Responsibilities
- Support vulnerability scanning operations including scan scheduling, asset grouping, tagging, and policy configuration.
- Review and validate vulnerability scan results to reduce false positives and improve data accuracy.
- Analyze vulnerability data to identify trends, recurring issues, and remediation priorities.
- Assist in assessing and prioritizing vulnerabilities using defined risk-based methodologies.
- Collaborate with IT, infrastructure, and application teams to communicate findings and remediation requirements.
- Track remediation progress, open risks, and system ownership for accountability and reporting.
- Assist with vulnerability assessments and validate remediation effectiveness.
- Contribute to vulnerability management documentation, playbooks, and runbooks.
- Participate in process improvement initiatives including automation and reporting enhancements.
- Stay informed on emerging threats and escalate significant risks when identified.
Requirements
- 5+ years of experience in cybersecurity, with a strong focus on vulnerability management, security operations, or risk-based security programs
- Good understanding of vulnerability scanning, remediation workflows, and vulnerability lifecycle.
- Hands-on experience or exposure to tools such as Qualys, Tenable, or similar platforms.
- Familiarity with Linux and Windows operating systems and basic networking concepts.
- Strong analytical and problem-solving skills.
- Good written and verbal communication skills, with the ability to work effectively with technical teams.
- Strong analytical skills with experience building dashboards, metrics, and executive-level reporting.
- Ability to support after-hours coordination or incident response activities as needed.
Nice to Have
- Exposure to scripting or automation using Bash or PowerShell.
- Familiarity with security frameworks such as OWASP Top 10, NIST, or ISO 27001.
- Relevant security certifications (Security+, CySA+, Cloud+, or similar).
- Bachelor’s degree in computer science, Cybersecurity, Information Technology, or equivalent experience.
Work Arrangement
Remote (Worldwide)
Additional Information
- Work hours may vary, and the position may require availability during off-business hours as dictated by project needs, system changes, or security events.