Vulnerability Management Analyst
Abacus Technology Corporation · Hanscom AFB, MA · 2 days ago
Business DevelopmentFull-time
About the role
Abacus Technology is seeking a Vulnerability Management Analyst to identify, analyze, and remediate vulnerabilities across enterprise systems at Hanscom AFB. This is a full-time position.
Responsibilities
- Perform vulnerability scanning, assessment, and remediation tracking using ACAS (Nessus/Security Center), ARAD (Tanium), or similar tools.
- Analyze scan data and coordinate patching activities with system administrators and functional owners.
- Develop and maintain PowerShell scripts to automate configuration management and patch deployment tasks.
- Work in Active Directory and Windows Server environments to implement secure baselines and GPO configurations.
- Coordinate vulnerability closure through ServiceNow or equivalent ticketing systems, ensuring timely and accurate updates.
- Prepare tracking and status reports on vulnerability status, patch compliance, and risk posture for leadership and compliance reviews.
- Collaborate with Cybersecurity, IT Operations, and Compliance teams to support RMF and STIG compliance requirements.
- Proactively communicate findings, remediation guidance, tracking insights, and risk impacts to both technical and non-technical stakeholders.
- Support HBSS/MECM and related endpoint management tools as required to deploy patches or security updates.
Qualifications
- 2+ years of experience in vulnerability management, patch management, or system administration within a DoD or enterprise environment.
- Associate's degree in a related field.
- Must be Security+ CE certified.
- Strong understanding of Windows OS (Windows 10/11) and Windows Server environments.
- Experience with vulnerability management tools (e.g., ACAS, Tenable, Nessus, Tanium, Qualys).
- Demonstrated experience with patch management and configuration management processes.
- Knowledge of PowerShell scripting for automation and remediation workflows.
- Knowledge of Active Directory, Group Policy, and system hardening techniques.
- Familiar with enterprise ITSM platforms (ServiceNow preferred).
- Experience supporting DoD cybersecurity programs and compliance frameworks (RMF, STIGs, DISA, NIST 800-53) desired.
- Familiarity with automation/orchestration platforms for patch and configuration management preferred.
- Experience creating dashboards and reports for leadership visibility using tools such as Power BI, Tanium, and ServiceNow Performance Analytics preferred.
- Excellent written and verbal communication skills, including the ability to convey technical details clearly.
- Proven ability to manage competing priorities in a mission-focused environment.
- Must be a US Citizen and hold a current Secret clearance.