Security Analyst, Incident Response & Vulnerability Management
Eclipse Foundation, Inc.
Overview The Eclipse Foundation is one of the world’s largest open source software foundations, with a proven track record of enabling developer-focused open source innovation earned over 19 years. The Foundation is the home of numerous industry-leading projects and collaborations including Adoptium, Software Defined Vehicle, Eclipse IDE, IOT and Jakarta EE. Supported by over 350 members globally, the Foundation has an established international reach and reputation. The Role We are looking for a junior-to-mid-level Security Analyst to join our Security Team. This role will focus primarily on incident response and vulnerability management, including the responsible use of automation and AI-assisted workflows where they improve accuracy, consistency, or efficiency. Working closely with the Head of Security, you will help monitor, investigate, document, and respond to security issues affecting Eclipse Foundation systems, services, and open source projects. You will also support vulnerability management activities by reviewing findings, helping prioritize remediation, coordinating with internal and external teams, and tracking issues through to resolution. This role is complementary to our AI-assisted vulnerability management engineering work. You will not be expected to design large-scale AI security pipelines. Instead, you will help operate and support incident response and vulnerability management workflows, using security tooling, automation, and AI-assisted approaches responsibly as part of day-to-day security operations. You will not be expected to handle major incidents alone. This is a hands-on role for someone with solid security fundamentals, careful documentation habits, good judgment, and a willingness to learn while working across technical and organizational boundaries. Location and Term This is an initial 12-month fixed-term role, fully remote and open to candidates located in the European Union, Canada, and the United States . Depending on organizational needs, funding, performance, and mutual fit, there may be an opportunity for renewal or transition to an ongoing/permanent position. Responsibilities Monitor, triage, and investigate security alerts, events, reports, and potential incidents. Assist with initial analysis, evidence gathering, containment coordination, documentation, and post-incident follow-up. Help maintain and improve incident response procedures, playbooks, templates, checklists, and related documentation. Review vulnerability scan results and security reports, validate findings, assess potential impact, and help prioritize remediation. Track vulnerabilities and remediation work across teams, ensuring issues are clearly documented and followed through to closure. Work with internal stakeholders, project teams, and other collaborators to communicate findings, risks, and recommended remediation steps in a clear and practical way. Help identify contributing factors behind incidents or recurring vulnerabilities and suggest practical improvements. Assist with access reviews, security assessments, risk reviews, and related operational security tasks. Contribute to improvements in security tooling, automation, reporting, dashboards, and operational workflows. Help promote a security-aware culture through practical guidance, documentation, and collaboration with technical and non-technical teams. Day-to-Day Work Day-to-day work may include reviewing vulnerability scanner output, preparing incident notes, following up on remediation tasks, reviewing evidence, updating playbooks, helping maintain security dashboards, and supporting teams in understanding what action is needed to address security risks. Success in This Role Success in this role means helping the Eclipse Foundation operate incident response and vulnerability management workflows in a consistent, reliable, and well-documented way. You will be successful if security alerts, incidents, and vulnerability findings are triaged carefully, documented clearly, followed up appropriately, and tracked through to resolution. You will help ensure that stakeholders understand what action is needed, that sensitive information is handled responsibly, and that security processes become easier to repeat and improve over time. This role does not require deep expertise in every security domain from day one. Success depends on sound judgment, attention to detail, clear communication, willingness to learn, and the ability to ask for help when needed. Education A degree in cybersecurity, computer science, information technology, or a related field is welcome but not required. We value equivalent practical experience, professional training, and relevant certifications. This role is suitable for someone with early-to-mid career experience in security operations, incident response, vulnerability management, IT security, or a related area. We do not expect candidates to have deep expertise in every area. We are looking for someone with solid fundamentals, good judgment, careful documentation habits, and a willingness to learn. Desired Skills and Experience We are looking for someone who is curious, pragmatic, and service-oriented. The successful candidate will be comfortable investigating technical issues, asking thoughtful questions, documenting work carefully, and helping others understand and address security risks. This role requires someone who can operate with a high level of trust, communicate calmly during security events, and balance security priorities with the realities of a collaborative, mission-driven open source environment. You should be comfortable working with distributed teams and contributing to a culture where security enables participation, transparency, and resilience. Must-have Early-to-mid career experience in security operations, incident response, vulnerability management, IT security, or a related area. Practical experience investigating security alerts, events, vulnerability reports, or security issues and documenting findings clearly. Familiarity with vulnerability management processes, including reviewing findings, assessing impact, helping prioritize remediation, and tracking issues to closure. Working knowledge of core security concepts such as incident response, vulnerability management, identity and access management, endpoint security, cloud security, network security, and secure configuration. Familiarity with security tools such as vulnerability scanners, ticketing systems, or similar technologies. Ability to communicate security risks and remediation guidance clearly to both technical and non-technical stakeholders. Strong documentation skills, attention to detail, and ability to produce clear incident notes, reports, and process documentation. Ability to work independently in a fully remote environment while collaborating effectively with distributed teams. Sound judgment, discretion, and the ability to handle sensitive information responsibly. Strong written and spoken communication skills in English. Nice-to-have Familiarity with open source software communities, open source development practices, or software supply-chain security. Familiarity with Git, GitHub or GitLab, pull requests, issue tracking, and CI/CD workflows. Experience working in or with nonprofit, foundation, open source, research, standards, or community-driven technology environments. Experience with scripting or automation using Python, Bash, or similar tools. Practical experience using LLMs or AI-assisted tools for security research, documentation, triage, or developer productivity. Experience improving incident response or vulnerability management workflows. Familiarity with CVE processes, security advisories, SBOMs, or software supply-chain security tools. Working Style We are looking for someone who values practical impact, clear communication, and steady execution. You should be comfortable working with incomplete information, asking for help when needed, documenting your work carefully, and helping teams understand and address security risks. This role requires good judgment, discretion with sensitive information, and the ability to balance security priorities with the realities of a collaborative open source environment. Compensation and Benefits We offer highly competitive compensation along with a comprehensive benefits package. We thank all applicants for their interest; however, only those to be interviewed will be contacted. For more information about Eclipse Foundation, please visit our website at Accessibility Eclipse respects the dignity and independence of people with disabilities, and is committed to providing accommodation and support to persons with disabilities throughout any recruitment process, once made aware of a need for accommodation. If you require any special accommodation or support during the recruitment process, please indicate in your email to us. #J-18808-Ljbffr Eclipse Foundation, Inc.
- Eclipse Foundation, Inc. is seeking a junior-to-mid-level Security Analyst to enhance its Security Team. This fully remote role focuses on incident response and vulnerability management. Key responsibilities include monitoring security alerts, aiding in incident documentation...SuggestedRemote job
- Tactacam is seeking a Security Analyst to defend its digital infrastructure by monitoring SIEM systems and analyzing... ...traffic for threats. The candidate will be responsible for incident response, vulnerability management, and fostering a culture of security awareness....Suggested
$100k - $130k
A leading cybersecurity firm is seeking a proactive Security Analyst to join their team in the United States. This role involves monitoring security alerts, responding to incidents, and developing threat detection capabilities. The ideal candidate will have 4-6 years of...SuggestedRemote job- A leading cybersecurity firm is seeking a Security/Soc Analyst III for a 6-month contract opportunity in Houston, TX. The ideal candidate... ...years of experience in the security domain, including incident response and threat monitoring. Responsibilities include performing...SuggestedContract work
- Ahead is seeking a Security Analyst to join our internal Platform Security team at the Chicago headquarters. This role involves contributing... ...to AHEAD’s information security program, with responsibilities in incident monitoring, security training, and vendor security...Suggested
- ...Lead Security Analyst The Lead Security Analyst will... ...individual will be responsible for monitoring compliance... ...procedures, incident response). Identify... ...communicate security vulnerabilities. Serve as an information... ...to leadership and Management. Review security...Full time
$70k - $84.7k
New York University is hiring an Information Security Analyst Tier 1 to serve as the first line of defense in their Security... ...role involves triaging and investigating security incidents, developing detection logic, and managing user access requests. Candidates should possess a...- Care Quality Commission is inviting applications for the Security Operations Analyst position. This role plays a pivotal part in managing cyber security incidents and enhancing organisational security measures. Candidates will work in a supportive team to analyze incidents...Remote job
$195k - $240k
(TVM Cloud) Senior Cloud Security and Vulnerability Analyst Location... ...Threat and Vulnerability Management Team (TVM) is dedicated to... ...latest threats. You will be responsible for analyzing and assessing... ...security engineering and incident response teams to set strategic...Temporary workFor contractorsWork experience placementWork at office$97.59k - $142.99k
...opportunity to join our team as a Sr. II Security Analyst - Vulnerabilities. In this role, the... ...Penetration Testing and Vulnerabilities Management team. The group is an agile team... ...up with remediation. Job Responsibilities: Run weekly and on-demand...$93k - $118k
Emergency Response Team (ERT) Security Analyst Base pay: $93,000.00/yr - $118,000.00/yr This position is posted... ...to a wide range of security incidents, including network, application, and... ...customer service skills Ability to manage multiple tasks, prioritize effectively...Immediate startRemote work$40 per hour
A cybersecurity firm is seeking experienced professionals to evaluate AI-generated security content and solve technical problems. This position offers the flexibility to work remotely and choose your projects on a flexible schedule. Candidates should have over 2 years...Remote jobHourly payFlexible hours- A leading healthcare system in New York is seeking a Sr. II Security Analyst focused on managing security vulnerabilities. The role involves conducting vulnerability scans, analyzing threats, and coordinating with various teams. Candidates must have at least 6 years of...
- ...Description Sr Cloud Security Analyst The Sr Cloud... ...design, implement, and manage security controls across... ...strategy. Key Responsibilities Design, implement... ...-related security incidents by working with... ...detections, and remediate vulnerabilities. Qualifications...
- ...of emergency medical and security solutions for corporations... ...excellence culture. We have managed crises in the worst... ...Operations Center (GSOC) Analyst will be responsible for handling the day-to-day... ...during security or medical incidents. Responsible for answering...Full timeWorldwideShift work
$117k - $130k
...: We are seeking a Security Analyst to join our Security... ...supports it. You will be responsible for identifying and... ...: Independently manage day-to-day security... ...monitoring and incident triage with intense... ...solve for underlying vulnerabilities. Use LLMs (like Claude...Remote workWork visaFlexible hours- ...looking for a Senior Associate, Security Operations to join its... ...York. This role is pivotal in managing day-to-day security operations... ...with our managed detection and response provider. The ideal candidate... ...security operations, proficiency in incident response, and strong...
- ...position for a Senior Information Security Analyst ("Security Analyst") within the... ...Security Analyst shall act as a risk manager with the responsibility for identifying, acting on and... ...efforts Qualys: - scanning for vulnerabilities and baseline configuration...Full timeWork experience placementWork at office
- ...Info Security Analyst (Temp To Perm) Hybrid Position... ...security tasks. Core Responsibilities Perform log monitoring... ...for credential management Administration of... ...alerts for malware incidents Monitor actions... ...for obsolete/demoted/vulnerable versions of software...Permanent employmentTemporary work
- ...and bespoke program management to navigate the ever... ...looking for a Senior Security Analyst to join our Security... ...our detection and response capabilities - building... ..., responding to incidents, and proactively hunting... ...and prioritize vulnerability findings using risk-...Flexible hoursShift work
- ...insights. The Role The Security Analyst, Information Security is responsible for managing and maintaining all... ...systems Participates in incident responses, assessments, audits... ...firewalls, egress filtering, vulnerability scanning, intrusion prevention...Contract workFor contractorsWork experience placementWork at officeLocal areaRemote work
$281k - $355k
Albert Invent is seeking a Director of Security to lead security strategy focused on infrastructure or application security. This role involves managing incident response activities, collaborating with engineering teams, and staying current with emerging security threats...$121.79k - $210.09k
...opportunity to join our team as a Lead IT Security Analyst. This position reports to the IT Controls & Regulatory Compliance Manager and serves as a senior individual contributor and subject matter expert responsible for leading enterprise risk assessments and...- ...Network & Infrastructure Security Analyst (AI Training) About the... ...wrong and why Classify incidents, misconfigurations, and control... ...Experience in incident response, threat hunting, or... ...architecture, red teaming, or vulnerability management Familiarity with cloud...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
- ...SOC Analyst Location: New York City, Boston... ...defense for information security operations... ...security posture. Key Responsibilities Actively monitor... ...IT teams to support incident response and system... ...of threat detection, vulnerability management, identity/access management...Shift work
- ...respectfully. As a Security Analyst you will help build... ...delivery operations. Responsibilities Assist in the... ...hardware and software vulnerabilities and common security... ...misconfigurations. Assist with managing enterprise EDR... ...and performing incident root cause analysis....Work experience placementLive inLocal areaNight shift
$60k - $80k
...direction of the Security Operations Lead, the Security Analyst plays a key role... ...This position is responsible for administering... ...approach to identifying vulnerabilities, responding to... ...status and incidents In consideration... ...and written Time management and organizational...Full timeRemote work- ...looking for a proactive Security Analyst to serve as the... ...security alerts. You’ll be responsible for analyzing... ...threats, executing incident response playbooks to... ...measures by conducting vulnerability scans and... ...information and event management (SIEM) systems and other...Work experience placement
- Responsibilities Security Planning Develop a security plan for the best standards... ...update the company’s incident response and disaster recovery... .../firmware updates for vulnerabilities Comprehend why a piece of... ...any flaws in IT systems Manage the negative effects of an...
- ## Security AnalystApplyremote type: Hybridlocations... ...newest Security Analyst.**SUMMARY**We are... ...Analyst will be responsible for protecting an... ..., and respond to incidents. The role... ...Detective, Compliance Manager GRC, VulScan.*... ...updating.* Vulnerability Scanning - Review...Work at officeLocal areaFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Analyst, Incident Response & Vulnerability Management. Be the first to apply!
- entry level security analyst New York, NY
- security analyst New York, NY
- junior security analyst New York, NY
- security analyst remote New York, NY
- bond analyst New York, NY
- entry level information security analyst New York, NY
- security operations analyst New York, NY
- work from home security analyst New York, NY
- senior information security analyst New York, NY
- information security compliance analyst New York, NY


