We are seeking for a Vulnerability Management Analyst to support daily operations of our vulnerability assessment platform. This role involves executing scheduled scans, managing asset groupings, tracking remediation efforts, and generating dashboards and reports. The ideal candidate is detail-oriented, collaborative, and eager to grow in the cybersecurity and risk management field.
- Execute scheduled and ad-hoc vulnerability scans, including discovery, compliance, and web application scans.
- Monitor scan schedules and ensure timely completion across in-scope systems and assets.
- Manage and update asset groupings, scan configurations, and scan credentials within the VA platform.
- Analyze scan findings, generate posture reports, and escalate critical issues based on defined SLAs.
- Support in generating weekly vulnerability dashboards and monthly executive summary reports.
- Track remediation activities in collaboration with server, network, and application teams; provide timely updates.
- Assist in agent deployment, configuration, and troubleshooting across supported assets.
- Conduct ad-hoc scanning requests from internal audit, risk, or operational teams and prepare tailored reports.
- Support documentation and SOPs related to scanning procedures, asset onboarding, and credential management.
- Contribute to audit readiness by maintaining accurate records of scans, findings, and remediation status.
- Collaborate with the SME and security teams in maintaining platform stability, versioning, and health.
Experience:
- Hands-on experience with VA platforms such as Qualys, Tenable, or Rapid7.
- Basic understanding of asset discovery, vulnerability scoring (CVSS), and common remediation strategies.
- Strong attention to detail and ability to track multiple remediation efforts across different teams.
Soft Skills:
- Strong analytical and problem-solving abilities with keen attention to detail.
Preferred Certifications
- Tenable Certified Analyst or Qualys Certified Specialist or similar certifications
- GIAC Security Essentials (optional)