Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Vulnerability Analyst

$78k - $135k

Coalfire Systems

What You'll Do Manage Plan of Action & Milestones (POA&Ms) lifecycle including creation, tracking, risk adjustment justification, and deviation requests in coordination with 3PAO assessors and federal stakeholders Collect, organize, and maintain security control evidence and artifacts for monthly continuous monitoring deliverables and assessment/authorization activities, ensuring alignment with FedRAMP, HITRUST, PCI, and similar frameworks Maintain accurate system inventory and authorization boundary documentation to ensure scanning scope aligns with approved system boundaries Analyze scan results for false positives, document justifications, and prepare deviation requests with supporting risk assessments Translate technical vulnerability findings into risk‑based language for federal clients and authorization officials, presenting monthly status briefings as needed Collaborate with development, SRE, and infrastructure teams to integrate vulnerability management into CI/CD pipelines, cloud environments (AWS, Azure, GCP), and container/Kubernetes platforms Participate in change management processes to ensure continuous monitoring activities align with system changes and maintain compliance posture Support and maintain enterprise vulnerability management tools (such as Tenable, Nessus, Burp, Qualys, Rapid7, Wiz, Prisma, Microsoft Defender), ensuring timely updates and patches Run regular and on‑demand scans across operating systems, databases, web applications, and containers, then work with technical teams to create tickets for remediation Track and document vendor dependencies, operational requirements, and open vulnerabilities, producing clear monthly reports and updates for clients Contribute to improving internal standards and processes, including maintaining documentation, training materials, and standard operating procedures What You'll Bring 3–5 years of professional experience in vulnerability management, compliance monitoring, or related security operations roles Hands‑on expertise with operating system, database, network, container, web application, and API vulnerability management Direct experience supporting vulnerability management in at least two of the following cloud providers: AWS, Azure, GCP Background working within at least one compliance framework (for example, FedRAMP, HITRUST, PCI), including risk assessment and reporting Experience delivering monthly or periodic vulnerability status reports and tracking remediation efforts with internal and external teams Administrator‑level certification in AWS, Azure, or GCP Working knowledge of cloud architecture and security controls in AWS, Azure, or GCP, including ability to assess attack surfaces and recommend cloud‑native remediation approaches Strong knowledge of vulnerability scanning technologies and methods, including scoring systems (CVSS, CMSS) and risk prioritization frameworks Understanding of NIST 800‑53 security controls, particularly RA‑5, SI‑2, CM‑6, and how continuous monitoring supports control implementation Experience with STIG benchmarks and automated compliance scanning tools (SCAP, SCC) Familiarity with baseline configuration standards (CIS Benchmarks, vendor hardening guides) and compliance posture reporting Ability to distinguish false positives from true vulnerabilities and articulate risk‑based justifications for deviation requests Proficiency in scripting languages (Python, PowerShell, Bash) for task automation, report generation, and remediation workflows Strong client‑facing communication and documentation skills, with ability to present technical findings to federal stakeholders and produce timely compliance reports Ability to work efficiently with cross‑functional technical teams to investigate, prioritize, and coordinate vulnerability remediation efforts Bachelor's degree or equivalent work experience US citizenship (required due to client contractual requirements) Bonus Points Security‑focused cloud certifications for AWS, Azure, or GCP CISSP certification Familiarity with container security scanning tools (Trivy, Anchore, Snyk) and Kubernetes security postures Knowledge of software composition analysis (SCA) and static/dynamic application security testing (SAST/DAST) tools Familiarity with CI/CD security integration patterns and DevSecOps toolchains $78,000 - $135,000 a year The salary range listed is a reasonable estimate of the compensation range for this role based on national salary averages. The actual salary offer to the successful candidate will be based on job-related education, geographic location, training, licensure and certifications and other factors. You may also be eligible to participate in annual incentive, commission, and/or recognition programs. At Coalfire, equal opportunity and pay equity is integral to the way we do business. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Coalfire is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. To request reasonable accommodation to participate in the job application or interview process, contact our Human Resources team at View email address on click.appcast.io. #J-18808-Ljbffr

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Vulnerability Analyst in New York, NY vacancy
  •  ...acceptable configurations, enclave policy, or local policy; measures effectiveness of defense- in-depth architecture against known vulnerabilities; analyzes cyber defense policies and configurations and evaluates compliance with regulations and organizational directives;... 
    Suggested
    Work experience placement
    Local area

    360 Adept, LLC

    New York, NY
    12 hours ago
  • $78k - $135k

    Coalfire, located in Chicago, Illinois, is seeking a Vulnerability Management professional to oversee the lifecycle of security programs and manage compliance with key frameworks. Ideal candidates will have 3-5 years of experience in security operations and a strong understanding... 
    Suggested

    Coalfire-

    New York, NY
    3 days ago
  • A premier health institution in New York is looking for a Sr. II Security Analyst specializing in vulnerabilities. This role involves conducting security assessments, analyzing security data, and coordinating remediation efforts. Candidates should have a Bachelor's degree... 
    Suggested

    NYU Langone

    New York, NY
    3 days ago
  • $45k - $65k

    Blu Omega LLC is seeking a Junior Vulnerability Analyst to support NIH cybersecurity operations remotely. The role involves assessing and mitigating vulnerabilities in healthcare and federal systems. Key responsibilities include evaluating vulnerabilities, creating reports... 
    Suggested
    Remote job

    Blu Omega LLC

    New York, NY
    12 hours ago
  • A technical staffing firm is seeking an IT Analyst for a remote contract position. The role involves reviewing Tenable Vulnerability Management systems, analyzing reports, prioritizing remediation efforts, and coordinating with technical teams. Ideal candidates should have... 
    Suggested
    Remote job
    Contract work

    ViziRecruiter,LLC.

    New York, NY
    1 day ago
  •  ...findings Mentor and coach junior security testers and ethical hackers Collaborate directly with clients, helping them understand vulnerabilities and prioritize remediation Research and develop new testing methodologies, scripts, and tools for emerging technologies Partner... 
    Remote work

    Control Gap Inc.

    New York, NY
    12 hours ago
  •  ...applications, platforms, and services. Leveraging industry‑standard methodologies and advanced techniques, you will proactively identify vulnerabilities, collaborate with application owners to understand root causes, and guide effective remediation to strengthen the firm's... 

    Koitecc Solutions

    New York, NY
    3 days ago
  •  ...Advisors, representing a well-known Financial Services Company, is seeking a Sr. Cyber Security Analyst in New York, NY. This role involves driving the entire vulnerability patch management lifecycle, collaborating with IT stakeholders, and ensuring compliance with security... 

    Phyton Talent Advisors

    New York, NY
    2 days ago
  • Overview Are you a highly motivated I T System Analyst / Tester with a passion for web-based applications? We’re searching for a dynamic individual to join our team, either at our offices in Athens or remotely. This role offers the opportunity to collaborate with a highly... 
    Full time
    Remote work
    Flexible hours

    EUROPEAN DYNAMICS

    Brooklyn, NY
    4 days ago
  •  ...Program within Bank of America's Cyber Security Assurance Offensive Security group. The program provides services to assess the vulnerability of the bank's applications to malicious hacking activity. This intermediate technical role is responsible for performing application... 
    Work at office
    Shift work
    Day shift

    Bank of America

    Jersey City, NJ
    6 days ago
  • A leading healthcare technology company is seeking a Director of IT & Security, CISO to oversee enterprise security and corporate IT. The ideal candidate will have over 10 years of IT experience, with strong expertise in securing AWS environments and leading security operations...
    Remote work

    Redox

    New York, NY
    12 hours ago
  •  ...applications, platforms, and services. Leveraging industry-standard methodologies and advanced techniques, you will proactively identify vulnerabilities, collaborate with application owners to understand root causes, and guide effective remediation to strengthen the firm's... 

    Chase

    New York, NY
    12 hours ago
  • $75k - $135k

     ...Security Assessments against web apps, mobile apps, web services, and fat-client applications. Proficiency in delivering Network Vulnerability and Penetration Assessments both externally and internally against wired and wireless targets is also required. Penetration... 
    Full time
    Remote work

    Aux Partners

    New York, NY
    12 hours ago
  •  ...complex computer systems Coordinate third-party vendor testing and analyze documented test results Stay current on new tools, vulnerabilities, and emerging threats to enhance security measures Required qualifications Bachelor's Degree and 4 years of experience in Systems... 
    Full time
    Remote work

    First-Citizens Bank & Trust Company

    New York, NY
    2 days ago
  • $90k - $150k

     ...oral and written communication skills Minimum Qualifications: Minimum six (6) years proven proficiency in performing extensive vulnerability assessment and penetration testing Minimum three (3) years of experience with testing tools, including NESSUS, METASPLOIT,... 
    Contract work
    Local area

    Goldbelt, Inc.

    New York, NY
    3 days ago
  •  ...culture. About the Role As a Security Engineer, Application Security you will be responsible for identifying and mitigating security vulnerabilities within software applications through building security tools, code reviews, penetration testing, and security assessments. We’... 
    Work at office
    Remote work
    Relocation package

    Slope

    New York, NY
    1 day ago
  •  ...role. You’ll embed in the development lifecycle, review code for exploitable flaws, build security tooling into CI/CD, and drive vulnerability remediation across a platform serving 300K+ experts and enterprise clients processing sensitive AI training data. We use AI... 
    Remote work
    Shift work

    Mercor Inc

    New York, NY
    1 day ago
  • $104k - $156k

     ...Preferred Qualifications Experience securing cloud-native applications / SaaS solutions and networks Familiarity with vulnerability scanning and threat protection Relevant certifications: Microsoft Certified: Azure Security Engineer Associate (AZ-500); Microsoft... 
    Remote work

    Relativity

    Brooklyn, NY
    3 days ago
  • $100k - $140k

     ...Manual testing support for light red teaming such as POC’ing vulnerabilities, leading penetration tests via vendor engagements and/or internally...  ...and tuning threat detections, partnering with Security Analysts to improve/automate runbooks and response actions. Demonstrated... 
    Full time
    Temporary work
    Remote work
    Home office
    Flexible hours
    Shift work

    BLACKCLOAK

    New York, NY
    4 days ago
  • Mercor seeks a Cybersecurity Expert to evaluate AI outputs and create cybersecurity scenarios. The role is remote, requiring over 3 years of experience in cybersecurity, with focus areas in incident response and threat intelligence. Ideal candidates should possess strong...
    Remote job
    Hourly pay

    Mercor Inc

    New York, NY
    3 days ago
  • $116.25k - $155k

    An innovative cybersecurity firm is seeking a Cyber Resilience Advisor to join their Cyber Resilience Team. This role focuses on partnering with clients to enhance their cybersecurity capabilities using the Immersive platform. Candidates should have at least 3 years of ...
    Remote job

    Immersive Dynamics Inc.

    New York, NY
    12 hours ago
  • $116.25k - $155k

    Overview A product you can believe in. Immersive is the leader in people-centric cyber resilience We have an exciting vision for cybersecurity that puts people at the center of cyber. Our cyber resilience SaaS platform is an agile, hands-on solution that helps teams continuously...
    Immediate start
    Remote work
    Flexible hours
    2 days per week

    Immersive Dynamics Inc.

    New York, NY
    12 hours ago
  • $116.25k - $155k

    A leading cybersecurity firm is seeking a Cyber Resilience Advisor to support federal customers in the US. This role focuses on enhancing cybersecurity objectives and resilience through strong partnerships and strategic initiatives. Ideal candidates will have over 3 years...
    Remote job

    Menlo Ventures

    New York, NY
    12 hours ago
  • $500 per month

    Become a Professional Game Tester We're looking for passionate gamers to join our elite team of mobile game testers. Get paid to play and test the latest games before they launch. $500+ Avg Monthly Pay 5-10 Hours/Week 100% Remote Position Requirements: ...
    Remote work
    10 hours per week

    Babki

    Jersey City, NJ
    2 days ago
  • $35 per hour

    A dynamic tech company is looking for a Freelance Beta Tester to evaluate mobile apps and games. You'll provide feedback on functionality and user experience, helping to shape future gaming innovations. This remote role allows you to work at your own pace, earning $35 ...
    Hourly pay
    Freelance
    Remote work
    Flexible hours

    Review Pays

    New York, NY
    12 hours ago
  • Soho Square Solutions is seeking a qualified candidate for a role focused on vulnerability and patch management in New York. The ideal candidate will possess a bachelor's degree in a relevant field and have proven experience in security roles. Responsibilities include assessing... 

    Soho Square Solutions

    New York, NY
    1 day ago
  • $35 per hour

    A digital product testing company is seeking a Freelance Product Tester to review mobile apps and games. In this remote role, you'll install apps, evaluate their performance, and provide detailed feedback to enhance user experiences. This position allows for flexible hours...
    Freelance
    Remote work
    Flexible hours

    Review Pays

    New York, NY
    12 hours ago
  • A technology feedback company is seeking a Freelance Product Tester to explore and review mobile applications. This entry-level position allows you to work remotely, sharing your insights into user experience and functionality. Ideal for beginners, this role offers flexibility...
    Freelance
    Remote work

    Review Pays

    New York, NY
    12 hours ago
  • A mobile app evaluation company is seeking a Remote Content Editor to test mobile apps and games, providing valuable user insights. This entry-level role is perfect for technology enthusiasts who can work flexibly. Ideal candidates will possess a smartphone or tablet and...
    Remote work

    Review Pays

    New York, NY
    12 hours ago
  • $32 - $73 per hour

    Penetration Tester- Contract (Remote) job at Fixpoint. Remote. Project length : 3~4 - weeks Commitment : ≥ 10hrs / week Compensation : $32 - $73 per hour Hourly rate may be higher for exception candidates About the project Fixpoint is hiring Penetration Testers for...
    Remote job
    Hourly pay
    Weekly pay
    Full time
    Contract work
    For contractors
    Work experience placement
    10 hours per week

    Fixpoint

    New York, NY
    12 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Vulnerability Analyst. Be the first to apply!