Daniel Vermilyea

Daniel Vermilyea

Vulnerability Analyst

Benton, United States

#OpenToWork

About

Senior Cyber Security professional with nearly 30 years of enterprise IT experience, supporting desktop and server administration, and vulnerability management and compliance programs across federal and commercial environments. Deep expertise in designing, implementing, and optimizing Tenable-based vulnerability management solutions, including large-scale deployments built from the ground up. Strong background in credentialed and agent-based scanning, vulnerability lifecycle management, and remediation and validation across hybrid infrastructure. Experienced supporting cloud and on-premises environments with a focus on vulnerability scanning, compliance auditing, operational efficiency, and enterprise service improvement. Known for strong troubleshooting capabilities, cross-team collaboration, and mentoring technical teams.

What I'm looking for

Looking for a position in Vulnerability Management.

Experience

Velera

Manager of IT Risk Mitigation

Velera

Dec 2024 – Mar 2026

Manage and mentor a team of engineers responsible for enterprise vulnerability and patch management operations. Oversee vulnerability intake from multiple sources including internal scanning, external assessments, and third-party testing. Direct triage, prioritization, and remediation workflows to align with compliance requirements including PCI-DSS, SOC 2, and CIS. Coordinate remediation efforts with system owners and track progress through ServiceNow ticketing and POAM processes. Perform remediation and validation activities to confirm successful resolution of vulnerabilities. Develop and maintain policies, standard operating procedures, and work instructions for vulnerability and patch management.

Vulnerability managementPCI-DSSServiceNowTenableTanium
Insight Global

Senior Tenable Engineering Consultant

Insight Global

Jun 2024 – Nov 2024

Provided SME-level support for enterprise vulnerability management services across multiple large-scale environments. Engineered and optimized Tenable scanning environments including Tenable.sc, Tenable.io, Nessus scanners, Nessus Agents, and Nessus Manager clusters. Supported development and improvement of vulnerability and compliance auditing strategies across diverse infrastructure. Assisted in improving scan accuracy, credentialed scanning configurations, and overall vulnerability program effectiveness. Advised on enterprise vulnerability workflows, remediation strategies, and operational efficiencies.

Tenable.scTenable.ioNessus ScannerNessus ManagerNessus Agents
GDIT

Cyber Security Analyst Lead

GDIT

Apr 2017 – May 2024

Served as subject matter expert for the enterprise vulnerability scanning solution supporting the Judiciary Branch, Administrative Office of the U.S. Courts. Led engineering, deployment, and ongoing support for the national vulnerability scanning platform utilizing the Tenable suite. Provided guidance and training to internal teams and government customer personnel on vulnerability identification and mitigation strategies. Supported reporting, metrics development, and overall vulnerability program operations. Mentored team members and assisted Judiciary personnel in resolving complex vulnerability scanning and remediation challenges.

Tenable suiteTrainingServiceNowCyberArk
NCI, Inc.

Security Systems Engineer (ACAS SME)

NCI, Inc.

Apr 2016 – Mar 2017

Served as SME for the Tenable Assured Compliance Assessment Solution (ACAS) supporting U.S. Army enterprise environments. Provided Tier III engineering support and guidance aligned with USCYBERCOM and NETCOM cybersecurity requirements. Developed scan policies, compliance configurations, and supporting technical documentation. Supported DISA STIG auditing and CCRI assessment preparation activities

Tenable (ACAS)DISA STIGTechnical Documentation
Teksystems

Cyber Security Analyst

Teksystems

Jan 2016 – Apr 2016

Provided guidance to Tenable scan team. Supported certification and accreditation efforts for enterprise systems under RMF and DIACAP frameworks. Validated implementation of security controls and DISA STIG requirements. Assisted in achieving high-performance CCRI assessment results.

Tenable (ACAS)DISA STIGRMFDIACAPCCRI
Harris Corporation

Security Systems Engineering Specialist II

Harris Corporation

Aug 2013 – Dec 2015

Engineered, deployed, and maintained ACAS vulnerability scanning solution for US Navy ONENET Europe. Transitioned enterprise scanning platform from Retina to Tenable ACAS. Led vulnerability identification, reporting, and mitigation across large-scale network environments. Collaborated with system owners and administrators to implement remediation strategies.

Beyond Trust RetinaTenable (ACAS)Vulnerability AnalysisComplianceDISA STIG

Senior Systems Administrator / Information Assurance Analyst

ITT/Exelis

Jul 2004 – Jul 2013

Supported enterprise server environments including deployment, configuration, and maintenance of Microsoft infrastructure. Managed vulnerability scanning and compliance reporting using enterprise vulnerability management tools. Assisted in remediation efforts and security compliance across operational environments.

Microsoft infrastructureVulnerability scanningCompliance reporting

Education

Holton High School

Holton High School

High School Diploma · General

1985 – 1989

Certifications

ITIL Foundation 4

ITIL

CompTIA A+

CompTIA

CompTIA Security+

CompTIA

Skills

Tenable SuitePatchMyPCIvantiTaniumSplunkCyberArkServiceNowDISA STIGSOC 2PCI-DSSNISTLinux ServersWindows ServersCloud environmentsAgent-based scanningCredentialed scanningQualysRapid7Nessus

Languages

English (Native or bilingual proficiency)