Vulnerability Assessment Analyst (Fort Bragg, NC) in Fort Bragg, North Carolina at Akira Technologies Inc.
Explore Related Opportunities
Job Description
Akira Technologies is seeking a Vulnerability Assessment Analyst to support the U.S. Army Reserve Command (USARC) in cyberspace operations supporting Army and joint requirements. The Vulnerability Assessment Analyst will plan and execute cybersecurity assessments under the Computer Defense Assistance Program (CDAP), including Network Assistance Visits (NAV), Network Damage Assessments (NDA), and web application assessments. The analyst will validate suspected compromises, identify vulnerabilities and intrusion depth, and recommend mitigation, recovery, and prevention actions.
This is an onsite position at Fort Bragg, NC supporting a mission-focused U.S. Army Reserve Command cyberspace operations environment. Active Secret clearance or higher is required.
Key Responsibilities
- Plan and execute CDAP integrated assessment missions, including NAV, NDA, and web assessments, in accordance with AR 380-53, applicable Rules of Engagement (ROE), and ARCYBER/RCC procedures.
- Conduct NAV activities including pre-coordination, network surveys, technical support, customized training, briefings, and final reporting.
- Respond to approved NDA requests within four hours of notification when directed; validate suspected compromises, determine intrusion scope, collect logs and forensic artifacts, and support onsite incident handling.
- Assist affected administrators with securing compromised networks and provide situational-awareness updates to leadership during active assessments.
- Coordinate assessment activities with ARCYBER, supported RCC personnel, ISSOs, mission owners, system administrators, and other stakeholders.
- Prepare formal NDA reports within five business days and NAV final reports within 30 calendar days, using approved reporting and handling procedures.
- Conduct annual web application assessments of registered public-facing websites using approved tools such as OWASP ZAP, Burp Suite Professional, Nessus Web Application Security Scanner, or successor tools.
- Analyze and validate assessment findings, including XSS, SQL injection, embedded credentials, exposed services, and other common vulnerabilities, while minimizing false positives and maximizing attack-vector coverage.
- Coordinate remediation validation and conduct 30/60/90-day retesting, based on finding severity and applicable requirements.
- Maintain authorized assessment tools in accordance with applicable DISA STIG/SRG requirements and Government-approved configurations.
- Ensure required authorization documentation, including current Letters of Authorization and APTC or equivalent credentials, is in place before conducting authorized testing against production systems.
- Maintain accurate assessment documentation, findings, evidence, remediation status, and technical reports.
- Perform other vulnerability assessment and DCO support duties as required.
Required Qualifications
- Army Penetration Testing Course (APTC) or equivalent credential required for personnel performing Persistent Penetration Testing under applicable PWS requirements.
- Active Secret security clearance at a minimum; TS/SCI eligibility/access where required by the assigned work role or supported network.
- Demonstrated experience with vulnerability assessment and web application security tools, including ACAS, Nessus, Burp Suite Professional, and/or OWASP ZAP, and exploitation frameworks such as Metasploit and Cobalt Strike.
- Proficiency in CVSSv3 scoring, vulnerability analysis, web application security testing, and network penetration-testing methodologies.
- Experience conducting cybersecurity assessments under formal Rules of Engagement (ROE) in a DoD environment.
- Experience identifying, validating, documenting, and prioritizing vulnerabilities and providing actionable remediation recommendations.
- Ability to work effectively in a classified, mission-focused environment and support operational requirements, including short-notice travel when required.
Preferred Qualifications
- Experience supporting Army, Army Reserve, ARCYBER, or joint cyberspace operations.
- Experience with CDAP, Network Assistance Visits, Network Damage Assessments, or similar DoD cybersecurity assessment programs.
- Familiarity with MITRE ATT&CK, OWASP Top 10, CVE, and CVSS.
- Experience with forensic artifact collection and compromise assessments.
- Familiarity with DISA STIGs/SRGs and DoD cybersecurity requirements.
- Relevant penetration testing, vulnerability management, or cybersecurity certifications are a plus.
Salary Range: $85,000 to $100,000
Akira’s pay range for this position considers various factors including skills, years of experience, training, licenses, certifications, alignment with market data, and internal equity in the organization. This pay range estimate is a general guideline only and not a guarantee of compensation or salary, which Akira believes to be done in good faith in compliance with local laws. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. It is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case.
General Description of Benefits
Akira offers its employees multiple options for medical plans (some with Health Savings Account), dental plans, and vision coverage, and a 401(k) plan with employer match. To promote work/life balance, Akira offers paid time off, including vacation and sick time, holidays, paid parental leave, military leave, bereavement leave, and jury duty leave. We also offer short and long-term disability benefits to protect employee income in the event of sickness or injury, life insurance, accidental death and dismemberment insurance, and critical illness insurance. Akira also offers tuition, training, and certification reimbursement for professional development and career advancement.
Akira regularly reviews our total rewards package to ensure our offerings remain competitive and reflect the values and needs expressed by our employees.
About Akira Technologies
Akira strives to meet and exceed the mission and objectives of US federal agencies. As a leading small business cloud modernization and data analytics services provider, we deliver trusted and highly differentiated solutions and technologies that serve the needs of our customers and citizens. Akira serves as a valued partner to essential government agencies across the intelligence, cyber, defense, civilian, and health markets. Every day, our employees deliver transformational outcomes, solving the most daunting challenges facing our customers.
Akira is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.