Cybersecurity Vulnerability Analyst
Job Description
Peraton is seeking a Cybersecurity Vulnerability Analyst to support a DoD Vulnerability Disclosure Program in the Baltimore-Metropolitan area. This fully on-site role (M-F) focuses on reviewing incoming vulnerability reports, validating findings, and coordinating mitigation through the established DoD workflow.
Role Responsibilities
- Review and vet security vulnerability reports submitted to the DoD VDP from external hackers.
- Evaluate reports to confirm the vulnerability is reproducible and meaningful to the customer.
- Assess each vulnerability for severity and assign an associated risk statement.
- Use the HackerOne Triage console tool to assist with triage, assigning, and prioritizing reports.
- Identify and flag duplicate submissions using the HackerOne Triage console tool.
- Produce vulnerability reports in a DoD approved format and send them to the Vulnerability Management Analyst team to enable system owner coordination and mitigation.
- Act as a VDP liaison with the hacker community.
- Utilize offensive toolsets such as Kali Linux to safely analyze production networks and systems, documenting procedures to create usable vulnerability assessments.
- Identify and investigate vulnerabilities, assess exploit potential, and document findings and remedies to support customer mitigations.
- Conduct web application vulnerability assessment testing using automated tooling and manual web exploitation techniques, including Burp Suite and open-source toolsets.
- Run automated scans against systems and applications using a range of industry-standard security tools.
- Develop and execute proof-of-concept exploits to demonstrate real-world impact using multiple web exploitation methods.
Required Qualifications
- Bachelor’s degree and 5+ years of experience, or Master’s and 3+ years, or PhD and 0+ years.
- Active Secret clearance.
- Active IAT Level II certification (CompTIA Security+ preferred).
- In-depth understanding of information security principles and practices.
- Pentesting experience.
- Ability to use MITRE ATT&CK, CVSS, and NIST frameworks to assess vulnerability severity and risk impact.
- In-depth understanding of web exploitation concepts and techniques.
- Knowledge of the OWASP Top 10.
- Experience operating in a professional IT or cybersecurity environment.
- Experience investigating security events, threats, and/or vulnerabilities.
- Understand information security principles, technologies, and practices.
- Excellent customer service skills.
Preferred Education
- Degree in Information Technology, Computer Science, Cybersecurity, Information Systems, Software Engineering, or Data Science is highly desired.
Security Tools and Technologies
- HackerOne Triage console tool
- Kali Linux
- Burp Suite
- MITRE ATT&CK
- CVSS
- NIST
- OWASP Top 10
- PowerShell
- Bash
- Python
- Perl
- CompTIA Security+
- CEH
- CCNA-Security
- CySA+
- OSCP
- PenTest+
- HTLM/CSS
- SQL
Location and Schedule
Location: Linthicum, MD (fully on-site).
Schedule: M-F in the Baltimore-Metropolitan area.
Compensation
Salary range: USD 104,000 to 166,000 per year.
Target salary range: $104,000 - $166,000.
Benefits
- Medical
- Dental
- Vision
- Life
- Health savings account
- Short/long term disability
- EAP
- Parental leave
- 401(k)
- Paid time off (PTO) for vacation
- Company paid holidays
Application and Additional Information
- Application period is estimated to be 30 days from the job posting date, and the timeline may be shortened or extended based on business needs and candidate availability.
- During review, applicants may be required to participate in an on-camera interview and a process to verify identity.
- EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.