Vulnerability Management Analyst (Information Security Specialist 2)
$77.38k - $117.5kCommonwealth of Pennsylvania
$77,379.00 - $117,497.00 Annually
LocationDauphin County, PA
Job TypeCivil Service Permanent Full-Time
Job NumberCSSC-2026-50087-01518
DepartmentExecutive Offices
DivisionEX OA Entrprs Info Scy Off
Opening Date06/03/2026
Closing Date6/16/2026 11:59 PM Eastern
Job Code01518
Position Number00047176
UnionNon Union
Bargaining UnitA3
Pay GroupST09
Bureau / Division Code00812072
Bureau / DivisionEnterprise Information Security Office
Worksite Address400 North Street
CityHarrisburg, Pennsylvania
Zip Code17120
Contact NameMatthew Zyroll
Contact PhoneView phone number on click.appcast.io
Contact EmailView email address on click.appcast.io
THE POSITIONThe Vulnerability Management Analyst position with the Office of Administration offers a chance to protect state systems while growing valuable technical skills. in this vital role, you will actively participate in actions that reduce the threat landscape and help reduce risk to the Commonwealth and its data. You will join a team that works to spot and prevent weaknesses before they become problems. Apply today and support the safety of digital tools used across the Commonwealth.
DESCRIPTION OF WORKThis role focuses on scanning technology, identifying risks, and supporting the security of Commonwealth systems. As a Vulnerability Management Analyst, you will perform the following duties:
- Scan Oversight: Conduct vulnerability scans across hosts, applications, and networks
- Asset Coverage: Review configurations and ensure all Commonwealth assets receive required assessments
- Issue Resolution: Troubleshoot problems that occur during or after scanning activities
- Data Review: Analyze scan results and other information to reduce vulnerabilities and risk
- Tool Management: Support management of scanners, agents, and information security software
- Team Support: Assist analysts who perform application level scanning and help maintain security standards
Interested in learning more? Additional details regarding this position can be found in the position description.
Work Schedule and Additional Information:
- Full-time employment
- Work hours are 8:00 AM to 5:00 PM, Monday - Friday, with 60-minute lunch.
- Telework: You may have the opportunity to work from home (telework) part-time. Position will be required to work in the office two days per week. In order to telework, you must have a securely configured high-speed internet connection and work from an approved location inside Pennsylvania. If you are unable to telework, you will have the option to report to the headquarters office in Harrisburg. The ability to telework is subject to change at any time. Additional details may be provided during the interview.
- Salary: In some cases, the starting salary may be non-negotiable.
- You will receive further communication regarding this position via email. Check your email, including spam/junk folders, for these notices.
QUALIFICATIONS
Minimum Experience and Training Requirements:
- One year as an Information Security Specialist 1 (Commonwealth job title or equivalent Federal Government job title, as determined by the Office of Administration); or
- Three years of experience performing technical work in information technology security, and an associate's degree in any information technology field; or
- One year of experience performing technical work in information technology security, and a bachelor's degree in any information technology field; or
- An equivalent combination of experience and training.
Other Requirements:
- This particular position also requires two or more years of full-time professional experience troubleshooting Enterprise networks or Enterprise network related issues.
- You must meet the PA residency requirement. For more information on ways to meet PA residency requirements, follow the link and click on Residency Guidelines.
- You must be able to perform essential job functions.
Legal Requirements:
- You must pass a background investigation and meet Criminal Justice Information Services (CJIS) compliance requirements.
- A conditional offer of employment will require an in-depth Pennsylvania State Police background check.
How to Apply:
- Resumes, cover letters, and similar documents will not be reviewed, and the information contained therein will not be considered for the purposes of determining your eligibility for the position. Information to support your eligibility for the position must be provided on the application (i.e., relevant, detailed experience/education).
- If you are claiming education in your answers to the supplemental application questions, you must attach a copy of your college transcripts for your claim to be accepted toward meeting the minimum requirements. Unofficial transcripts are acceptable.
- Your application must be submitted by the posting closing date . Late applications and other required materials will not be accepted.
- Failure to comply with the above application requirements may eliminate you from consideration for this position.
- All application materials and interview responses must reflect the applicant's own experience, qualifications, and work. Applicants may use generative AI tools for preparation purposes only. Use of AI to misrepresent or falsify information, or to assist during interviews, is not permitted. Review the Guidance for Generative AI Tools & Job Seekers for additional information.
Veterans:
- Pennsylvania law (51 Pa. C.S. *7103) provides employment preference for qualified veterans for appointment to many state and local government jobs. To learn more about employment preferences for veterans, go to and click on Veterans.
Telecommunications Relay Service (TRS):
- 711 (hearing and speech disabilities or other individuals).
If you are contacted for an interview and need accommodations due to a disability, please discuss your request for accommodations with the interviewer in advance of your interview date.
The Commonwealth is an equal employment opportunity employer and is committed to a diverse workforce. The Commonwealth values inclusion as we seek to recruit, develop, and retain the most qualified people to serve the citizens of Pennsylvania. The Commonwealth does not discriminate on the basis of race, color, religious creed, ancestry, union membership, age, gender, sexual orientation, gender identity or expression, national origin, AIDS or HIV status, disability, or any other categories protected by applicable federal or state law. All diverse candidates are encouraged to apply.
EXAMINATION INFORMATION- Completing the application, including all supplemental questions, serves as your exam for this position. No additional exam is required at a test center (also referred to as a written exam).
- Your score is based on the detailed information you provide on your application and in response to the supplemental questions.
- Your score is valid for this specific posting only.
- You must provide complete and accurate information or:
- your score may be lower than deserved.
- you may be disqualified.
- You may only apply/test once for this posting.
- Your results will be provided via email.
$77.38k - $117.5k
.../ Division: Enterprise Information Security Office Worksite Address... ...THE POSITION The Vulnerability Management Analyst position with the Office... ...an Information Security Specialist 1 (Commonwealth job title... ...WORK BEHAVIOR 2 - SECURITY DESIGN AND CUSTOMIZATION...SuggestedPermanent employmentFull timePart timeWork experience placementWork at officeLocal areaRemote workWork from homeMonday to FridayFlexible hours2 days per week$76.4k - $138.6k
...fueled by vast amounts of information. Data is more valuable than... ...in EY Information Security has a critical role to play... ...As an Offensive Security Analyst on the Vulnerability Management team, you will play a supporting... ...0-EY-HELP3, select Option 2 for candidate related inquiries...SuggestedSummer holidayLocal areaFlexible hours$90k - $109k
...eliminate data and cyber security risks. Designs and develops... ...testing to discover and exploit vulnerabilities to test the effectiveness... ...with a minimum of 2+ years in information security, penetration testing... ...considered in any personnel or management decisions. We affirm our...SuggestedContract workWork at office- ...Expert (SME) for DLA's NIPRNet and SIPRNet enclaves, supporting vulnerability management and cyber compliance for all assigned software, hardware,... ...Responsible for validation of compliance with established security configurations leveraging defined baselines such as...Suggested
$89.51k - $116.36k
...Job Posting See below for important information regarding this job. Position will be filled at any of the locations listed below. Site specific salary information as follows: Battle Creek, MI: $89,508 - $ 116,362 Columbus, OH: $93,400 - $121,422 Dayton,...Suggested- ...Business Analyst 2 The Department of Education is seeking a motivated Business Analyst... ...description. Work Schedule and Additional Information: Full-time employment Work... .... In order to telework, you must have a securely configured high-speed internet...Full timePart timeTraineeshipWork at officeLocal areaRemote workWork from homeMonday to Friday1 day per week
$59.35k - $90.21k
...Division: Transportation Program Management Office Worksite Address:... ...a detail oriented Business Analyst 2 to oversee system... ...system needs, gathering useful information, and helping teams keep applications... ...telework, you must have a securely configured high-speed...Permanent employmentFull timePart timeFor contractorsTraineeshipWork experience placementWork at officeLocal areaRemote workWork from homeMonday to FridayFlexible hours- ...NIPRNet and SIPRNet enclaves, supporting vulnerability management and cyber compliance for all assigned... ...of compliance with established security configurations leveraging defined baselines... ...Summary To qualify for an IT Specialist (INFOSEC), your resume and supporting...Full timeRemote work
$71.4k - $133.8k
...Title FirstEnergy Service Co. Asset Management Systems Analyst Job Description FirstEnergy at... ...Substation Maintenance engineers, Information Technology, and other internal stakeholders... ...Develop and implement user and data security enhancements to improve Cascade data...Full timeContract workWork experience placementH1b$105.79k - $141.05k
...connected ecosystem. We enable secure, high‑performance connectivity... .... The Role The Senior Information Security Auditor is an experienced... ...member of a team to manage the execution of multiple security... ...with 4+ years of experience. ~2-3 years practical experience...Full timeTemporary workRemote work$79.3k
...responsible for the implementation and program management of value-based payment arrangements.... ...programs, and provider contact information, as well as records for auditing purposes... ...Policies and Procedures as well as all data security guidelines established within the...Contract workFor contractorsWork at officeLocal area- ...implement support tickets, assist documenting and managing incidents and vulnerabilities, perform network monitoring and reporting, and... .../Desired Amount of Experience Experience in information security related support Required 2.0 Years Experience in helpdesk related...Contract workRemote work
- ...Services & Insurance IT Security Engineering Advisor Sr PRIMARY... ...PURPOSE OF THE ROLE: To manage the implementation of... ...computer systems, networks and information. Identifies and defines system... ...in mitigating security vulnerabilities and automating repeatable tasks...Work at officeLocal area
- ...Fortune Best Workplaces in Financial Services & Insurance IT Security Manager PRIMARY PURPOSE OF THE ROLE: To manage and advance the... ...and performance criteria, data security requirements and information technology skills. Develops and maintains productive internal...Work at officeLocal area
- ...Job Title: Technical Security Risk & Governance Analyst Location:... ...risk registers. Vulnerability & Third-Party Risk:... ...governance for vulnerability management (SLAs, exception... ...providers), evaluate SOC 2/ISO certifications,... ...: Provide risk-informed guidance during...
$71.2k - $158.2k
...Job Description The Senior Federal Information Systems Security Engineer (ISSE) serves as a technical integrator responsible for ensuring that... ...stakeholders to gather system connectivity details, generate and manage Ports, Protocols, and Services Management (PPSM)...Contract workTemporary workWork experience placementRelocationFlexible hours- ...people thrive when empowered with better information. Teradata Autonomous Knowledge Platform... ...‑looking recommendations that support security, reliability, compliance, and... ...established risk frameworks (e.g., NIST Risk Management Framework) to identify control gaps, assess...Permanent employmentRemote workFlexible hours
- ...Conducts proactive research to analyze security weaknesses and recommends appropriate... ...initiatives/issues for one or more Information Security Strategy/Cybersecurity functional... ..., Threat Hunting, Forensics, Vulnerability Management, Data Analytics) Assists in the development...Full timeWork experience placementWork at officeLocal area
$94.2k
...: JOB SUMMARY This job secures AI/ML, Generative AI, and agentic... ...LLM Top 10 to assess and manage AI security risks; contribute... ...security (Azure, GCP, AWS) ~2 years of experience in Detection... ...Science, Computer Engineering, Information Technology, Cybersecurity, or...For contractorsWork at officeLocal areaRemote work- ...highly focused on Performance Management and Performance Metrics... ...understanding of measuring and rating vulnerabilities based on principal... ...of conducting Offensive Security and/or Red Team exercises against... ...and internet facing information systems and infrastructure...
$98.9k
...What you can expect The Security Engineer is responsible for security design and... ...functionalities. This includes identifying security vulnerabilities such as those in the OWASP Top Ten,... ...'s degree in Computer Science, Information Science, Cyber Security, Computer or...Work at officeRemote work- ...Command Group, keeping leadership informed on crucial matters while... ...facilities, preparing agendas, managing invitations, and operating front... ...To qualify for a Management Analyst, your resume and supporting documentation... ...equivalent graduate degree or 2 full years of progressively...Full timeWork at officeRemote work
$68.4k
.... *** The Business Systems Analyst serves as a subject‑matter expert... ..., Architects, Capability Managers, and other team members to capture... ...in Business Management, Information Systems, or closely related field... ...as well as all data security guidelines established within...Contract workFor contractorsWork at officeLocal area$79.54k - $113.63k
...Platform Security Engineer 2 At HDR, our employee-owners are fully engaged in creating a welcoming... ...and hardening standards for VCF management and workload domains. Conduct recurring... ...Qualifications: Bachelor's degree in Information Technology, Cybersecurity, Computer Science...Full timeTemporary workPart timeMonday to FridayShift work$100k - $126k
...eliminate high level data and cyber security risks. Designs, tests and... ...Degree preferred. ~2-3 years overall experience and 2-3 years experience managing vulnerability management systems and /or scanning... ...Comprehensive knowledge of information security and security...Contract workWork at office- ...~ Location: 100% Remote. -Security Architect - Consultant 9309 . Employment Type: W2 Only (No Subcontractors)Contract Duration... ...security awareness and understanding Bachelor's degree in an information technology or information security related field; OR 8+ years...Contract workWork experience placementFor subcontractorRemote work
$17.5 per hour
...Patrol Security Officer GardaWorld Security Services is now hiring a Patrol Security Officer... ...schedule: Full-time, Monday-Friday, Days 2:00PM-10:00PM (40 Hours Per Week)... ...verifying identity, and guiding visitors Manage access control Perform regular patrols...Hourly payFull timeWork at officeLocal areaImmediate startAll shiftsMonday to Friday10 hours per week- ...Description Job Description IT Security Support Specialist *This is a hybrid position with 2 days/week onsite... ...performing technical work in information technology security and... ...tickets assist documenting and managing incidents and vulnerabilities perform network monitoring...For contractors2 days per week
$122.21k - $211.32k
...Information Systems Security Engineer (ISSE) - Navy Job Locations US-PA-Mechanicsburg Job... ...Computer Science or Information Science or Management or related study ~ DoD 8570... ...data communications Two (2)+ years of experience with AWS, GCP or...Full timeContract workLocal area- ...Position Overview: JMA Resources is seeking an Information Systems Security Officer to support Risk Management Framework activities for information systems... ...control implementation, assessment, documentation, vulnerability management, and remediation activities. The ISSO...Full timeContract workRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vulnerability Management Analyst (Information Security Specialist 2). Be the first to apply!
- order management analyst Harrisburg, PA
- vendor management analyst Harrisburg, PA
- business analyst part time remote Harrisburg, PA
- senior business analyst contract Harrisburg, PA
- business development analyst Harrisburg, PA
- senior business development analyst Harrisburg, PA
- knowledge management analyst Harrisburg, PA
- deloitte business technology analyst Harrisburg, PA
- remote business analyst Harrisburg, PA
- business analyst Harrisburg, PA


