AFL Global

IT Threat and Vulnerability Management Analyst (Hybrid Office Schedule)

AFL Global • $80K — $95K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, IT, Cybersecurity, or equivalent experience.
  • 2+ years in vulnerability management, security operations, or IT infrastructure.
  • Hands-on experience with vulnerability management or scanning platforms.
  • Knowledge of Windows and Linux patching processes.
  • Familiarity with CVSS, EPSS, and CISA Known Exploited Vulnerabilities catalog.
  • Ability to articulate vulnerability risks in simple terms.
  • Understanding of networking fundamentals, including segmentation and firewall rules.
  • Preferred experience with specific tools like Horizon3 NodeZero, CrowdStrike, and scripting in Python or PowerShell.

Responsibilities

  • Run scheduled discovery and assessment cycles across the environment.
  • Maintain asset coverage and ensure data accuracy.
  • Triage findings daily, ranking exposures by exploitability and criticality.
  • Execute attack path validation assessments and translate findings into remediation tasks.
  • Confirm exploitability before escalating severity of findings.
  • Create and track remediation tickets with clear guidance for teams.
  • Drive remediation efforts to closure, following up on aging findings.

Benefits

  • Hybrid work schedule based in Duncan, SC.
  • Occasional availability outside standard hours for maintenance.
  • Standard office environment with access to manufacturing floors.
  • Flexibility to travel to other AFL sites as needed.
Full Job Description
We are seeking an IT Threat and Vulnerability Management Analyst to join our global IT organization in Duncan, SC. Under general direction, this role executes AFL's continuous threat exposure management program across both the corporate network and the manufacturing environments behind it. The incumbent runs discovery and validation cycles, triages findings by real exploitability, and drives remediation to closure with Systems, Network, and Application teams. Success is measured by remediated exposures, not the number of tickets created.

Responsibilities

  • Run scheduled discovery, scanning, and assessment cycles across the environment. Maintain scan schedules, credential health, and sensor coverage.
  • Maintain asset coverage and data accuracy. Investigate gaps where systems appear in one data source and not another.
  • Triage findings daily. Rank exposures by exploitability, asset criticality, and network exposure, and reconcile duplicate or conflicting findings before assigning work.
  • Execute attack path validation assessments on defined scopes and schedules. Translate validated attack paths into prioritized remediation work.
  • Confirm exploitability in the AFL environment before escalating severity.
  • Create and track remediation tickets with clear technical guidance for the owning team.
  • Drive remediation to closure. Follow up on aging findings, escalate service level breaches, and verify fixes through retest.
  • Maintain the exception and risk acceptance queue, including expiration tracking and renewal review.
  • Identify recurring exposures and root cause patterns, and raise them for upstream correction.
  • Produce exposure metrics and dashboards for IT leadership and technical teams, and prepare exposure data for audit and compliance requests.


Qualifications

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity or equivalent work experience.
  • Two or more years in vulnerability management, security operations, systems administration, or IT infrastructure.
  • Hands-on use of a vulnerability management or scanning platform.
  • Working knowledge of Windows and Linux patching, including how updates deploy and why they fail.
  • Understanding of CVSS, and awareness of EPSS and the CISA Known Exploited Vulnerabilities catalog.
  • Ability to read a vulnerability finding and explain the actual risk in plain terms.
  • Networking fundamentals, including segmentation and firewall rule review.
  • Clear written communication and persistence in a matrixed environment.
  • Preferred: Horizon3 NodeZero, CrowdStrike Falcon Exposure Management, Tanium, Qualys, Tenable, or Rapid7; scripting or reporting automation in Python, PowerShell, or SQL; ServiceNow; and manufacturing or OT patching experience.
  • Certifications in one of the following preferred, but not required: Security+, GCIH, GFACT, GEVA, or vendor certifications for the deployed security platforms.


Personal Qualities

  • Follows remediation work to closure across teams outside the security function.
  • Separates the findings that matter from the findings that merely score high.
  • Builds credibility with systems, network, and application engineers.
  • Catches coverage gaps and data discrepancies others overlook.
  • Writes remediation guidance an engineer will act on.


Working Conditions

  • Hybrid schedule based onsite in Duncan, SC.
  • Occasional availability outside standard business hours to support patch windows and production maintenance schedules.
  • Standard office environment. Occasional access to manufacturing floors where hearing protection and personal protective equipment are required.
  • Flexibility to travel to AFL sites if needed.

About AFL Global

AFL Global is a leading provider of integrated solutions in the fiber optics industry. The company offers a wide range of products and services, including fiber optic cable, connectivity, and accessories, as well as engineering, installation, and maintenance services. AFL Global serves a variety of industries, including telecommunications, broadband, electric utility, and enterprise.
Learn more about AFL Global
Size
5,000 employees
Industry
Founded
1984

Similar Jobs

More Jobs at AFL Global

More Information Technology Jobs

Find similar IT Threat and Vulnerability Management Analyst (Hybrid Office Schedule) jobs: