Loading jobs…
Loading jobs…
Berkadia Commercial Mortgage, LLC — Washington, District of Columbia
Revolutional delivers advanced technology solutions and mission support to federal agencies across civilian, health, and national security environments. We apply modern capabilities, including AI/ML, cloud, cybersecurity, and IT modernization to solve complex challenges, enable faster and more secure operations, and drive measurable mission outcomes. We are redefining how federal technology gets built and delivered by operating with a product mindset, prioritizing speed, ownership, and execution over bureaucracy.
Title: Risk and Vulnerability Analyst II Location: Washington, DC or Chandler, AZ Terms: Full-time Clearance: Secret eligibility required Salary Range: $90-140k DOE Travel: 1 0-20% Position Description As a Risk and Vulnerability Analyst II at Revolutional, you own the scanning and vulnerability identification pipeline across a large-scale federal enterprise. You run ad hoc and automated scans across operating systems, databases, web applications, cloud environments, and APIs — and you do it with the precision and consistency that compliance-driven federal programs demand. You are technically skilled and operationally reliable.
You troubleshoot scanning issues before they become coverage gaps, automate what can be automated, and produce findings that give security teams and leadership an accurate picture of enterprise risk. You are organized, customer-focused, and understand that vulnerability management is a service function as much as a technical one.
Responsibilities
Execute ad hoc and automated vulnerability scans across operating systems, databases, and web applications using industry-accepted scanning tools for approximately 200 systems of varying size, scope, and complexity against recurring schedules in accordance with DHS 4300 policy Conduct cloud compliance scans across federal and commercial cloud environments; troubleshoot scanning configuration issues and ensure continuous coverage Perform on-site scanning operations as required, coordinating with system owners and network teams to maintain scan fidelity and minimize operational impact Execute Information Security Vulnerability Management (ISVM) scans and ensure results align with compliance
Requirements
and program reporting standards Conduct API discovery and scanning to identify undocumented or unsecured API endpoints across the enterprise environment Develop and maintain scanning automation to improve coverage, consistency, and efficiency across the vulnerability management program Track high-visibility vulnerability findings through the remediation lifecycle in coordination with the SOC and system personnel Produce clear, accurate scan results and compliance dashboards/reports for technical teams and program leadership Maintain scanning tool configurations, credentials, and schedules; ensure tooling remains current and aligned with the evolving enterprise asset inventory Support vulnerability findings through the remediation lifecycle; coordinate with system owners and security teams to ensure timely closure Produce clear, accurate vulnerability reports and compliance dashboards for technical teams and program leadership Maintain scanning tool configurations, credentials, and schedules; ensure tooling remains current and aligned with the evolving enterprise asset inventory Support continuous monitoring
and contribute to FISMA compliance reporting as it relates to vulnerability management What You Bring (
) Baseline
Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience) 3 to 5 years of security-related experience with a focus on vulnerability management and scanning operations Secret eligibility required Technical Domain Capabilities Hands-on experience with industry-accepted vulnerability scanning tools (e.g., Tenable Nessus, Qualys, Rapid7, or equivalent) for OS, database, and web application scanning Experience conducting cloud compliance scans across commercial