability to analyze security findings, prioritize risks, and coordinate remediation with technical stakeholders.

Preferred Certifications

  • CompTIA Security
  • Certified Information Systems Security Professional (CISSP)
  • Certified Ethical Hacker (CEH)
  • GIAC Security Certifications (GSEC, GPEN, or similar)
  • Tenable Certified Professional or equivalent vulnerability management certification

Salary.com Estimation for SBA - Vulnerability Analyst II in Washington, DC
$99,112 to $134,021
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a SBA - Vulnerability Analyst II?

Sign up to receive alerts about other jobs on the SBA - Vulnerability Analyst II career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$83,431 - $103,091
Income Estimation: 
$106,113 - $127,991
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at cFocus Software Incorporated

  • cFocus Software Incorporated Tyson's Corner, VA
  • The Human Resources Benefits & Compliance Analyst position plays a critical role in ensuring the organization's adherence to employment laws, regulations, ... more
  • 17 Days Ago

  • cFocus Software Incorporated Washington, DC
  • cFocus Software seeks a Cyber Exercises Support Lead to join our program supporting the Administrative Office of the United States Courts (AOUSC). This pos... more
  • 2 Days Ago

  • cFocus Software Incorporated Washington, DC
  • cFocus Software seeks a Threat Hunt Lead to join our program supporting the Administrative Office of the United States Courts (AOUSC). This position is Hyb... more
  • 2 Days Ago

  • cFocus Software Incorporated Washington, DC
  • cFocus Software seeks a Blue Team Lead to join our program supporting the Administrative Office of the United States Courts (AOUSC). This position is Hybri... more
  • 2 Days Ago


Not the job you're looking for? Here are some other SBA - Vulnerability Analyst II jobs in the Washington, DC area that may be a better fit.

  • SAIC Washington, DC
  • Job ID 2612468 Location Washington, DC, US Date Posted 2026-05-12 Category Cyber Subcategory Cybersecurity Spec Schedule Full-Time Shift Day Job Travel No ... more
  • 12 Days Ago

  • Jobs via Dice Washington, DC
  • Job ID: 2612468 Location: Washington, DC, US Date Posted: 2026-05-12 Category: Cyber Subcategory: Cybersecurity Spec Schedule: Full-Time Shift: Day Job Tra... more
  • 12 Days Ago

AI Assistant is available now!

Feel free to start your new journey!