Remotery

Cybersecurity Threat & Vulnerability Analyst

Posted 6 days ago

This is a fully remote position, open to applicants in Connecticut, +3 more states.

📋 Description

• Design and improve vulnerability scanning strategies across the enterprise landscape.

• Perform internal and external vulnerability assessments and confirm scan results.

• Assess vulnerabilities according to severity, exploitability, and business impact.

• Organize and prioritize assets based on criticality and organizational significance.

• Collaborate with EBTS teams to formulate and implement vulnerability remediation plans within service level agreements (SLAs).

• Monitor and report on remediation activities.

• Evaluate emerging cyber threats and analyze their effects on the technology environment.

• Convey risk exposure, remediation activities, and security recommendations to leadership and stakeholders.

• Create and present weekly and monthly vulnerability management metrics and executive reports.

• Uphold vulnerability management and threat intelligence policies, standards, procedures, and documentation.

• Assist in meeting audit and regulatory requirements by ensuring effective operation of security controls.

• Contribute to the enhancement of the threat hunting program through the development of threat scenarios, response playbooks, and use cases.

• Investigate and address vulnerability findings, false positives, and remediation exceptions.

• Aid in the continuous improvement of the organization’s cybersecurity posture.


⛳️ Requirements

• High School Diploma or GED is required.

• A Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Information Technology, or a related field is preferred.

• Relevant experience may substitute for a degree.

• At least five (5) years of experience in Information Security is required.

• Minimum of three (3) years dedicated to vulnerability identification, assessment, and remediation.

• Experience in a large enterprise environment is preferred.

• Background in supporting security audits, regulatory compliance reviews, and risk management programs is preferred.

• One or more of the following certifications: CISSP, GCTI, GIAC, CompTIA Security+, or Certified Ethical Hacker (CEH) is required or strongly preferred.

• Strong knowledge of cybersecurity frameworks and methodologies, including the Cyber Kill Chain and Defense-in-Depth.

• Extensive understanding of vulnerability management and patch management processes.

• Profound knowledge of Indicators of Compromise (IOCs), Advanced Persistent Threats (APTs), cybercrime techniques, and attacker tactics, techniques, and procedures (TTPs).

• Familiarity with Windows, Linux/Unix, and macOS operating systems.

• Experience with vulnerability management platforms such as Nessus, Qualys, InsightVM (Nexpose), or similar tools.

• Knowledge of CIS benchmarks and Critical Security Controls.

• Understanding of threat intelligence platforms and sources.

• Awareness of cybersecurity audit, regulatory, and compliance requirements.

• Ability to prioritize vulnerabilities and systems based on risk, asset importance, and business consequences.

• Experience with CVSS scoring and risk-based vulnerability management methodologies.

• Proficiency in creating executive-level dashboards, scorecards, and presentations using Microsoft PowerPoint, Visio, and Excel.

• Experience in developing and documenting security processes, standards, and procedures.

• Ability to foster cross-functional collaboration and drive remediation initiatives.

• Experience in negotiating remediation plans, exception requests, SLA extensions, and false-positive determinations.

• Strong project management, organizational, and time management skills.

• Capability to manage multiple priorities in a fast-paced environment.

• Ability to work independently and communicate effectively with stakeholders.

• Candidates must reside in New Jersey, New York, Pennsylvania, Connecticut, or Delaware.


🏝️ Benefits

• Comprehensive health benefits (Medical/Dental/Vision).

• Retirement Plans.

• Generous Paid Time Off (PTO).

• Incentive Plans.

• Wellness Programs.

• Paid Volunteer Time Off.

• Tuition Reimbursement.

People also viewed

Assurant5 hours ago

Cybersecurity Analyst

AR flagArgentina OnlyFull-timeSecurity Analyst
ApplyView job
Fuze Health7 hours ago

Senior Security Analyst

US flagAlabama, +34 more statesFull-timeSecurity Analyst$128.8k – $161k/year
ApplyView job
Hitss Brasil18 hours ago

Senior Information Security Analyst

BR flagBrazil OnlyFull-timeSecurity Analyst
ApplyView job
The Walt Disney Company19 hours ago

Cybersecurity Analyst

US flagUnited States OnlyFull-timeSecurity Analyst$100k – $125k/year
ApplyView job
First Quality19 hours ago

Cyber Security Analyst

US flagFlorida, +3 more statesFull-timeSecurity Analyst$100k – $130k/year
ApplyView job
DaVita Kidney Care20 hours ago

Senior Security Analyst – IT

US flagNew Jersey OnlyFull-timeSecurity Analyst$70k – $106k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers