Cybersecurity Analyst III
Upbound Group
Vulnerability Management Specialist Information Security | Cybersecurity Operations On-Site, Full-Time About The Role This position is the senior technical owner of our enterprise vulnerability management program. The ideal candidate combines deep technical expertise with the communication skills and organizational influence needed to drive risk reduction outcomes across the business. Incident response support is a secondary but meaningful responsibility. Job Purpose The Cybersecurity Analyst III — Vulnerability Management Specialist leads our enterprise vulnerability management program across cloud, endpoint, network, and identity environments. This role is responsible for the full vulnerability lifecycle: continuous discovery and scanning, risk-based prioritization, coordinated remediation, validation, and executive reporting. This is a program leadership role, not simply an analyst seat. The right candidate drives measurable risk reduction by building strong cross‑functional relationships, maintaining clear remediation SLAs, and ensuring the organization consistently moves from vulnerability identification to resolution. In addition to owning the VM program, this analyst supports cybersecurity incident response efforts, contributing environmental knowledge and analytical depth when incidents arise. Key Responsibilities Vulnerability Management Program Leadership (~70–80%) Lead the enterprise vulnerability management lifecycle: asset discovery, continuous scanning, risk-based prioritization, remediation coordination, validation, and reporting. Define and maintain SLA/remediation timelines by risk tier and manage escalation paths for items approaching or exceeding thresholds. Partner with infrastructure, cloud, engineering, application, and endpoint teams to ensure vulnerability findings are clearly communicated, ownership is assigned, and remediation is completed on schedule. Translate vulnerability data into business context: deliver clear reporting for technical teams and concise risk summaries for executive audiences that reflect progress, trends, and areas of focus. Prioritize vulnerabilities using risk-based methodologies that incorporate CVSS scores, EPSS, CISA KEV, asset criticality, business impact, and active threat intelligence — not severity scores in isolation. Maintain a formal risk acceptance and exception process, including documentation of business justification, compensating controls, and expiration timelines. Integrate vulnerability findings into ticketing and ITSM workflows (e.g., ServiceNow, Jira) to ensure every finding has an assigned owner, a due date, and a tracked resolution path. Develop and maintain program KPIs: vulnerability fix rate, mean time to remediate (MTTR), scan coverage, exception aging, and sustained reduction in critical/high exposure. Facilitate regular stakeholder reviews with technology teams to assess remediation progress, surface blockers, and maintain shared accountability for risk outcomes. Continuously refine scanning coverage, tool configurations, and program policies in response to environmental changes and evolving threats. Monitor threat intelligence feeds, vulnerability disclosures, and CISA KEV to identify newly weaponized vulnerabilities that warrant accelerated remediation cycles. Coordinate formal risk acceptance decisions with leadership for findings that cannot be addressed within standard timelines; maintain auditable records of approvals. Incident Response Support (~20–30%) Support cybersecurity incident response activities including triage, containment, eradication, recovery, and post-incident review. Apply vulnerability landscape knowledge and asset inventory familiarity to provide rapid environmental context during active investigations. Participate in incident post-mortems and incorporate findings into vulnerability management program improvements. Contribute to security documentation including runbooks, playbooks, and vulnerability management procedures. Cross-Functional Collaboration & Communication Serve as the primary security point of contact for technology teams on vulnerability obligations, remediation expectations, and risk escalation. Advise technology partners on patch management strategies, configuration hardening, and compensating controls. Support internal audit and compliance engagements by demonstrating control effectiveness against SOX, PCI-DSS, and other applicable frameworks. Promote security awareness among technology partners by providing clear context on why remediation requirements exist and how they protect the organization. Who Thrives Here This role is best suited for a security professional who takes ownership seriously — someone who is as focused on getting vulnerabilities fixed as they are on finding them. If you are energized by building relationships, navigating organizational dynamics, and tracking risk metrics over time, you will find this role deeply rewarding. Required Qualifications Vulnerability Management Expertise 5+ years of experience in cybersecurity operations, with at least 3 years in a role focused on enterprise vulnerability management. Hands‑on experience with enterprise vulnerability scanning platforms such as Tenable (Nessus / Tenable.io / Tenable.sc), Qualys, or Rapid7 InsightVM. Demonstrated experience owning a vulnerability management program end to end, including SLA development, remediation coordination, and stakeholder accountability. Experience integrating vulnerability findings with ITSM or ticketing platforms (ServiceNow, Jira, or equivalent) to operationalize remediation workflows. Strong command of risk-based vulnerability prioritization frameworks: CVSS, EPSS, CISA KEV, asset criticality, and business impact analysis. Experience developing vulnerability metrics, executive dashboards, and program performance reporting. Familiarity with vulnerability lifecycle management practices: risk acceptance, exception handling, compensating controls, and SLA governance. Stakeholder Engagement & Cross-Functional Influence Proven ability to drive remediation outcomes through technology teams (infrastructure, cloud, engineering, application) using influence, communication, and structured accountability — without direct management authority. Strong written and verbal communication skills with the ability to tailor messaging for technical and non-technical audiences alike. Experience facilitating recurring stakeholder forums such as remediation review meetings, and maintaining follow‑through on commitments via escalation when needed. Demonstrated ability to build credibility and collaborative relationships across peer teams. Technical Depth Solid understanding of cloud security in AWS and/or Azure environments, including cloud-native security tooling and logging architectures. Familiarity with endpoint protection, network monitoring, intrusion detection, and IAM platforms. Working knowledge of core network protocols (TCP/IP, DNS, SMTP, etc.). Experience with SIEM platforms and security log analysis. Familiarity with the MITRE ATT&CK framework and how adversary TTPs inform vulnerability prioritization. Foundational knowledge of incident response concepts and practices sufficient to contribute meaningfully when called upon. Preferred Qualifications Relevant certifications: CISSP, GPEN, GWAPT, CompTIA Security+, Tenable Certified, Qualys Certified, or equivalent. Familiarity with SOX and PCI-DSS compliance requirements as they relate to vulnerability and patch management. Experience with exposure management methodologies such as Continuous Threat Exposure Management (CTEM) and attack surface management. Familiarity with SOAR platforms or automation tools used to streamline vulnerability-to-ticket workflows. Experience with Microsoft Defender suite, Rapid7, or comparable enterprise security platforms. Exposure to penetration testing or adversary emulation methodologies to inform vulnerability prioritization. Familiarity with AI-assisted attack techniques and their implications for vulnerability exploit timelines. What Success Looks Like All critical and high vulnerabilities tracked in integrated workflows with clear ownership and due dates. Consistent remediation within defined SLA timelines across technology teams. Measurable, sustained reduction in mean time to remediate (MTTR) for critical and high findings. Reliable executive reporting cadence with meaningful risk trend data. Comprehensive scan coverage across endpoint, cloud, network, and identity environments. Additional Information This position requires on-site presence five days per week (Monday – Friday). Sponsorship Applicants must be authorized to work for any employer in the U.S. We are unable to sponsor or take over sponsorship of an employment visa at this time. Why Join Our Team You will join a collaborative and growing Cybersecurity Operations team where your leadership of the vulnerability management program directly shapes the organization’s security posture. This is a high-visibility role with broad cross‑functional reach, real ownership, and the opportunity to make a measurable difference. If you are looking for a position where your work has clear, demonstrable impact on risk reduction, we want to hear from you. Upbound Group is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. #J-18808-Ljbffr Upbound Group
- ...meaningful work environment that supports and protects explorers and heroes? Join our team! The Program Planning and Scheduling Analyst III leads the development and management of comprehensive project schedules for large-scale and complex programs. This role ensures the...SuggestedFull timeWork at office
- ...implement security policies, procedures, and best practices to ensure compliance with industry standards. Monitor and analyze cybersecurity threats and trends to anticipate and mitigate potential risks. Collaborate with cross-functional teams (IT, legal, compliance...SuggestedWork at officeLocal area
- Job Description: Scrum Master III Technology Operations and Engineering, Digital Business Operations Who We Are At Upbound Group, we are committed to elevating financial opportunity for all through innovative, inclusive, and technology-driven financial solutions that...SuggestedLocal areaMonday to Friday
$95k - $110k
...Cybersecurity Specialist This position is onsite and will be located in either Plano, Texas or Neptune, New Jersey. Relocation assistance is unavailable. This role may require access to technical data or technology governed by U.S. export control laws, including...SuggestedWork experience placementRelocation package- ...your Technology career to the next level.As a Software Engineer III at JPMorgan Chase within the Corporate Sector - Chief... ...assurance of the integrity of staff by virtue of 1) sensitive cybersecurity and technology functions they perform within systems or 2) information...SuggestedWork at office
- ...Get notified about new Information Technology Security Analyst jobs in United States . 1,000+ Information Technology Security Analyst Jobs in United States Information Systems Security Officer (ISSO) Information Systems Security Officer (ISSO) Information Systems Security...
$52.5 per hour
...TERM 6-month contract with high likelihood of extension/conversion to full time employee POSITION OVERVIEW – Marketing Analyst Coordinator III The main function of a marketing analyst/coordinator is to research market conditions in local, regional, or national...Hourly payFull timeContract workLocal areaMonday to Friday- ...to be part of an inclusive, adaptable, and forward-thinking organization, apply now.We are currently seeking a Systems Programming Analyst to join our team in Plano, Texas (US-TX), United States (US).Position OverviewWe are hiring a 77 - FT Supervisor Systems Programming...Permanent employmentWork at officeRemote workFlexible hours
- ...2Technology|Infrastructure Vulnerability Management|Container security Work LocationRichardson, TX CountryUSAState / Region / ProvinceTexasCompanyITL USA Interest GroupInfosys Limited Job RoleTechnology Consultant 1Career RoleTechnology Analyst - USAuto req ID: 149624BRFull timeTemporary workRelocation
- ...part of an inclusive, adaptable, and forward-thinking organization, apply now.We are currently seeking a Lead Systems Programming Analyst to join our team in Plano, Texas (US-TX), United States (US).Linux Restoration and Support Lead - Job DescriptionTeam: Linux Support...Work at officeRemote workFlexible hours
- Company DescriptionArtech is the 10th Largest IT Staffing Company in the US, according to Staffing Industry Analysts' 2012 annual report. Artech provides technical expertise to fill gaps in clients' immediate skill-sets availability, deliver emerging technology skill-...H1bImmediate start
- Company DescriptionSatincorp ( is a market leader and one of the fastest growing IT consulting firms with operations in US, Canada, Mexico & India. SAT is an Oracle Gold Partner, SAP Services Partner & IBM Certified enterprise.We guarantee you the best rate for your skills...
- US Citizens & Permanent Residents ONLY Job Title: Business Analyst III Job Location (Onsite, NO REMOTE): Cary, NC or Carrolton, TX Responsibilities: A Business Analyst III takes a more proactive role in analyzing business needs and translating them into effective technology...Permanent employmentWork experience placementRemote work
$107.5k - $204.5k
...Join us and help shape the future of aerospace and defense.Our cybersecurity team is seeking a Program Information Systems Security Manager... ...Do Cybersecurity Site ISSMs are required to maintain IAM Level III certification commensurate with their role as required by DoDD...Contract workTemporary workWork experience placementWork at officeRemote workRelocation packageFlexible hours- ...Toyota Financial Services (TFS) Technology team is looking for a highly motivated person to fill a role as an Application Security Analyst. Your responsibilities will be to ensure the security of company software applications, web services, and APIs. You will work closely...Relocation packageEarly shift
- ...and operational readiness across critical business and technology environments.The DR Manager collaborates with infrastructure, cybersecurity, cloud, application, network, and business stakeholders to establish recovery objectives, coordinate recovery exercises, manage...Work at officeRemote workFlexible hours
- ...bright future for NTT DATA Services and for the people who work here.NTT DATA Services currently seeks a Information Security Senior Analyst to join our team in Plano, Texas (US-TX), United States (US).Desired candidate will work directly with other Security Systems staff...For contractorsLocal area
- ...of evolving Internet threats to ensure the security of Dell Services Client networks • Participate in knowledge sharing with other analysts and develop customer solutions efficiently • Coordinate or participate in individual or team projects to ensure quality support...Work experience placementLocal areaRemote workAll shiftsShift work
$86.8k - $165.2k
...program/dataset specific processes and standards, and provide training and guidance on tools and methods to other members of the cybersecurity team.What You Will Do:Responsible for assessing and monitoring system compliance, auditing, security plan development, and...Temporary workWork experience placementWork at officeRemote workFlexible hours- Analyst Desired Skills & Experience Analysis of Static Security Vulnerability scan reports generated by the tools ( Veracode, Tenable ) on Magellan application environmentso Remediation recommendations to development teamo Review/Verification of remediations and ensuring...
- Req ID: 137841 Region: Americas Country: USA State/Province: Texas City: Richardson General OverviewFunctional Area: OPS - OperationsCareer Stream: SUP - Operations SupportRole: AnalystSAP Short Name: ANAJob Title: Security AnalystJob Code: ANA-OPS-SECJob Level: Band...Local area
- Req ID:375354NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.We are currently seeking a Information Security Manager to ...Contract workWork at officeRemote workFlexible hours
- Overview Title: Application Security Analyst Duration: 12 Months Location: Plano, TX Pay Rate: $65/hr on W2 (H4, USC, GC, TN) Hybrid... ...Highlight Top 3-5 skills. Bachelor’s degree in Computer Science, Cybersecurity, or related field. 8+ years of experience in DevOps, Security...Remote workShift work
- ...a global scale, come make a difference at Fiserv.Job TitleCybersecurity Architect AdvisorAbout your role:As a Global Enterprise Cybersecurity Architect, you will lead the strategy and design of enterprise-wide security architecture across on-premises, hybrid, and multi-...Full timeTemporary workH1bWork at officeMonday to Friday
$142k - $230k
...work of your career alongside people who are just as passionate as you are, you’re in the right place.Who We AreIn order to be the cybersecurity partner of choice, we must trailblaze the path and shape the future of our industry. This is something our employees work at...Full timeWork at officeShift work$10k
It's an exciting time to join Fisher Investments! We're continuing to invest in the future of our firm's technology and information security. Our business is growing internationally, which emphasizes the need to build an unparalleled global team that inspires future scale...Work at officeWork from home$10k
It's an exciting time to join Fisher Investments! We're continuing to invest in the future of our firm's technology and information security. Our business is growing internationally, which emphasizes the need to build an unparalleled global team that inspires future scale...Work at officeWork from home- OverviewThe Infosys Financial Services unit is a global leader in driving digital transformation for financial institutions. We specialize in leveraging advanced technologies such as AI, cloud, and data-led innovation to help our clients accelerate growth and unlock business...Full timeTemporary workRelocation
- DescriptionThe Implementation Consultant is an impactful, client-facing role responsible for the successful delivery of Tyler’s Enterprise Justice software solutions. This position partners with court and justice agencies to guide them through the end-to-end implementation...
- DescriptionAs a Senior Implementation Consultant, you will serve as a trusted advisor to clients throughout the software implementation lifecycle, helping them successfully adopt and maximize the value of Tyler solutions. In this highly collaborative role, you will combine...Work experience placementWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity Analyst III. Be the first to apply!
- remote cyber security Plano, TX
- cybersecurity administrator Plano, TX
- cyber security Plano, TX
- cyber security incident responder Plano, TX
- cybersecurity software engineer Plano, TX
- cyber security architect Plano, TX
- IT cyber security Plano, TX
- cyber security intern Plano, TX
- cyber security sales Plano, TX
- cybersecurity policy and compliance analyst Plano, TX


