Why This Role Stands Out
This hybrid Senior Vulnerability Analyst role offers a fantastic opportunity to lead critical security initiatives and drive significant impact across a reputable technology company. You'll thrive here if you possess strong analytical skills, a deep understanding of vulnerability management frameworks, and a passion for continuous improvement within a collaborative environment. Apply now to advance your career in cybersecurity and contribute to robust enterprise security.
Quick Overview
Job Description
Seeking an experienced Vulnerability Management professional to lead enterprise vulnerability identification, risk analysis, prioritization, and remediation across infrastructure, applications, endpoints, cloud, and containers.
Key Responsibilities
- Manage vulnerability data from scanners and vulnerability management platforms.
- Prioritize vulnerabilities using CVSS, EPSS, KEV, CWE and business risk.
- Track and drive remediation of high-risk vulnerabilities and SLA escalations.
- Develop dashboards, KPIs, KRIs, reports using Excel and reporting tools.
- Validate findings, analyze exploitability, and identify false positives/detection gaps.
- Partner with application, infrastructure, Threat Intelligence, and Security Operations teams.
- Manage risk acceptance, governance, audit, and compliance activities.
- Identify and implement vulnerability management process improvements.
Required Skills
- 5+ years of experience in Cybersecurity / Vulnerability Management / Security Operations.
- Strong knowledge of CVSS, EPSS, KEV, CWE, OWASP Top 10.
- Advanced Microsoft Excel skills including Power Query and Pivot Tables.
- Experience with Tenable, Qualys, Rapid7, or similar vulnerability scanners.
- Experience with Nucleus Security or similar vulnerability management platforms.
- Windows server/workstation vulnerability assessment experience.
- Knowledge of MSRC, GitHub Security Advisories, Nmap, OWASP ZAP, Nuclei.
- Understanding of PKI, encryption, digital signatures, DNS, and web technologies.
- Strong communication, analytical, and stakeholder-management skills.
Preferred Skills
- Python or PowerShell automation.
- LLM/AI-assisted vulnerability analysis.
- SBOM, container security, dependency management.
- Cloud Security Posture Management (CSPM).
- MITRE ATT&CK and cyber kill-chain concepts.
- Dynamic security analysis and AI-enabled security assessment tools.
Education: Bachelor's degree in Cybersecurity, Computer Science, IT, or related field, or equivalent experience. Security+, CySA+, GSEC, CISSP, or equivalent certifications are preferred.
Similar jobs
- TE
Cyber Security Engineer - New York City, NY, Boston, MA, Hartford, CT, Princeton, NJ, Newark, NJ.
TechniPros, LLC
New York, NY🇺🇸Hybrid1 week agoDockerAWSAzure+8Technology - CE
Senior Firewall Security Analyst
NewComputer Enterprises, Inc.
United States🇺🇸$65 - $75/hrRemote19 hours agoTechnology - MC
Product Security & Business Enablement Lead
NewMariner Careers
United States🇺🇸Remote3 hours agoEncryptionOnboardingProcurement+1 - HA
Director, Identity & Access Management
NewHasbro
Renton🇺🇸Hybrid6 hours agoAWSMFAActive Directory - CY
Security Research Engineer, Attack Surface & Risk Signals
NewCybcube
San Francisco Office🇺🇸Hybrid5 hours agoSQLTCP/IPCornerstone+4 - CR
Senior Threat Detection Engineer
NewCribl
Remote - United States🇺🇸Remote3 hours agoGCPAWSAzure+5Engineering