Primary Responsibilities.
The Vulnerability Analysis Subject Matter Expert (SME) serves as a senior technical authority for vulnerability identification, analysis, prioritization, remediation, and risk assessment across sensitive and classified information systems.
The SME will evaluate vulnerabilities within the context of the operating environment and make defensible, risk-based determinations based on technical severity, exploitability, threat intelligence, system architecture, existing security controls, mission criticality, and potential impact.
The position requires both deep technical knowledge and cybersecurity risk-management experience. The SME must be capable of translating technical vulnerability information into actionable recommendations for engineers, system owners, cybersecurity personnel, and senior leadership.
Perform detailed analysis of vulnerabilities affecting enterprise systems, applications, network infrastructure, operating systems, virtualization platforms, and security appliances.
Assess vulnerability applicability and actual organizational risk using CVSS, CISA KEV, EPSS, vendor advisories, available exploits, threat intelligence, system exposure, architecture, compensating controls, and mission impact.
Research emerging and zero-day vulnerabilities and determine potential impact to organizational systems; recommend appropriate remediation, mitigation, monitoring, or risk-acceptance actions.
Administer and maintain enterprise vulnerability assessment and management technologies, including Tenable Security Center/Tenable.sc, Nessus, or comparable platforms.
Develop and manage credentialed vulnerability scanning strategies and troubleshoot scan coverage, authentication, connectivity, and accuracy issues.
Monitor government, commercial, vendor, and open-source cyber threat intelligence and initiate appropriate vulnerability analysis and response activities. Identify false positives, non-applicable findings, superseded vulnerabilities, and scanner limitations requiring additional technical analysis.
Work with system administrators, engineers, ISSOs/ISSMs, and system owners to validate findings and develop practical remediation or compensating-control strategies.