SRS Distribution

Sr Cyber Security Analyst- Vulnerability Management

SRS Distribution • $110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, IT, Engineering, or related field (or equivalent experience).
  • 5+ years of experience in Cybersecurity, Vulnerability Management, or Cyber Security Operations.
  • Experience with enterprise Vulnerability Management tools like Wiz, CrowdStrike, Rapid7, or Nagomi.
  • Strong knowledge of vulnerability assessment methods across diverse environments (Windows, Linux, cloud).
  • Excellent analytical skills to assess technical risks and remediation strategies.

Responsibilities

  • Lead enterprise Vulnerability Management program activities, including identification and remediation.
  • Administer and optimize Vulnerability Management tools and technologies.
  • Conduct vulnerability assessments across various technology environments.
  • Validate and prioritize vulnerabilities based on risk factors and business context.
  • Collaborate with various technology teams to ensure successful remediation of vulnerabilities.
  • Analyze and report on vulnerability trends and risks within the enterprise.

Benefits

  • Opportunities for professional development and training in cybersecurity.
  • Access to advanced vulnerability management technologies.
  • Supportive hybrid work environment offering flexibility.
  • Collaborative team environment with cross-departmental projects.
Full Job Description

Position Purpose:

The Senior Cyber Security Analyst at the company will serve as a senior hands-on technical resource within Cyber Security Operations, with primary responsibility for enterprise Vulnerability Management and secondary responsibility for supporting Cyber Operations activities associated with mergers and acquisitions. This role is responsible for identifying, validating, prioritizing, tracking, and helping drive remediation of vulnerabilities across
the enterprise.


The Senior Cyber Security Analyst will work extensively with vulnerability and exposure management technologies such as Wiz, CrowdStrike, Rapid7, and Nagomi to improve visibility, prioritize risk, validate findings, and measure reduction of security exposure. The position will also provide hands-on technical support during mergers and acquisitions by assessing acquired environments, identifying vulnerabilities and cybersecurity gaps, onboarding assets into established security processes, validating remediation activities, and helping transition acquired environments into standard Cyber Operations practices.


The Senior Cyber Security Analyst will report directly to the Cyber Security Operations Manager and will receive technical direction and engineering guidance from the Cybersecurity Staff Engineer.

Key Responsibilities:

  • Serve as a senior hands-on technical resource for the enterprise Vulnerability Management program, supporting vulnerability identification, validation, prioritization, remediation, and closure.
  • Administer, maintain, optimize, and support Vulnerability Management and exposure management technologies, including Wiz, CrowdStrike, Rapid7, Nagomi, and related platforms.
  • Perform vulnerability assessments across enterprise technology environments, including servers, workstations, network devices, cloud-hosted assets, applications, and other technology assets.
  • Analyze and validate vulnerability findings to reduce false positives and ensure remediation efforts are focused on legitimate cybersecurity risk.
  • Prioritize vulnerabilities using risk-based factors such as vulnerability severity, known exploitation, internet accessibility, asset criticality, business impact, threat intelligence, exploitability, compensating controls, and exposure paths.
  • Identify and prioritize vulnerabilities associated with active exploitation, zero-day vulnerabilities, CISA Known Exploited Vulnerabilities, emerging threats, and other high-risk security conditions.
  • Coordinate with Infrastructure, Network, Cloud, Application, and other technology teams to drive vulnerability remediation activities through completion.
  • Track vulnerabilities throughout the full lifecycle, including identification, validation, remediation, mitigation, exception, risk acceptance, and closure.
  • Perform technical validation following remediation to confirm vulnerabilities and exposures have been successfully addressed.
  • Identify recurring vulnerabilities, systemic weaknesses, and remediation challenges and recommend technical or process improvements.
  • Develop and maintain Vulnerability Management procedures, standards, runbooks, dashboards, operational documentation, and reporting.
  • Support vulnerability exception and risk acceptance processes by providing technical analysis, exposure information, and compensating-control considerations.
  • Perform vulnerability trend analysis and identify areas of increasing enterprise risk or recurring exposure.
  • Serve as a primary hands-on technical resource for Nagomi, supporting integrations, exposure analysis, security control validation, and risk-based prioritization.
  • Correlate vulnerability data, asset context, threat intelligence, and control information within Nagomi to improve remediation prioritization and identify areas of security exposure.
  • Analyze Nagomi findings to identify control gaps, vulnerabilities, security configuration issues, and opportunities to reduce enterprise exposure.
  • Develop vulnerability and exposure metrics that demonstrate remediation progress, vulnerability aging, recurring risk, coverage, and measurable reduction of security exposure.
  • Serve as a hands-on Cyber Operations resource supporting mergers, acquisitions, and business integrations.
  • Execute assigned Cyber Operations activities during M&A discovery, assessment, onboarding, and integration efforts.
  • Perform technical security discovery and vulnerability assessments within acquired environments to identify cybersecurity risks, vulnerabilities, unmanaged assets, unsupported technologies, security configuration weaknesses, and technical debt.
  • Establish an initial vulnerability and exposure baseline for acquired environments.
  • Assist with onboarding acquired assets into enterprise Vulnerability Management and exposure management technologies and processes.
  • Perform vulnerability scans, technical assessments, validation activities, and follow-up testing required during acquisition integration.
  • Analyze M&A security findings and provide actionable remediation recommendations to the appropriate technology teams.
  • Validate patches, configuration changes, mitigations, and other corrective actions implemented during M&A remediation efforts.
  • Track assigned M&A cybersecurity findings and Cyber Operations activities through completion.
  • Work closely with Infrastructure, Network, Cloud, Application, Identity, GRC, and other technology teams to complete assigned cybersecurity integration activities.
  • Assist with transitioning acquired environments into established Vulnerability Management processes, remediation workflows, reporting standards, and Cyber Operations practices.
  • Support automation, API integrations, reporting, and workflow improvements that increase the efficiency and scalability of Vulnerability Management activities.

Direct Manager Direct Reports:

  • The Senior Cyber Security Engineer will report directly to the Cyber Security Operations Manager.
  • This role does not have any direct reports.
  • The Senior Cyber security Engineer will receive technical direction, eguidance, standards, and technical prioritization from the Cybersecurity Staff Analyst.
  • The position will work closely with Cyber Security Operations, Cyber Engineering, Infrastructure, Network, Cloud, Application, Identity, GRC, and other technology teams to drive vulnerability remediation and support M&A Cyber Operations activities.

Travel Requirements:

  • The Senior Cyber Security Engineer may be required to travel occasionally to support mergers and acquisitions, cybersecurity assessments, acquired-company integration activities, technical meetings, or other business requirements.
  • Travel may include visits to acquired organizations, branch locations, data centers, offices, or other company facilities as needed to support hands-on Cyber Operations activities.

Physical Requirements:

  • The Senior Cyber Security Engineer position involves working in a standard office environment, with duties requiring extended periods of sitting, standing, and computer use.
  • The role requires the ability to communicate effectively with technical teams, business partners, leadership, and other stakeholders both verbally and in written form.
  • Occasional travel may be necessary to attend meetings, assessments, site visits, or M&A integration activities.

Working Conditions:

  • The Senior Cyber Security Engineer role is designed to operate within a hybrid work environment, blending both in-office and remote work arrangements to support flexibility, collaboration, and productivity.
  • The position operates in a fast-paced Cyber Security Operations environment where priorities may shift based on vulnerability severity, emerging threats, active exploitation, business risk, mergers and acquisitions, and remediation requirements.
  • The role requires the ability to independently manage multiple technical priorities while maintaining strong communication and coordination with Cyber Security, IT, and business stakeholders.
  • The Senior Cyber Security Engineer is expected to work collaboratively with technical teams to drive measurable reduction in enterprise vulnerability exposure and support the secure integration of acquired environments.

Minimum Qualifications:

  • Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, Engineering, or a related technical field from an accredited institution, or equivalent combination of education and professional experience.
  • At least 5 years of progressive experience in Cybersecurity, Vulnerability Management, Security Engineering, Cyber Security Operations, or a related technical discipline.
  • Strong hands-on experience with enterprise Vulnerability Management technologies and processes.
  • Demonstrated experience using vulnerability or exposure management technologies such as Wiz, CrowdStrike, Rapid7, Nagomi, or comparable platforms.
  • Strong understanding of vulnerability identification, validation, prioritization, remediation, mitigation, exception handling, and closure.
  • Strong knowledge of CVE, CVSS, CISA Known Exploited Vulnerabilities, EPSS, threat intelligence, exploitability, and risk-based vulnerability prioritization.
  • Experience assessing vulnerabilities across Windows, Linux, network, cloud-hosted, application, and enterprise infrastructure environments.
  • Demonstrated ability to analyze vulnerability findings across multiple data sources and determine appropriate remediation or mitigation actions.
  • Experience working with Infrastructure, Network, Cloud, Application, and other technology teams to drive vulnerability remediation through completion.
  • Strong analytical and problem-solving skills with the ability to distinguish technical severity from actual organizational risk.
  • Experience developing vulnerability reporting, dashboards, remediation metrics, technical documentation, procedures, and operational standards.
  • Strong written and verbal communication skills with the ability to communicate technical risks and remediation requirements to both technical and non-technical stakeholders.
  • Demonstrated ability to independently manage multiple priorities and technical workstreams within a fast-paced Cyber Security Operations environment.

Preferred Qualifications:

  • Hands-on experience supporting cybersecurity activities associated with mergers, acquisitions, divestitures, or large-scale technology integrations.
  • Experience performing technical vulnerability assessments of newly acquired environments.
  • Experience establishing vulnerability and exposure baselines for acquired or newly integrated organizations.
  • Experience onboarding acquired assets into enterprise Vulnerability Management technologies and processes.
  • Advanced experience with Wiz, CrowdStrike vulnerability capabilities, Rapid7, Nagomi, or similar vulnerability and exposure management technologies.
  • Experience with attack surface analysis, exposure management, security control validation, and risk-based vulnerability prioritization.
  • Experience using APIs, scripting, or automation to integrate security technologies, automate vulnerability workflows, or improve reporting capabilities.
  • Experience developing and maintaining vulnerability dashboards, executive reporting, remediation metrics, and operational performance indicators.
  • Experience working within a large, distributed enterprise containing multiple business units, locations, technology platforms, and acquired organizations.
  • Strong understanding of enterprise vulnerability remediation processes, including patching, configuration management, mitigation, exceptions, and risk acceptance.
  • Experience identifying systemic vulnerability patterns and recommending long-term engineering or process improvements.
  • Relevant cybersecurity certifications are preferred.

Minimum Education:

  • A Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, Engineering, or a related technical field is preferred. Equivalent professional experience may be considered in lieu of a degree.

Preferred Education:

  • A Bachelor’s or Master’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, Engineering, or a related technical discipline is preferred.

Minimum Years Of Work Experience:

  • 5 years of progressive experience in Cybersecurity, Vulnerability Management, Security Engineering, Cyber Security Operations, or a related technical discipline.

Certifications:

  • Preferred: Certified Information Systems Security Professional (CISSP).
  • Preferred: GIAC Security Essentials (GSEC), GIAC Certified Incident Handler (GCIH), or other relevant GIAC certification.
  • Preferred: CompTIA Security+ or CySA+.
  • Preferred: Vendor-specific certifications related to vulnerability management, exposure management, cloud security, or security operations technologies.

Competencies:

1. Vulnerability Management Expertise:

Demonstrated ability to identify, validate, prioritize, track, and drive
remediation of enterprise vulnerabilities using risk-based methodologies and
multiple security data sources.

2. Technical Analysis:

Strong analytical capability to investigate complex vulnerability findings,
validate technical risk, distinguish severity from actual exposure, and
determine appropriate remediation or mitigation actions.

3. Risk-Based Prioritization:

Ability to evaluate vulnerabilities using business context, asset criticality,
exploitation activity, threat intelligence, exposure, and compensating controls
rather

About SRS Distribution

SRS Distribution is a building materials distribution company based in McKinney, Texas. The company was founded in 2008 and has since grown to become one of the largest distributors of roofing and other building materials in the United States. SRS Distribution operates a network of more than 300 locations across 44 states. The company's mission is to provide its customers with high-quality products and exceptional service. SRS Distribution is known for its strong relationships with its suppliers and its commitment to innovation and sustainability.
Learn more about SRS Distribution
Size
5,000 employees
Industry
Net Income
$100 million
Founded
2008
5 Year Trend
+30%
Revenue
$5 billion
NASDAQ

Similar Jobs

More Jobs at SRS Distribution

More Information Technology Jobs

Find similar Sr Cyber Security Analyst- Vulnerability Management jobs: