Vulnerability Analyst
$78k - $135kCoalfire Systems
What You'll Do Manage Plan of Action & Milestones (POA&Ms) lifecycle including creation, tracking, risk adjustment justification, and deviation requests in coordination with 3PAO assessors and federal stakeholders Collect, organize, and maintain security control evidence and artifacts for monthly continuous monitoring deliverables and assessment/authorization activities, ensuring alignment with FedRAMP, HITRUST, PCI, and similar frameworks Maintain accurate system inventory and authorization boundary documentation to ensure scanning scope aligns with approved system boundaries Analyze scan results for false positives, document justifications, and prepare deviation requests with supporting risk assessments Translate technical vulnerability findings into risk‑based language for federal clients and authorization officials, presenting monthly status briefings as needed Collaborate with development, SRE, and infrastructure teams to integrate vulnerability management into CI/CD pipelines, cloud environments (AWS, Azure, GCP), and container/Kubernetes platforms Participate in change management processes to ensure continuous monitoring activities align with system changes and maintain compliance posture Support and maintain enterprise vulnerability management tools (such as Tenable, Nessus, Burp, Qualys, Rapid7, Wiz, Prisma, Microsoft Defender), ensuring timely updates and patches Run regular and on‑demand scans across operating systems, databases, web applications, and containers, then work with technical teams to create tickets for remediation Track and document vendor dependencies, operational requirements, and open vulnerabilities, producing clear monthly reports and updates for clients Contribute to improving internal standards and processes, including maintaining documentation, training materials, and standard operating procedures What You'll Bring 3–5 years of professional experience in vulnerability management, compliance monitoring, or related security operations roles Hands‑on expertise with operating system, database, network, container, web application, and API vulnerability management Direct experience supporting vulnerability management in at least two of the following cloud providers: AWS, Azure, GCP Background working within at least one compliance framework (for example, FedRAMP, HITRUST, PCI), including risk assessment and reporting Experience delivering monthly or periodic vulnerability status reports and tracking remediation efforts with internal and external teams Administrator‑level certification in AWS, Azure, or GCP Working knowledge of cloud architecture and security controls in AWS, Azure, or GCP, including ability to assess attack surfaces and recommend cloud‑native remediation approaches Strong knowledge of vulnerability scanning technologies and methods, including scoring systems (CVSS, CMSS) and risk prioritization frameworks Understanding of NIST 800‑53 security controls, particularly RA‑5, SI‑2, CM‑6, and how continuous monitoring supports control implementation Experience with STIG benchmarks and automated compliance scanning tools (SCAP, SCC) Familiarity with baseline configuration standards (CIS Benchmarks, vendor hardening guides) and compliance posture reporting Ability to distinguish false positives from true vulnerabilities and articulate risk‑based justifications for deviation requests Proficiency in scripting languages (Python, PowerShell, Bash) for task automation, report generation, and remediation workflows Strong client‑facing communication and documentation skills, with ability to present technical findings to federal stakeholders and produce timely compliance reports Ability to work efficiently with cross‑functional technical teams to investigate, prioritize, and coordinate vulnerability remediation efforts Bachelor's degree or equivalent work experience US citizenship (required due to client contractual requirements) Bonus Points Security‑focused cloud certifications for AWS, Azure, or GCP CISSP certification Familiarity with container security scanning tools (Trivy, Anchore, Snyk) and Kubernetes security postures Knowledge of software composition analysis (SCA) and static/dynamic application security testing (SAST/DAST) tools Familiarity with CI/CD security integration patterns and DevSecOps toolchains $78,000 - $135,000 a year The salary range listed is a reasonable estimate of the compensation range for this role based on national salary averages. The actual salary offer to the successful candidate will be based on job-related education, geographic location, training, licensure and certifications and other factors. You may also be eligible to participate in annual incentive, commission, and/or recognition programs. At Coalfire, equal opportunity and pay equity is integral to the way we do business. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Coalfire is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. To request reasonable accommodation to participate in the job application or interview process, contact our Human Resources team at View email address on click.appcast.io. #J-18808-Ljbffr
- ...acceptable configurations, enclave policy, or local policy; measures effectiveness of defense- in-depth architecture against known vulnerabilities; analyzes cyber defense policies and configurations and evaluates compliance with regulations and organizational directives;...SuggestedWork experience placementLocal area
- ...A premier health institution in New York is looking for a Sr. II Security Analyst specializing in vulnerabilities. This role involves conducting security assessments, analyzing security data, and coordinating remediation efforts. Candidates should have a Bachelor's degree...Suggested
- cFocus Software Incorporated is seeking an Infrastructure Scanning Analyst to support the National Institutes of Health (NIH). This fully... ...a Public Trust clearance and involves conducting detailed vulnerability assessments in various systems. The ideal candidate will...SuggestedRemote job
$78k - $135k
Coalfire, located in Chicago, Illinois, is seeking a Vulnerability Management professional to oversee the lifecycle of security programs and manage compliance with key frameworks. Ideal candidates will have 3-5 years of experience in security operations and a strong understanding...Suggested- Alignerr is seeking a Vulnerability Management Analyst to help train and evaluate AI models by analyzing CVEs, exposure scenarios, and remediation workflows. This remote, hourly contract role offers flexible scheduling and global collaboration for qualified security practitioners...SuggestedRemote jobHourly payContract workFlexible hours
$45k - $65k
Blu Omega LLC is seeking a Junior Vulnerability Analyst to support NIH cybersecurity operations remotely. The role involves assessing and mitigating vulnerabilities in healthcare and federal systems. Key responsibilities include evaluating vulnerabilities, creating reports...Remote job- A technical staffing firm is seeking an IT Analyst for a remote contract position. The role involves reviewing Tenable Vulnerability Management systems, analyzing reports, prioritizing remediation efforts, and coordinating with technical teams. Ideal candidates should have...Remote jobContract work
$100k - $145k
Application Vulnerability & Obsolescence Analyst Talan is an international consulting and technology expertise group supporting Corporate and Investment Banking (CIB) and Financial Services clients through large-scale transformation programs driven by data, technology,...Worldwide- ...the United States, Georgia, is seeking a Senior Cybersecurity Analyst to lead the proactive identification and remediation of threats across various environments. This role involves conducting vulnerability scans, analyzing findings, and coordinating with IT and security...Contract work
- ...findings Mentor and coach junior security testers and ethical hackers Collaborate directly with clients, helping them understand vulnerabilities and prioritize remediation Research and develop new testing methodologies, scripts, and tools for emerging technologies Partner...Remote work
- Ascendion is a full-service digital engineering solutions company. We make and manage software platforms and products that power growth and deliver captivating experiences to consumers and employees. Our engineering, cloud, data, experience design, and talent solution ...Temporary work
- ManpowerGroup is seeking a Vulnerability Management Analyst to oversee Enterprise Payments vulnerabilities. This remote position requires expertise in the Brinqa Vulnerability tool and advanced Excel skills to effectively lead remediation efforts and analyze vulnerability...Remote job
$100k - $145k
...to benefit people and society. Join us and be part of meaningful change! Job Description We are looking for an IT Risk & Vulnerability Analyst to support one of our strategic CIB clients in keeping their software secure and up to date. The ideal candidate has experience...- New York University is seeking a Vulnerability Management Analyst 2 to join Security Operations and drive effective vulnerability identification and remediation. You will leverage advanced tools and workflows to identify impacted systems and optimize processes, collaborating...Remote job
$110k - $130k
Position Title Vulnerability Management Analyst 2 Posting Information Posting Number: 2026-15806 Location: US-NY-New York Hybrid Remote Work Classification: Mostly Remote: Remote more than 60% of time Department: Security Operations School/Division: NYU IT (WS1170...Full timePart timeWork experience placementRemote work- Experis US LLC is looking for a Vulnerability Management Analyst to manage vulnerabilities in Enterprise Payments. This role involves reviewing vulnerability reports, leading remediation efforts, and producing analytics while working remotely. The ideal candidate will...Remote job
$95.86k
The KPMG Advisory practice is at the forefront of transformation, offering excellent opportunities for individuals to advance their careers and expertise with KPMG. Looking ahead, we anticipate continued evolution and success within the practice, fostering both personal...H1bLocal area- QUANTEAM - North America (RAINBOW PARTNERS Group) is seeking a Vulnerability & Patch Management Analyst to join their New York team. The successful candidate will manage the end-to-end VPM program, working closely with network teams and IT stakeholders in a global financial...
- A global consulting firm is seeking an IT Risk & Vulnerability Analyst to ensure software security and compliance for strategic clients. The role involves tracking software versions, collaborating with IT teams, and maintaining accurate reports. Candidates should have a...
$122.57k - $204.25k
...of internally developed and commercial products. Apply creative and analytical thinking to bypass security controls, identify vulnerabilities, and develop practical remediation guidance; stay informed on evolving tactics, techniques, and procedures (TTPs), zero‑day vulnerabilities...Work from home$2,150 per month
...per completed task Location: Remote Role Responsibilities Review and evaluate AI-generated outputs related to threat analysis, vulnerability assessment, and security architecture recommendations. Create realistic scenarios based on cybersecurity workflows such as incident...Hourly payContract workPart timeSummer workRemote work- ...project management team.There is no typical day for our Pen Test team. Our clients rely on us to find and exploit a myriad of vulnerabilities across their on premise and cloud-based networks and applications. The benefit of being exposed to so many different situations...Contract workWork experience placementLocal areaImmediate startRemote workFlexible hours
$60 per hour
A tech company specializing in AI is seeking experienced cybersecurity professionals to evaluate AI-generated cybersecurity content and contribute to the development of security-focused AI systems. This flexible, remote position allows you to work with state-of-the-art...Remote workFlexible hours$1,000 per month
Join Our Team as a Website Tester at Little Wheel Little Wheel is a gambling technology company focused on researching and building products that put players first. We are currently hiring Website Testers across Michigan, New Jersey, Pennsylvania, and West Virginia...Extra incomeTemporary workSecond jobCurrently hiringImmediate startWork from homeFlexible hours- A mobile game testing company is seeking a Freelance Software Tester to explore and analyze mobile applications. In this remote role, you'll provide critical feedback on app performance and usability. This position is ideal for beginners, requires no prior experience, ...FreelanceRemote work
$500 per month
Become a Professional Game Tester We're looking for passionate gamers to join our elite team of mobile game testers. Get paid to play and test the latest games before they launch. $500+ Avg Monthly Pay 5-10 Hours/Week 100% Remote Position Requirements: ...Part timeRemote work10 hours per week- A mobile app evaluation company is seeking a Remote Content Editor to test mobile apps and games, providing valuable user insights. This entry-level role is perfect for technology enthusiasts who can work flexibly. Ideal candidates will possess a smartphone or tablet and...Remote work
$35 per hour
A dynamic tech company is looking for a Freelance Beta Tester to evaluate mobile apps and games. You'll provide feedback on functionality and user experience, helping to shape future gaming innovations. This remote role allows you to work at your own pace, earning $35 ...Hourly payFreelanceRemote workFlexible hours- Accenture is seeking a detail-oriented consultant to support end-to-end IR readiness engagements within the Crisis Readiness team. You will help create and maintain readiness playbooks, response plans, and assessment reports tailored to client environments, and facilitate...
- A technology feedback company is seeking a Freelance Product Tester to explore and review mobile applications. This entry-level position allows you to work remotely, sharing your insights into user experience and functionality. Ideal for beginners, this role offers flexibility...FreelanceRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vulnerability Analyst. Be the first to apply!

