
Vulnerability Analyst IV
Posted Aug 6

Posted Aug 6
This is a fully remote position, open to applicants in Utah.
• Conduct thorough research on newly identified vulnerabilities across operating systems, application software, infrastructure, and firewalls.
• Act as a senior technical leader within the Security Operations Center (SOC).
• Oversee the organization-wide strategies for vulnerability management.
• Investigate, analyze, and devise methods for exploiting vulnerabilities.
• Execute Security Impact Analysis to evaluate the effects of system changes on overall security.
• Lead sophisticated cyber vulnerability assessments for applications, systems, vendor IT networks, and cloud architecture.
• Analyze and validate scan results, correlate findings, assess severity and risk impact, and prioritize remediation efforts.
• Maintain systems for tracking vulnerabilities, dashboards, and compliance reports.
• Create and present reports, briefs, and metrics to leadership.
• Perform risk assessments on IT systems, applications, and business processes, and suggest improvements for security controls.
• Manage risk registers utilizing threat intelligence and vulnerability data.
• Develop and implement cybersecurity risk assessments and mitigation strategies.
• Collaborate with administrators, DevOps teams, researchers, the Change Advisory Board (CAB), and the IT Tech Debt Committee to address vulnerabilities.
• Lead remediation initiatives with system owners and senior security personnel.
• Utilize threat modeling, penetration testing, and exploit development techniques in both on-premises and cloud environments.
• Prepare regular updates on vulnerabilities and executive-level summaries.
• Assist with incident-response investigations and propose enhancements to system defenses.
• Design and deliver training on vulnerability management, remediation, and secure system design.
• Provide expert assistance to SOC Tier 1 and Tier 2 analysts for threat detection and incident response.
• Report directly to the SOC Manager.
• Bachelor’s degree in Cybersecurity, Information Technology, or a related field.
• Six (6) years of experience in cybersecurity, with at least four years dedicated to vulnerability analysis, penetration testing, or cyber risk management.
• Strong comprehension of security frameworks, including NIST and MITRE ATT&CK.
• Experience with vulnerability scanning tools.
• Familiarity with Endpoint Detection and Response (EDR) solutions.
• Exceptional communication, analytical, and problem-solving abilities.
• In-depth knowledge of NIST, ISO/IEC 27001, and HITRUST frameworks.
• Preferred relevant certifications such as CISSP, CISM, CEH, CND, GCIA, or GCIH.
• Preferred experience in healthcare or laboratory settings.
• Preferred master's degree in Cybersecurity, Information Technology, or a related field.
• Availability to work Monday–Friday, 40 hours per week, from 8:00 AM to 5:00 PM.
• Ability to adhere to ARUP policies and procedures.
• Capability to operate in a biohazard laboratory environment and utilize necessary PPE in alignment with CDC and OSHA regulations and company policies.
• Ability to fulfill physical requirements, including occasional mobility between work sites and within the office, sedentary tasks, fine motor control, and close, far, and peripheral visual acuity.
• Opportunities for professional growth and ongoing development.
• A work environment that emphasizes diversity.
• Provision of personal protective equipment in accordance with CDC and OSHA regulations and company policies.
Assurant
Fuze Health
Hitss Brasil
The Walt Disney Company
Get handpicked remote jobs straight to your inbox weekly.