Cyber Vulnerability Assessment Analyst - Intermediate
Job Description
Job Description
POSITION SUMMARY
NewSat is seeking an Intermediate-level Vulnerability Assessment Analyst to support our U.S. Space Force (USSF) customer. This position performs vulnerability assessment and remediation-tracking activities across a platform spanning more than 42 deployed environments across approximately 900 servers at multiple classification levels.
Working with only periodic high-level guidance, the Intermediate VAA executes recurring and ad hoc assessments, validates findings, and supports remediation and continuous monitoring activities in non-routine and sometimes complicated situations. This role supports the task order’s Continuous Cyber Monitoring, Threat Assessment and Risk Mitigation, and Body of Evidence artifact management service areas.
KEY RESPONSIBILITIES
• Execute scheduled and ad hoc vulnerability scans across the existing environment and during assessment of new connections using ACAS/Nessus and DoD-approved assessment tooling.
• Apply DISA STIGs and SCAP benchmarks; validate compliance results and research findings to confirm or dismiss false positives.
• Analyze scan output, correlate findings across environments, and document results in standardized assessment reports.
• Track remediation actions to closure with system owners; support POA&M entry, updates, and supporting evidence.
• Assemble Body of Evidence (BoE) artifacts supporting Certificate to Field (CtF), Authority to Connect (ATC) and continuous monitoring requirements.
• Support assessment of cloud and container workloads, including AWS tenant spaces and EKS-hosted services.
• Escalate complex, high-risk, or disputed findings to the Advanced VAA or Security Architect for adjudication.
• Maintain assessment documentation, scan configurations, and reporting cadence in accordance with program procedures.
REQUIRED QUALIFICATIONS
• Active TS clearance with SCI eligibility; ability to meet program-directed access requirements.
• Minimum 4 years of cybersecurity experience with direct vulnerability assessment or vulnerability management responsibility.
• Security+ CE or equivalent DoD 8140 / 8570 baseline certification current at time of hire.
• Hands-on experience with ACAS/Nessus or comparable scanning platforms and with STIG/SCAP compliance checking.
• Familiarity with RMF, NIST SP 800-53 control families, and POA&M processes.
• Ability to work non-routine assessment tasks with only periodic high-level supervision.
PREFERRED QUALIFICATIONS
• Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or a related field.
• Experience supporting DoD, IC, or space ground system programs.
• Certifications such as CySA+, CEH, GCIH, or GSEC.
• Exposure to containerized or cloud environments (Kubernetes/EKS, AWS).
• Scripting familiarity (Python, PowerShell, Bash) for reporting and data reduction.
Company DescriptionNewSat provides cost-competitive, best-of-breed, global C5ISR solutions to ensure mission success for our customers. Our small business provides solutions to many industry partners, both as a prime contractor and value-added subcontractor.
Company Description
NewSat provides cost-competitive, best-of-breed, global C5ISR solutions to ensure mission success for our customers. Our small business provides solutions to many industry partners, both as a prime contractor and value-added subcontractor.
