Junior Vulnerability & Exposure Analyst
The Junior Vulnerability & Exposure Analyst is an entry-level cybersecurity role focused on operating vulnerability scanning tools, reviewing scan results, and assisting with vulnerability triage to support risk reduction efforts. This position involves collaborating with incident response teams, maintaining security documentation, and monitoring evolving cybersecurity threats to enhance the organization's security posture. The role requires foundational knowledge in cybersecurity and hands-on experience with vulnerability management processes under close supervision.
About Careertakes
👉 Important disclosure: Careertakes is a third-party recruiting platform supporting this hiring process. If selected, you will be employed directly by our client, State Government — Information Technology.
Applicants for this role may also receive access to additional matched opportunities through the Careertakes platform.
Position overview
Confidential Client is seeking a Junior Vulnerability & Exposure Analyst to join a cybersecurity team supporting state-level information technology systems. This is a contract role focused on vulnerability scanning, triage, reporting, and helping reduce risk across applications, systems, and networks. This role is entry-level to early-career but requires relevant hands-on experience.
What You’ll Do
- Operate enterprise vulnerability scanning tools to run scheduled and ad-hoc scans across assets.
- Review and perform initial triage of scan results; identify high-risk findings and potential false positives.
- Correlate vulnerability findings with asset inventory and context to prioritize remediation.
- Assist in preparing vulnerability reports and executive/technical summaries for system owners.
- Track remediation progress in the vulnerability management platform or ticketing system.
- Escalate critical vulnerabilities for further analysis or remediation when required.
- Support Incident Response efforts by providing vulnerability data and analysis during investigations.
- Contribute to post-incident reviews and lessons-learned activities to improve processes.
- Help develop and maintain Standard Operating Procedures (SOPs) and response playbooks.
- Monitor vendor advisories, CVEs, CISA KEV catalog, and threat intelligence sources to identify emerging risks.
- Keep current on vulnerability research, attack techniques, and defensive best practices.
Minimum Qualifications
- Four years of relevant experience in one or more of: threat hunting, network security analysis, network traffic analysis, information security, information systems, information assurance, security operations, cryptography, or cyber threat modeling.
- Familiarity with vulnerability scanning tools and vulnerability management workflows.
- Ability to analyze scan output, identify false positives, and document findings clearly.
- Strong written and verbal communication skills to interact with technical teams and system owners.
- Applicants must submit an up-to-date and accurate resume.
Notes on substitutions:
- Candidates may substitute a bachelor’s degree in computer science, cybersecurity, information technology, software engineering, information systems, computer engineering or related field for up to two years of the required experience.
- Candidates with a High School Diploma or High School Equivalency certificate may substitute that education plus two additional years of relevant experience.
- A graduate-level degree in a related field may be substituted for portions of the experience requirement.
Preferred / Helpful Skills
- Experience with common vulnerability scanners and platforms (e.g., Nessus, Qualys, Rapid7, Tenable, or similar).
- Familiarity with CVE lookup, CISA advisories, and public vulnerability intelligence feeds.
- Basic knowledge of operating systems, networking, and common web/application vulnerabilities.
- Exposure to ticketing or remediation tracking systems (e.g., ServiceNow, Jira).
- Certifications such as Security+, CEH, or entry-level vendor certs are a plus.
Compensation & Contract Details
- Estimated pay: $101,162 per year (estimated).
- This is a contractual position with limited benefits.
- All hires must be eligible to work in the U.S. — U.S. Citizens or Permanent Residents (the client cannot sponsor work authorization).
- Contract length and exact benefits will be confirmed during the interview/offer process.
Location
- Role location: Crownsville, MD — on-site or as defined by the client’s operational requirements. (Refer to the hiring team for exact on-site/telework expectations.)
Notes for Applicants
- This role emphasizes hands-on scanning, accurate triage, and strong documentation. Candidates should be prepared to discuss specific tools and examples of vulnerability analysis.
- Confidential Client expects timely and accurate resumes; please ensure your resume reflects relevant experience.
Equal Opportunity & Hiring Transparency
Careertakes and our client are Equal Opportunity Employers committed to building a diverse and inclusive workforce. We prohibit discrimination or harassment of any kind. To support a fair and efficient hiring process, AI tools may be used to assist with application review or resume screening. These tools do not replace human decision-making. Final hiring decisions are made by people.
If you have questions about how your data is used, please contact us directly.
Negotiate a higher salary! Check the salary ranges for this job type in your area.
View My Salary Range