Daniel Vermilyea
Vulnerability Analyst
Benton, United States
#OpenToWork
About
Senior Cyber Security professional with nearly 30 years of enterprise IT experience, supporting desktop and server administration, and vulnerability management and compliance programs across federal and commercial environments.
Deep expertise in designing, implementing, and optimizing Tenable-based vulnerability management solutions, including large-scale deployments built from the ground up.
Strong background in credentialed and agent-based scanning, vulnerability lifecycle management, and remediation and validation across hybrid infrastructure.
Experienced supporting cloud and on-premises environments with a focus on vulnerability scanning, compliance auditing, operational efficiency, and enterprise service improvement.
Known for strong troubleshooting capabilities, cross-team collaboration, and mentoring technical teams.
What I'm looking for
Looking for a position in Vulnerability Management.
Experience
Manager of IT Risk Mitigation
Velera
Dec 2024 – Mar 2026
Manage and mentor a team of engineers responsible for enterprise vulnerability and patch management operations. Oversee vulnerability intake from multiple sources including internal scanning, external assessments, and third-party testing. Direct triage, prioritization, and remediation workflows to align with compliance requirements including PCI-DSS, SOC 2, and CIS. Coordinate remediation efforts with system owners and track progress through ServiceNow ticketing and POAM processes. Perform remediation and validation activities to confirm successful resolution of vulnerabilities. Develop and maintain policies, standard operating procedures, and work instructions for vulnerability and patch management.
Vulnerability managementPCI-DSSServiceNowTenableTanium
Senior Tenable Engineering Consultant
Insight Global
Jun 2024 – Nov 2024
Provided SME-level support for enterprise vulnerability management services across multiple large-scale environments. Engineered and optimized Tenable scanning environments including Tenable.sc, Tenable.io, Nessus scanners, Nessus Agents, and Nessus Manager clusters. Supported development and improvement of vulnerability and compliance auditing strategies across diverse infrastructure. Assisted in improving scan accuracy, credentialed scanning configurations, and overall vulnerability program effectiveness. Advised on enterprise vulnerability workflows, remediation strategies, and operational efficiencies.
Tenable.scTenable.ioNessus ScannerNessus ManagerNessus Agents
Cyber Security Analyst Lead
GDIT
Apr 2017 – May 2024
Served as subject matter expert for the enterprise vulnerability scanning solution supporting the Judiciary Branch, Administrative Office of the U.S. Courts. Led engineering, deployment, and ongoing support for the national vulnerability scanning platform utilizing the Tenable suite. Provided guidance and training to internal teams and government customer personnel on vulnerability identification and mitigation strategies. Supported reporting, metrics development, and overall vulnerability program operations. Mentored team members and assisted Judiciary personnel in resolving complex vulnerability scanning and remediation challenges.
Tenable suiteTrainingServiceNowCyberArk
Security Systems Engineer (ACAS SME)
NCI, Inc.
Apr 2016 – Mar 2017
Served as SME for the Tenable Assured Compliance Assessment Solution (ACAS) supporting U.S. Army enterprise environments. Provided Tier III engineering support and guidance aligned with USCYBERCOM and NETCOM cybersecurity requirements. Developed scan policies, compliance configurations, and supporting technical documentation. Supported DISA STIG auditing and CCRI assessment preparation activities
Tenable (ACAS)DISA STIGTechnical Documentation
Cyber Security Analyst
Teksystems
Jan 2016 – Apr 2016
Provided guidance to Tenable scan team. Supported certification and accreditation efforts for enterprise systems under RMF and DIACAP frameworks. Validated implementation of security controls and DISA STIG requirements. Assisted in achieving high-performance CCRI assessment results.
Tenable (ACAS)DISA STIGRMFDIACAPCCRI
Security Systems Engineering Specialist II
Harris Corporation
Aug 2013 – Dec 2015
Engineered, deployed, and maintained ACAS vulnerability scanning solution for US Navy ONENET Europe. Transitioned enterprise scanning platform from Retina to Tenable ACAS. Led vulnerability identification, reporting, and mitigation across large-scale network environments. Collaborated with system owners and administrators to implement remediation strategies.
Beyond Trust RetinaTenable (ACAS)Vulnerability AnalysisComplianceDISA STIG
Senior Systems Administrator / Information Assurance Analyst
ITT/Exelis
Jul 2004 – Jul 2013
Supported enterprise server environments including deployment, configuration, and maintenance of Microsoft infrastructure. Managed vulnerability scanning and compliance reporting using enterprise vulnerability management tools. Assisted in remediation efforts and security compliance across operational environments.
Microsoft infrastructureVulnerability scanningCompliance reporting
Education
Holton High School
High School Diploma · General
1985 – 1989
Certifications
CompTIA Security+
CompTIA
Skills
Tenable SuitePatchMyPCIvantiTaniumSplunkCyberArkServiceNowDISA STIGSOC 2PCI-DSSNISTLinux ServersWindows ServersCloud environmentsAgent-based scanningCredentialed scanningQualysRapid7Nessus
Languages
English (Native or bilingual proficiency)