Vulnerability Management Analyst
Connexus Credit Union
Connexus Credit Union - Who We Are:
Serving members across all 50 states, Connexus Credit Union is a member-focused cooperative that is proud to return profits to member-owners through high yields for checking accounts and deposit products, as well as competitive rates on our loans. We are a remote first employer with the majority of our employees residing in the upper Midwest.
As an employer we foster collaboration and high performance to achieve excellence. We holistically care for and develop our employees to thrive personally and professionally. We are proud to share our success with our employees and those we serve.
Connexus offers an Amazing Benefits package:
25 days of paid time off and 10 paid holidays
16 hours of paid Volunteer Time Off
401K Retirement with up to 6% employer match
Excellent Health, Dental, Vision insurance, including multiple plan options
Health Savings Account with generous employer contributions
Employer paid Life insurance, Short-Term and Long-Term Disability
Tuition Reimbursement from $4,000 - $7,000 per calendar year
Robust Learning and Development program that includes an annual professional development stipend
Responsibilities:
Conduct regular vulnerability scanning of networks, servers, endpoints, cloud environments, and applications using approved tools.
Analyze scan results to identify false positives, determine exploitability, and assess business and regulatory risk.
Prioritize vulnerabilities based on CVSS scores, threat intelligence, asset criticality, and financial institution risk impact.
Track vulnerabilities through remediation, validation, and closure using ticketing or governance platforms.
Perform re-scans to validate remediation effectiveness.
Ensure vulnerability management practices align with:
FFIEC Cybersecurity Assessment Tool (CAT)
NCUA or banking regulatory guidance
GLBA Safeguards Rule
Internal Information Security and Risk Management policies
Prepare documentation, metrics, and evidence for internal audits, regulatory exams, and third-party assessments.
Support risk acceptance decisions by documenting compensating controls and residual risk.
Partner with IT infrastructure, application development, cloud, and network teams to remediate identified risks.
Translate technical vulnerabilities into clear business risk language for leadership and non-technical stakeholders.
Provide guidance on secure configuration, patching, and vulnerability mitigation strategies.
Participate in security incident response activities when vulnerabilities are exploited or pose imminent risk.
Monitor emerging threats, zero-day vulnerabilities, and industry advisories relevant to financial services.
Contribute to vulnerability management policies, standards, and procedures.
Assist with penetration testing coordination and result analysis.
Collect, organize, and maintain security control evidence and artifacts for monthly continuous monitoring deliverables and assessment/authorization activities, ensuring alignment with required frameworks
Maintain accurate system inventory and authorization boundary documentation to ensure scanning scope aligns with approved system boundaries
Analyze scan results for false positives, document justifications, and prepare deviation requests with supporting risk assessments.
Participate in change management processes to ensure continuous monitoring activities align with system changes and maintain compliance posture.
Support and maintain enterprise vulnerability management tools (such as Tenable, Nessus, Burp, Qualys, Rapid7, Wiz, Prisma, Microsoft Defender), ensuring timely updates and patches.
Run regular and on-demand scans across operating systems, databases, web applications, and containers, then work with technical teams to create tickets for remediation.
Track and document vendor dependencies, operational requirements, and open vulnerabilities, producing clear monthly reports and updates.
Contribute to improving internal standards and processes, including maintaining documentation, training materials, and standard operating procedures.
Run the daily vulnerability management program operations, work closely with the patch management analyst in identifying and patching vulnerabilities, and actively participate in weekly vulnerability management team meetings.
Comply with all Federal Regulations as they pertain to your job duties, including BSA.
Position Requirements:
This position is Remote.
Bachelor's degree in Information Security, Computer Science, Information Technology or commensurate experience is Required.
3+ years professional work experience in vulnerability management, security operations, or IT risk within a regulated environment is Required.
The GIAC (GSEC or GEVA) certification is preferred upon hire although required to be completed within 6 months of hire.
Prior financial industry regulations and frameworks (FFIEC, NCUA, GLBA, NIST) is Required.
Hands-on experience with vulnerability scanning tools, such as: Tenable (Nessus, Tenable.io), Qualys, Rapid7 or similar platforms is Required.
Strong understanding of, network, operating system, and application vulnerabilities, patch management processes, and secure configuration standards (CIS Benchmarks) is Required,
Strong knowledge of vulnerability scanning technologies and methods, including scoring systems (CVSS, CMSS) and risk prioritization frameworks is Required.
Experience delivering monthly or periodic vulnerability status reports and tracking remediation efforts with internal and external teams is Required.
Connexus Credit Union's Employer Recognitions:
2026 Best Place to Work in IT, Computer World
Equal Opportunity Employer/Disabled/Veterans/41 CFR 60-1.4, 41 CFR 60-1.35
$62.69k - $105.9k
...Business Process Analyst I/II/III At Accurex, a division of the Greenheck Group, we foster a culture of empowerment, collaboration... ...I/II/III, you will be responsible for defining, tracking, and managing process improvement efforts within the Accurex Sales Entity as...SuggestedWork experience placementWork at office- ...system. Provides leadership for and directs the activities of organizational effectiveness, leadership training and development for management (direct responsibility), and physicians (in collaboration with Medical Group Leadership) responsible for developing a system-wide...SuggestedFull timePart time
- ...identify issues or barriers related to the research program Develop, coordinate and implement research strategies to successfully manage assigned protocols Maintain confidentiality of patient protected health information by following confidentiality guidelines...Suggested
- ...CLINIC MANAGER Aspirus Cardiology Clinic, Wausau, WI Full Time (1.0 FTE, 80 hours every pay period) Monday – Friday day shift, generally no weekends Compassion. Accountability. Collaboration. Foresight. Joy. These are the Aspirus Core Values; and we are looking...SuggestedFull timeContract workPart timeMonday to FridayDay shift
- ...Job Description Job Description Delivery Performance Analyst Position Summary Reporting to the Customer Service Manager, the Operations Analyst serves as a critical link between customer service, scheduling, and the production floor to ensure on-time delivery...SuggestedWork at office
$60k - $75k
...response agencies and the community. Participate in community events. Build and maintain a database of customer information. Manage data in our main operating systems, NextGear and Luxor. Collaborate with SRM and SMB Corporate staff on business development...Local areaMonday to FridayShift workWeekend work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vulnerability Management Analyst. Be the first to apply!
- business analyst part time remote Wausau, WI
- asset management intern Wausau, WI
- utilization management nurse Wausau, WI
- management team Wausau, WI
- management development program Wausau, WI
- managed care specialist Wausau, WI
- events management graduate Wausau, WI
- quality management nurse Wausau, WI
- order management representative Wausau, WI
- provider data management Wausau, WI


