Vulnerability Analyst
$78k - $135kCoalfire Systems
What You'll Do Manage Plan of Action & Milestones (POA&Ms) lifecycle including creation, tracking, risk adjustment justification, and deviation requests in coordination with 3PAO assessors and federal stakeholders Collect, organize, and maintain security control evidence and artifacts for monthly continuous monitoring deliverables and assessment/authorization activities, ensuring alignment with FedRAMP, HITRUST, PCI, and similar frameworks Maintain accurate system inventory and authorization boundary documentation to ensure scanning scope aligns with approved system boundaries Analyze scan results for false positives, document justifications, and prepare deviation requests with supporting risk assessments Translate technical vulnerability findings into risk‑based language for federal clients and authorization officials, presenting monthly status briefings as needed Collaborate with development, SRE, and infrastructure teams to integrate vulnerability management into CI/CD pipelines, cloud environments (AWS, Azure, GCP), and container/Kubernetes platforms Participate in change management processes to ensure continuous monitoring activities align with system changes and maintain compliance posture Support and maintain enterprise vulnerability management tools (such as Tenable, Nessus, Burp, Qualys, Rapid7, Wiz, Prisma, Microsoft Defender), ensuring timely updates and patches Run regular and on‑demand scans across operating systems, databases, web applications, and containers, then work with technical teams to create tickets for remediation Track and document vendor dependencies, operational requirements, and open vulnerabilities, producing clear monthly reports and updates for clients Contribute to improving internal standards and processes, including maintaining documentation, training materials, and standard operating procedures What You'll Bring 3–5 years of professional experience in vulnerability management, compliance monitoring, or related security operations roles Hands‑on expertise with operating system, database, network, container, web application, and API vulnerability management Direct experience supporting vulnerability management in at least two of the following cloud providers: AWS, Azure, GCP Background working within at least one compliance framework (for example, FedRAMP, HITRUST, PCI), including risk assessment and reporting Experience delivering monthly or periodic vulnerability status reports and tracking remediation efforts with internal and external teams Administrator‑level certification in AWS, Azure, or GCP Working knowledge of cloud architecture and security controls in AWS, Azure, or GCP, including ability to assess attack surfaces and recommend cloud‑native remediation approaches Strong knowledge of vulnerability scanning technologies and methods, including scoring systems (CVSS, CMSS) and risk prioritization frameworks Understanding of NIST 800‑53 security controls, particularly RA‑5, SI‑2, CM‑6, and how continuous monitoring supports control implementation Experience with STIG benchmarks and automated compliance scanning tools (SCAP, SCC) Familiarity with baseline configuration standards (CIS Benchmarks, vendor hardening guides) and compliance posture reporting Ability to distinguish false positives from true vulnerabilities and articulate risk‑based justifications for deviation requests Proficiency in scripting languages (Python, PowerShell, Bash) for task automation, report generation, and remediation workflows Strong client‑facing communication and documentation skills, with ability to present technical findings to federal stakeholders and produce timely compliance reports Ability to work efficiently with cross‑functional technical teams to investigate, prioritize, and coordinate vulnerability remediation efforts Bachelor's degree or equivalent work experience US citizenship (required due to client contractual requirements) Bonus Points Security‑focused cloud certifications for AWS, Azure, or GCP CISSP certification Familiarity with container security scanning tools (Trivy, Anchore, Snyk) and Kubernetes security postures Knowledge of software composition analysis (SCA) and static/dynamic application security testing (SAST/DAST) tools Familiarity with CI/CD security integration patterns and DevSecOps toolchains $78,000 - $135,000 a year The salary range listed is a reasonable estimate of the compensation range for this role based on national salary averages. The actual salary offer to the successful candidate will be based on job-related education, geographic location, training, licensure and certifications and other factors. You may also be eligible to participate in annual incentive, commission, and/or recognition programs. At Coalfire, equal opportunity and pay equity is integral to the way we do business. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Coalfire is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. To request reasonable accommodation to participate in the job application or interview process, contact our Human Resources team at View email address on click.appcast.io. #J-18808-Ljbffr
- ...acceptable configurations, enclave policy, or local policy; measures effectiveness of defense- in-depth architecture against known vulnerabilities; analyzes cyber defense policies and configurations and evaluates compliance with regulations and organizational directives;...SuggestedWork experience placementLocal area
$78k - $135k
Coalfire, located in Chicago, Illinois, is seeking a Vulnerability Management professional to oversee the lifecycle of security programs and manage compliance with key frameworks. Ideal candidates will have 3-5 years of experience in security operations and a strong understanding...Suggested- A premier health institution in New York is looking for a Sr. II Security Analyst specializing in vulnerabilities. This role involves conducting security assessments, analyzing security data, and coordinating remediation efforts. Candidates should have a Bachelor's degree...Suggested
$45k - $65k
Blu Omega LLC is seeking a Junior Vulnerability Analyst to support NIH cybersecurity operations remotely. The role involves assessing and mitigating vulnerabilities in healthcare and federal systems. Key responsibilities include evaluating vulnerabilities, creating reports...SuggestedRemote job- A technical staffing firm is seeking an IT Analyst for a remote contract position. The role involves reviewing Tenable Vulnerability Management systems, analyzing reports, prioritizing remediation efforts, and coordinating with technical teams. Ideal candidates should have...SuggestedRemote jobContract work
- ...findings Mentor and coach junior security testers and ethical hackers Collaborate directly with clients, helping them understand vulnerabilities and prioritize remediation Research and develop new testing methodologies, scripts, and tools for emerging technologies Partner...Remote work
- ...applications, platforms, and services. Leveraging industry‑standard methodologies and advanced techniques, you will proactively identify vulnerabilities, collaborate with application owners to understand root causes, and guide effective remediation to strengthen the firm's...
- ...Advisors, representing a well-known Financial Services Company, is seeking a Sr. Cyber Security Analyst in New York, NY. This role involves driving the entire vulnerability patch management lifecycle, collaborating with IT stakeholders, and ensuring compliance with security...
- Overview Are you a highly motivated I T System Analyst / Tester with a passion for web-based applications? We’re searching for a dynamic individual to join our team, either at our offices in Athens or remotely. This role offers the opportunity to collaborate with a highly...Full timeRemote workFlexible hours
- ...Program within Bank of America's Cyber Security Assurance Offensive Security group. The program provides services to assess the vulnerability of the bank's applications to malicious hacking activity. This intermediate technical role is responsible for performing application...Work at officeShift workDay shift
- A leading healthcare technology company is seeking a Director of IT & Security, CISO to oversee enterprise security and corporate IT. The ideal candidate will have over 10 years of IT experience, with strong expertise in securing AWS environments and leading security operations...Remote work
- ...applications, platforms, and services. Leveraging industry-standard methodologies and advanced techniques, you will proactively identify vulnerabilities, collaborate with application owners to understand root causes, and guide effective remediation to strengthen the firm's...
$75k - $135k
...Security Assessments against web apps, mobile apps, web services, and fat-client applications. Proficiency in delivering Network Vulnerability and Penetration Assessments both externally and internally against wired and wireless targets is also required. Penetration...Full timeRemote work- ...complex computer systems Coordinate third-party vendor testing and analyze documented test results Stay current on new tools, vulnerabilities, and emerging threats to enhance security measures Required qualifications Bachelor's Degree and 4 years of experience in Systems...Full timeRemote work
$90k - $150k
...oral and written communication skills Minimum Qualifications: Minimum six (6) years proven proficiency in performing extensive vulnerability assessment and penetration testing Minimum three (3) years of experience with testing tools, including NESSUS, METASPLOIT,...Contract workLocal area- ...culture. About the Role As a Security Engineer, Application Security you will be responsible for identifying and mitigating security vulnerabilities within software applications through building security tools, code reviews, penetration testing, and security assessments. We’...Work at officeRemote workRelocation package
- ...role. You’ll embed in the development lifecycle, review code for exploitable flaws, build security tooling into CI/CD, and drive vulnerability remediation across a platform serving 300K+ experts and enterprise clients processing sensitive AI training data. We use AI...Remote workShift work
$104k - $156k
...Preferred Qualifications Experience securing cloud-native applications / SaaS solutions and networks Familiarity with vulnerability scanning and threat protection Relevant certifications: Microsoft Certified: Azure Security Engineer Associate (AZ-500); Microsoft...Remote work$100k - $140k
...Manual testing support for light red teaming such as POC’ing vulnerabilities, leading penetration tests via vendor engagements and/or internally... ...and tuning threat detections, partnering with Security Analysts to improve/automate runbooks and response actions. Demonstrated...Full timeTemporary workRemote workHome officeFlexible hoursShift work- Mercor seeks a Cybersecurity Expert to evaluate AI outputs and create cybersecurity scenarios. The role is remote, requiring over 3 years of experience in cybersecurity, with focus areas in incident response and threat intelligence. Ideal candidates should possess strong...Remote jobHourly pay
$116.25k - $155k
An innovative cybersecurity firm is seeking a Cyber Resilience Advisor to join their Cyber Resilience Team. This role focuses on partnering with clients to enhance their cybersecurity capabilities using the Immersive platform. Candidates should have at least 3 years of ...Remote job$116.25k - $155k
Overview A product you can believe in. Immersive is the leader in people-centric cyber resilience We have an exciting vision for cybersecurity that puts people at the center of cyber. Our cyber resilience SaaS platform is an agile, hands-on solution that helps teams continuously...Immediate startRemote workFlexible hours2 days per week$116.25k - $155k
A leading cybersecurity firm is seeking a Cyber Resilience Advisor to support federal customers in the US. This role focuses on enhancing cybersecurity objectives and resilience through strong partnerships and strategic initiatives. Ideal candidates will have over 3 years...Remote job$500 per month
Become a Professional Game Tester We're looking for passionate gamers to join our elite team of mobile game testers. Get paid to play and test the latest games before they launch. $500+ Avg Monthly Pay 5-10 Hours/Week 100% Remote Position Requirements: ...Remote work10 hours per week$35 per hour
A dynamic tech company is looking for a Freelance Beta Tester to evaluate mobile apps and games. You'll provide feedback on functionality and user experience, helping to shape future gaming innovations. This remote role allows you to work at your own pace, earning $35 ...Hourly payFreelanceRemote workFlexible hours- Soho Square Solutions is seeking a qualified candidate for a role focused on vulnerability and patch management in New York. The ideal candidate will possess a bachelor's degree in a relevant field and have proven experience in security roles. Responsibilities include assessing...
$35 per hour
A digital product testing company is seeking a Freelance Product Tester to review mobile apps and games. In this remote role, you'll install apps, evaluate their performance, and provide detailed feedback to enhance user experiences. This position allows for flexible hours...FreelanceRemote workFlexible hours- A technology feedback company is seeking a Freelance Product Tester to explore and review mobile applications. This entry-level position allows you to work remotely, sharing your insights into user experience and functionality. Ideal for beginners, this role offers flexibility...FreelanceRemote work
- A mobile app evaluation company is seeking a Remote Content Editor to test mobile apps and games, providing valuable user insights. This entry-level role is perfect for technology enthusiasts who can work flexibly. Ideal candidates will possess a smartphone or tablet and...Remote work
$32 - $73 per hour
Penetration Tester- Contract (Remote) job at Fixpoint. Remote. Project length : 3~4 - weeks Commitment : ≥ 10hrs / week Compensation : $32 - $73 per hour Hourly rate may be higher for exception candidates About the project Fixpoint is hiring Penetration Testers for...Remote jobHourly payWeekly payFull timeContract workFor contractorsWork experience placement10 hours per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vulnerability Analyst. Be the first to apply!

