
Cybersecurity Threat & Vulnerability Analyst
Posted 6 days ago

Posted 6 days ago
This is a fully remote position, open to applicants in Connecticut, +3 more states.
• Design and improve vulnerability scanning strategies across the enterprise landscape.
• Perform internal and external vulnerability assessments and confirm scan results.
• Assess vulnerabilities according to severity, exploitability, and business impact.
• Organize and prioritize assets based on criticality and organizational significance.
• Collaborate with EBTS teams to formulate and implement vulnerability remediation plans within service level agreements (SLAs).
• Monitor and report on remediation activities.
• Evaluate emerging cyber threats and analyze their effects on the technology environment.
• Convey risk exposure, remediation activities, and security recommendations to leadership and stakeholders.
• Create and present weekly and monthly vulnerability management metrics and executive reports.
• Uphold vulnerability management and threat intelligence policies, standards, procedures, and documentation.
• Assist in meeting audit and regulatory requirements by ensuring effective operation of security controls.
• Contribute to the enhancement of the threat hunting program through the development of threat scenarios, response playbooks, and use cases.
• Investigate and address vulnerability findings, false positives, and remediation exceptions.
• Aid in the continuous improvement of the organization’s cybersecurity posture.
• High School Diploma or GED is required.
• A Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Information Technology, or a related field is preferred.
• Relevant experience may substitute for a degree.
• At least five (5) years of experience in Information Security is required.
• Minimum of three (3) years dedicated to vulnerability identification, assessment, and remediation.
• Experience in a large enterprise environment is preferred.
• Background in supporting security audits, regulatory compliance reviews, and risk management programs is preferred.
• One or more of the following certifications: CISSP, GCTI, GIAC, CompTIA Security+, or Certified Ethical Hacker (CEH) is required or strongly preferred.
• Strong knowledge of cybersecurity frameworks and methodologies, including the Cyber Kill Chain and Defense-in-Depth.
• Extensive understanding of vulnerability management and patch management processes.
• Profound knowledge of Indicators of Compromise (IOCs), Advanced Persistent Threats (APTs), cybercrime techniques, and attacker tactics, techniques, and procedures (TTPs).
• Familiarity with Windows, Linux/Unix, and macOS operating systems.
• Experience with vulnerability management platforms such as Nessus, Qualys, InsightVM (Nexpose), or similar tools.
• Knowledge of CIS benchmarks and Critical Security Controls.
• Understanding of threat intelligence platforms and sources.
• Awareness of cybersecurity audit, regulatory, and compliance requirements.
• Ability to prioritize vulnerabilities and systems based on risk, asset importance, and business consequences.
• Experience with CVSS scoring and risk-based vulnerability management methodologies.
• Proficiency in creating executive-level dashboards, scorecards, and presentations using Microsoft PowerPoint, Visio, and Excel.
• Experience in developing and documenting security processes, standards, and procedures.
• Ability to foster cross-functional collaboration and drive remediation initiatives.
• Experience in negotiating remediation plans, exception requests, SLA extensions, and false-positive determinations.
• Strong project management, organizational, and time management skills.
• Capability to manage multiple priorities in a fast-paced environment.
• Ability to work independently and communicate effectively with stakeholders.
• Candidates must reside in New Jersey, New York, Pennsylvania, Connecticut, or Delaware.
• Comprehensive health benefits (Medical/Dental/Vision).
• Retirement Plans.
• Generous Paid Time Off (PTO).
• Incentive Plans.
• Wellness Programs.
• Paid Volunteer Time Off.
• Tuition Reimbursement.
Fuze Health
Hitss Brasil
The Walt Disney Company
Get handpicked remote jobs straight to your inbox weekly.