Drive remediation accountability across technology and business stakeholders.
Develop executive-level reporting and metrics for leadership forums.
Lead responses to major vulnerabilities including zero-day threats and high-profile CVEs.
Identify systemic vulnerability trends and suggest strategic improvements.
Collaborate with various teams to validate findings and enrich vulnerability data.
Implement dashboards and automation for program efficiency and reporting.
Provide mentorship to junior analysts and lead during complex investigations.
Benefits
Opportunity to work on enterprise-scale cybersecurity initiatives.
Collaboration with diverse teams including Threat Intelligence and Incident Response.
Access to industry-leading security tools and platforms.
Platform for influencing senior leadership on cybersecurity strategies.
Engagement in continuous improvement initiatives in vulnerability management.
Full Job Description
Job Purpose and Impact
The Senior Vulnerability Management Analyst safeguards the organization's digital assets by leading the identification, assessment, prioritization, and remediation of cybersecurity vulnerabilities across the global enterprise. This role serves as a trusted advisor and technical leader, driving enterprise vulnerability management strategy, governance, and continuous improvement initiatives. With minimal supervision, the Senior Analyst partners with cybersecurity, infrastructure, cloud, engineering, risk, and business leaders to reduce organizational exposure and improve cyber resilience.
Key Accountabilities
Leading enterprise-wide vulnerability management and exposure reduction programs.
Performing advanced analysis of vulnerability data from tools such as Tenable, Qualys, Rapid7, Wiz, and cloud-native security platforms.
Establishing risk-based prioritization methodologies that incorporate threat intelligence, exploit activity, business criticality, and compensating controls.
Driving remediation accountability and governance across technology and business stakeholders.
Developing executive-level reporting, metrics, and risk insights for leadership and governance forums.
Leading major vulnerability response efforts related to zero-day threats, actively exploited vulnerabilities, and high-profile CVEs.
Identifying systemic vulnerability trends and recommending strategic improvements to reduce recurring risk.
Partnering with Threat Intelligence, Threat Hunting, Red Team, Incident Response, and Security Architecture teams to validate and enrich findings.
Leading continuous improvement efforts related to scanning coverage, asset visibility, attack surface management, and remediation effectiveness.
Designing and implementing dashboards, automation, and integrations to improve program efficiency and reporting.
Consulting on security architecture, cloud adoption, and remediation strategies across on-premises and cloud environments.
Mentoring junior analysts and providing technical leadership during complex investigations and remediation efforts.
Demonstrating deep expertise in CVSS, EPSS, MITRE ATT&CK, threat modeling, and cyber risk management frameworks.
Providing strategic guidance for remediation across Windows, Linux, networking, cloud platforms (AWS, Azure, GCP, OCI), containers, and modern enterprise technologies.
Qualifications
Minimum requirement of 5 years of relevant work experience with relevant cybersecurity, vulnerability management, attack surface management, or exposure management experience.
Typically reflects 7+ years of relevant experience.
Experience leading enterprise-scale vulnerability management, exposure management, or cyber risk reduction initiatives preferred.
Demonstrated experience influencing senior leaders and driving cross-functional remediation efforts.
Relevant industry certifications such as CISSP, GSEC, GIAC, Security+, CySA+, AWS Security, Azure Security Engineer, or equivalent are preferred