
Cloud Vulnerability, Patch Analyst
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Ohio.
• Perform regular vulnerability assessments across Azure cloud environments utilizing ACAS, Tenable Nessus, Microsoft Defender for Cloud, and various automated tools.
• Evaluate and correlate alerts and logs from Microsoft Sentinel to identify threats, suspicious behaviors, and compliance issues.
• Conduct vulnerability triage, validation, and prioritization in accordance with DoD RMF and CMMC 2.0 standards.
• Create, maintain, and enhance secure baseline configurations for Azure services, virtual machines, containers, and DevSecOps tools.
• Implement and oversee CI/CD-integrated security measures for the early identification of misconfigurations and code vulnerabilities.
• Collaborate effectively with cloud engineers, developers, and ISSO/ISSM personnel to address remediation and corrective actions.
• Generate vulnerability reports, dashboards, POA&M updates, and compliance documentation.
• Assist in ongoing monitoring and security automation efforts.
• Engage in threat hunting and security analysis leveraging threat intelligence sources.
• Offer cybersecurity guidance, training, and technical advice to DevSecOps stakeholders.
• Execute additional tasks as needed.
• Must be a U.S. citizen.
• Possession of an active Secret security clearance.
• Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related technical discipline (or equivalent practical experience).
• Practical experience with vulnerability scanning tools such as ACAS, Tenable Nessus, Microsoft Defender for Cloud, or comparable enterprise solutions.
• Proficient understanding of Microsoft Azure, including security architecture, identity management, and best practices for cloud configuration.
• Familiarity with DoD RMF (NIST SP 800-53 r5) and CMMC 2.0 / NIST SP 800-171 security controls.
• Experience in analyzing security events using SIEM platforms like Microsoft Sentinel.
• Strong grasp of vulnerability management principles, secure configuration standards, and cybersecurity best practices.
• Capability to produce clear documentation, communicate findings, and work collaboratively with DevSecOps, engineering, and compliance teams.
• Successful completion of a background investigation including criminal history and identity verification.
• Competitive benefits package within the industry.
• Recognition and awards program.
• Personalized support from ARS Senior Managers.
• Emphasis on work/life balance.
• Opportunities for career development and a culture that prioritizes employee well-being.
Republic Services
Curtiss-Wright Corporation
Get handpicked remote jobs straight to your inbox weekly.