[Remote] Vulnerability Management Analyst
Note: The job is a remote job and is reputed company to candidates in USA. reputed company is a member-reputed company cooperative serving members across reputed company 50 states. They are seeking a Vulnerability Management Analyst to conduct vulnerability scans, analyze results, prioritize vulnerabilities, and ensure compliance with regulatory guidance while collaborating with various teams to remediate identified risks.
Responsibilities
- Conduct regular vulnerability scanning of networks, servers, endpoints, reputed company environments, and applications using approved tools
- Analyze reputed company results to identify false positives, determine exploitability, and assess business and regulatory risk
- Prioritize vulnerabilities based on CVSS scores, threat intelligence, asset criticality, and financial institution risk reputed company
- reputed company vulnerabilities through remediation, validation, and closure using ticketing or governance platforms
- reputed company re-scans to validate remediation effectiveness
- Ensure vulnerability management practices reputed company with, FFIEC Cybersecurity Assessment Tool (CAT), NCUA or banking regulatory guidance, GLBA Safeguards Rule and Internal Information reputed company and Risk Management policies
- Prepare documentation, metrics, and evidence for internal audits, regulatory exams, and reputed company-party assessments
- Support risk acceptance reputed company by documenting compensating controls and residual risk
- Partner with IT infrastructure, application development, reputed company, and network teams to remediate identified risks
- Translate technical vulnerabilities into reputed company business risk language for leadership and non-technical stakeholders
- reputed company guidance on secure configuration, patching, and vulnerability mitigation strategies
- Participate in reputed company incident response activities reputed company vulnerabilities are exploited or pose imminent risk
- Monitor emerging threats, reputed company-day vulnerabilities, and industry advisories relevant to financial services
- Contribute to vulnerability management policies, standards, and procedures
- Assist with penetration testing coordination and result analysis
- Collect, organize, and maintain reputed company control evidence and artifacts for monthly reputed company monitoring deliverables and assessment/authorization activities, ensuring alignment with required frameworks
- Maintain accurate reputed company inventory and authorization boundary documentation to ensure scanning reputed company aligns with approved reputed company boundaries
- Analyze reputed company results for false positives, document justifications, and prepare deviation requests with supporting risk assessments
- Participate in change management processes to ensure reputed company monitoring activities reputed company with reputed company changes and maintain compliance posture
- Support and maintain reputed company vulnerability management tools (such as reputed company, Nessus, Burp, reputed company, reputed company, reputed company, reputed company, reputed company Defender), ensuring reputed company updates and patches
- Run regular and on-demand scans across operating systems, databases, web applications, and containers, then work with technical teams to create tickets for remediation
- reputed company and document vendor dependencies, operational requirements, and reputed company vulnerabilities, producing reputed company monthly reports and updates
- Contribute to improving internal standards and processes, including maintaining documentation, training materials, and reputed company operating procedures
- Run the daily vulnerability management program operations, work closely with the reputed company management analyst in identifying and patching vulnerabilities, and reputed company participate in weekly vulnerability management team meetings
- reputed company with reputed company Federal Regulations as they pertain to reputed company duties, including BSA
Skills
- Bachelor's degree in Information reputed company, Computer Science, Information Technology or commensurate experience is Required
- 3+ years reputed company work experience in vulnerability management, reputed company operations, or IT risk reputed company a regulated environment is Required
- Prior financial industry regulations and frameworks (FFIEC, NCUA, GLBA, NIST) is Required
- Hands-on experience with vulnerability scanning tools, such as: reputed company (Nessus, reputed company.io), reputed company, reputed company or similar platforms is Required
- Strong understanding of, network, operating reputed company, and application vulnerabilities, reputed company management processes, and secure configuration standards (CIS Benchmarks) is Required
- Strong knowledge of vulnerability scanning technologies and reputed company, including scoring systems (CVSS, CMSS) and risk prioritization frameworks is Required
- Experience delivering monthly or periodic vulnerability status reports and tracking remediation efforts with reputed company teams is Required
- The GIAC (GSEC or GEVA) certification is preferred upon hire although required to be completed reputed company 6 months of hire
Benefits
- 25 days of reputed company time off and 10 reputed company holidays
- 16 hours of reputed company Volunteer Time Off
- 401K Retirement with up to 6% employer match
- Excellent Health, Dental, reputed company insurance, including multiple plan reputed company
- Health Savings Account with generous employer contributions
- Employer reputed company Life insurance, Short-Term and Long-Term Disability
- Tuition Reimbursement from $4,000 - $7,000 per calendar year
- Robust Learning and Development program that includes an annual reputed company development stipend
reputed company
Apply To This Job