Cybersecurity Analyst – Vulnerability Management (Tenable / Nessus / ACAS)

Position Title: Cybersecurity Analyst – Vulnerability Management (Tenable / Nessus / ACAS) Location: Remote (U.S.) with Occasional Travel Client: Federal / Public Sector Programs Work Authorization: Candidates must be authorized to work in the United States. U.S. Citizenship may be required based on client assignment. Application Email: careers@wintrio.com  📩 To apply, please submit your resume to careers@wintrio.com or complete the application form below.  Job Summary  WINTrio LLC is seeking a Cybersecurity Analyst – Vulnerability Management to support enterprise vulnerability assessment, analysis, remediation coordination, compliance tracking, and continuous monitoring activities across Federal IT environments.  The ideal candidate will possess hands-on experience performing vulnerability scans, analyzing security findings, validating scan results, coordinating remediation activities, and supporting compliance reporting efforts. This role requires a strong understanding of vulnerability management processes, Federal cybersecurity requirements, and risk-based remediation strategies across cloud, on-premises, and hybrid technology environments.  The successful candidate will work closely with system administrators, developers, ISSOs, cloud engineers, and program stakeholders to improve security posture and reduce organizational risk.  Job Responsibilities  Perform recurring and ad hoc vulnerability assessments using Tenable, Nessus, ACAS, Qualys, Rapid7, or similar vulnerability management platforms. Analyze vulnerability findings across operating systems, databases, web applications, APIs, cloud services, containers, endpoints, and network infrastructure. Validate scan results, identify false positives, and assess risk based on exploitability, asset criticality, and mission impact. Coordinate remediation activities with system administrators, developers, ISSOs, cloud teams, and infrastructure personnel. Track vulnerabilities through closure using POA&Ms, ticketing systems, remediation dashboards, and risk registers. Support compliance with NIST SP 800-53, FISMA, FedRAMP, DHS CDM requirements, agency service-level agreements, and remediation timelines. Develop vulnerability reports, trend analyses, executive summaries, compliance metrics, and technical remediation guidance. Support STIG, SCAP, CIS Benchmark, and configuration compliance assessments. Assist with authenticated scanning, credentialed scanning, web application testing, scan tuning, and policy optimization activities. Support continuous monitoring programs, security assessments, audits, and evidence collection activities. Collaborate with cybersecurity and operations teams to strengthen overall security posture and vulnerability management processes. Support continuous improvement initiatives and vulnerability management best practices. Required Qualifications  Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field, or equivalent professional experience. Minimum three (3) years of cybersecurity experience with a focus on vulnerability management, security assessments, scanning, or remediation support. Hands-on experience with Tenable.io, Tenable.sc, Nessus, ACAS, Qualys, Rapid7, or comparable vulnerability management tools. Understanding of CVEs, CVSS scoring, asset criticality, exploitability analysis, remediation prioritization, and risk-based decision making. Experience coordinating remediation activities with technical and operational teams. Understanding of Federal cybersecurity frameworks, including NIST SP 800-53, FISMA, RMF, and FedRAMP. Strong written and verbal communication skills. Strong analytical, organizational, and problem-solving abilities. Technical Areas  Vulnerability Management  Vulnerability Assessment Vulnerability Analysis Risk-Based Remediation Continuous Monitoring Security Findings Validation Remediation Tracking Vulnerability Reporting Federal Cybersecurity Compliance  NIST SP 800-53 NIST SP 800-40 Risk Management Framework (RMF) FISMA FedRAMP DHS Continuous Diagnostics and Mitigation (CDM) Security Operations & Analysis  CVE Analysis CVSS Scoring CWE Analysis CPE Identification Known Exploited Vulnerabilities (KEV) Exploit Prediction Scoring System (EPSS) Attack Surface Management Cloud & Infrastructure Security  AWS Microsoft Azure Windows Server Linux Kubernetes Docker Tools & Platforms  Vulnerability Management Tools  Tenable.io Tenable.sc Nessus ACAS Qualys Rapid7 InsightVM Application Security Tools  WebInspect Burp Suite OWASP ZAP Fortify SonarQube Configuration Compliance Tools  STIG Viewer SCAP CIS-CAT DISA STIGs CIS Benchmarks Tracking & Collaboration Tools  ServiceNow JIRA Azure DevOps POA&M Tracking Systems Reporting & Analytics  Splunk Power BI Microsoft Excel Tableau Executive Dashboards Preferred Certifications  CompTIA Security+ CompTIA CySA+ Certified Ethical Hacker (CEH) Tenable Certified Nessus Auditor Tenable.sc Specialist Tenable.io Specialist GIAC Security Certifications (GSEC, GPEN, or equivalent) AWS Certified Security – Specialty Microsoft Azure Security Engineer Associate ITIL Foundation Preferred Qualifications  Experience supporting large-scale vulnerability management programs involving thousands of assets. Experience with authenticated scanning, scan credential troubleshooting, and scan policy optimization. Experience supporting POA&M development, remediation tracking, and risk acceptance documentation. Experience supporting Federal civilian, DHS, DoD, intelligence, or cloud-hosted environments. Experience supporting enterprise continuous monitoring programs and security operations activities. Familiarity with cloud-native infrastructure and modern application environments. Work Environment  Full-time position. Remote within the United States. Standard business hours Monday through Friday. Occasional travel may be required in support of customer meetings, security assessments, and program activities. WINTrio Benefits  Healthcare (Medical, Dental, and Vision) Flexible Spending Account (FSA) and Health Savings Account (HSA) 401(k) and Retirement Savings Plan Annual Bonus and Profit Sharing Opportunities Paid Time Off (PTO) and Vacation Employee Assistance Program (EAP) Life, Personal, and Voluntary Disability Insurance Growth Opportunities  There is ample opportunity to grow in multiple dimensions, including vulnerability management, cybersecurity operations, cloud security, compliance modernization, DevSecOps, risk management, and cybersecurity leadership. We are a completely employee-driven company, and our continued success is built on the talent, dedication, and innovation of our team members.  Equal Opportunity Employer  WINTrio LLC is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity, sexual orientation, national origin, age, disability, protected veteran status, or any other characteristic protected by applicable federal, state, or local law. 

Back to blog

Other Jobs To Apply

Casualty Coverage and Mass Tort - Complex Claims Director

Specialist, Customer Information Managment

Data Scientist for H Labs @ Chicago, Illinois, United States

Insurance Account Manager

Associate - Digital Technology

IT Vendor Financials and Contract Manager at Deloitte: 100% Remote (US)

Nessus Administrator

Federal Business Development Operations Manager - Remote

Proofread Early Chapter Book (140-160 pages)

Licensed Mental Heath Clinician(LCSW/LMHC) - 100% virtual in a group private practice in NY | Northeast Psychological Wellness | Handshake

Senior Director, Finance IT Enterprise Applications

Global Power Delivery Equipment Lead

Tele-Critical Care Clinical Coord FT

Medical Insurance Collector

Patient Relations Coordinator - Remote in Eugene, OR - 2251433

[Hiring] Medical Science Liaison, Immunology - Admilparant @Bristol Myers Squibb

Engineer, Software (East Moline, Illinois, US, 61244)

Building Automation and Digital Services Leader

TurboTax Product Expert (Work From Home)

Remote Marketing Ops Specialist - HubSpot & Data Quality

Customer Service Rep(07857) - 805 W. Whittier Blvd.

Coca - Cola Remote?o Experience $25/hr At Careermilard ( Remote )

Utilization Management Nurse Consultant - Medical Review (Remote)

Travel Consultant - Remote VIP

Technology Director, Head of Engineering

Oracle Fusion Techno-Functional Developer- Remote, US

[Remote] Senior Associate, Journey Builder (Adobe Experience Platform)

Work From Home Customer Service Rep

External Wholesaler – Independent Broker Dealer Channel

Senior Representative, Personal Line

Property Adjuster at Allstate: 100% Remote (TX)

Business Development Officer, Schwab Wealth Advisory (Central Division)

Korn Ferry Skillbridge Intern (remote)

Associate Client Advocate, Multiple Teams

Strategy Insights & Planning Associate Consultant - HEOR Evidence Generation

Associate Consultant Internship

Implementation - Procurement Associate

Analytics Intern – Analytics Services

Associate Director Private & Trusts Assurance

Senior Insurance Claims Forensics Specialist

Annuities Customer Support

Ingenium Software Developer [Technical Consultant]

Varonis Engineer Role

CyberArk Architect

Account Executive, Mid-Market (North Central)

Remote Named Account Manager

Senior Remote Distributed Systems Engineer

Senior Director of Developer Relations – Community

Sr. Data Analyst (SAS, data warehouse) | REMOTE

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...