Analyst IT Vulnerability Management
$70k - $120kJetBlue
Analyst IT Vulnerability Management
Location: Long Island City, NY, US, 11101 Washington, DC, US, 20005 Orlando, FL, US, 32827 Salt Lake City, UT, US, 84121 Req ID: 58229 Category: Information Technology
Position Summary: At JetBlue, cybersecurity is driven by risk management, threat-informed defense, and operational resilience. The Analyst, Vulnerability Management - Cloud supports JetBlue's vulnerability management program across cloud-hosted infrastructure, cloud control planes, containers, infrastructure as code, and application-adjacent cloud services. This crewmember identifies, analyzes, validates, reports, and coordinates remediation of cloud vulnerabilities and misconfigurations across JetBlue's multi-cloud environment, including AWS, Azure, GCP, OCI, and future cloud platforms as adopted. The analyst works closely with Cybersecurity, Cloud Engineering, DevOps, Infrastructure, Application, Product, GRC, Threat Intelligence, and Managed Service Provider teams to improve vulnerability visibility, remediation accountability, and risk-based prioritization.
Essential Responsibilities:
- Conduct and support vulnerability assessments across cloud-hosted infrastructure, cloud configurations, containers, Kubernetes, infrastructure as code, application components, and related cloud services.
- Use approved vulnerability management, cloud security, CSPM/CNAPP, container, code-scanning, and external attack-surface tools to identify vulnerabilities, misconfigurations, exposed services, outdated software, and insecure deployment patterns.
- Analyze findings using severity, exploitability, CISA KEV status, exposure, asset criticality, data sensitivity, compensating controls, and business impact.
- Coordinate with cloud engineering, DevOps, application, infrastructure, and product owners to prioritize and track remediation through patching, configuration changes, code changes, image updates, infrastructure-as-code changes, or compensating controls.
- Validate remediation through rescans, evidence review, configuration review, ticket closure checks, or other approved verification methods.
- Assist with authenticated scan coverage, agent deployment coordination, cloud account onboarding, asset tagging, ownership validation, and CMDB/application mapping.
- Support remediation governance by tracking findings against JetBlue policy timelines and escalating overdue, disputed, or blocked remediation items.
- Collaborate with engineering and QA teams to ensure proper Software Development Life Cycle (SDLC) practices and minimize the release of vulnerable software through the deployment pipeline.
- Route non-remediated or delayed findings through the approved cyber risk exception/acceptance process when required.
- Configure and maintain vulnerability metrics and reporting for cloud findings, remediation progress, risk exposure, aging, coverage gaps, recurring issues, and exception trends.
- Partner with Threat Intelligence, Detection & Response, Penetration Testing, and Application Security teams to incorporate active exploitation, external exposure, attack path, and test-result context into prioritization.
- Support Cyber compliance requirements with evidence, reporting, and control validation for PCI, SOX, TSA-related obligations, and other applicable oversight frameworks.
- Participate in cross-functional working sessions to improve cloud vulnerability remediation processes, reduce direct exposure, strengthen compensating controls, and improve cloud security visibility.
Minimum Experience and Qualifications:
- Bachelor's Degree in Computer Science, Information Security, Information Technology, Cybersecurity, Cloud Computing, or a related field; OR demonstrated capability to perform job responsibilities with a High School Diploma/GED and at least four (4) years of previous relevant work experience.
- One (1) year of experience in vulnerability management, cloud security, security operations, infrastructure security, DevOps, application security, or a related cybersecurity role.
- Working knowledge of at least one major cloud provider; AWS/Azure preferred.
- Experience with vulnerability scanning tools such as Tenable, Qualys, Rapid7, Prisma Cloud, Wiz, Defender for Cloud, AWS Inspector, or similar.
- Understanding of cloud shared responsibility models, cloud networking, identity, compute, storage, containers, Kubernetes, and infrastructure-as-code concepts.
- Ability to analyze scan results, identify false positives, validate risk, and communicate remediation needs clearly.
- Knowledge of vulnerability risk factors such as CVSS, exploitability, internet exposure, asset criticality, data sensitivity, compensating controls, and remediation timelines.
- Familiarity with patch management, configuration remediation, change management, and remediation validation.
- Strong written and verbal communication skills with the ability to interact effectively with stakeholders across all levels of the organization.
- Ability to work collaboratively with Cybersecurity, IT, DevOps, infrastructure, product, application, compliance, and managed service provider teams.
Available for occasional overnight travel (10%). Must pass a pre-employment drug test. Must be legally eligible to work in the country in which the position is located. Authorization to work in the United States is required; this position is not eligible for visa sponsorship.
Compensation: The base pay range for this position is between $70,000.00 and $120,000.00 per year. Base pay is one component of JetBlue's total compensation package, which may also include access to healthcare benefits, a 401(k) plan and company match, crewmember stock purchase plan, short-term and long-term disability coverage, basic life insurance, free space available travel on JetBlue, and more.
JetBlue Airways is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status, or any other legally protected basis.
- ...Full-Time Description RiVidium is seeking a Vulnerability Management Analyst to support our planned MODES III team supporting Military Community and Family Policy (MC&FP). This role supports IT, Cybersecurity, and Data Operations - Core Operations and helps...SuggestedFull timeContract workPart time
- ...True Zero Vulnerability Management Position True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes. True Zero recognizes...SuggestedWork at office
- ...Vulnerability Management, Tenable/Nessus & Metrics Analyst We are seeking a Vulnerability Management, Tenable/Nessus & Metrics Analyst to support vulnerability... ...vulnerability management, security operations, cyber GRC, IT operations, application support, or related...Suggested
- ...contract award *** Overview SOSi is seeking a Risk and Vulnerability Analyst II to support vulnerability assessment and risk analysis... ...teams to support tool operations, testing, and vulnerability management activities Qualifications · Experience: Three (...SuggestedContract workWork at officeWorldwideMonday to FridayWeekend workAfternoon shift
$115k - $135k
...Data Management Specialist Systems Planning and Analysis, Inc. (SPA) delivers high-impact, technical solutions to complex national... ...integration support inclusive of understanding of threats and vulnerability; technical assessment & evaluation to support and complement...SuggestedWork at office- ...cyber defense and resiliency, vulnerability research, ubiquitous... ...is seeking a Cyber Incident Manager to support this critical customer... ...into small, and large-scale IT networks, and conduct cursory... ...), escalating to specialized analysts Required Skills: - U.S...Contract workImmediate startShift workNight shiftWeekend work
- ...senior level policy makers to program managers, to choose smartly, buy effectively and... ...composed of a mix of junior and mid-level analysts who will look to you for technical... ...frameworks such as MITRE ATT&CK to evaluate vulnerabilities, threats, and risks. Develop and...For contractorsRemote workShift work
- ...cyber defense and resiliency, vulnerability research, ubiquitous... ...is seeking a Cyber Incident Manager to support this critical customer... ...into small, and large-scale IT networks, and conduct cursory... ...), escalating to specialized analysts Required Skills: - U.S...Contract workImmediate startShift work
- ...Description:\n\nCompany Description ProSidian is a Management And Operations Consulting Services firm... ...| Compliance | Business Process | IT Effectiveness | Engineering |... ...Description ProSidian Seeks a Compliance Data Analyst | Human Capital Programmatic Evaluation &...Full timeContract workTemporary workFor contractorsH1bWork at officeFlexible hours
$70k - $74k
...will provide comprehensive program and project management support services to a federal customer supporting a large, distributed IT environment. Services include end-to-end... ...concurrent projects and portfolios. The IT Analyst provides support to projects, handling...Full timeContract workFlexible hours$69k - $72k
...SUVI Global Services is looking for an IT Analyst to support IT across all DoD OIG networks. To join our team of outstanding professionals... ...data. Oversee the implementation of computer solutions by managing programmers, coders, and equipment vendors to ensure the...Full timePart timeFor contractorsLocal areaImmediate startRemote work- ...Description:\n\nCompany Description ProSidian is a Management And Operations Consulting Services firm... ...| Compliance | Business Process | IT Effectiveness | Engineering |... ...Description ProSidian Seeks a BI / Reporting Analyst (OAS/Tableau) | Workforce Planning & Strategic...Full timeContract workH1bWork at officeFlexible hours
$66k - $69k
...SUVI Global Services is looking for a Data Analyst to support IT across all DoD OIG networks. To join our team of outstanding professionals... ...data systems and programs in support of ad-hoc and standing management or customer requests. Validate data for completeness and...Full timePart timeFor contractorsLocal areaRemote work- ...Data Analyst This position requires an active TS/Sensitive Compartmental Information... ...Support Center (NTC) within the Knowledge management and Information management Cell (KIC).... ...stakeholders Technical Skills: Adept IT skills w/ability to adapt/infuse new systems...Full timeWork at office
- ...POSITION REQUIRES A CURRENT Top Secret / SCI w/ Poly . Core One seeks an experienced Information Analyst - Level 1 to support the Classification Management Branch of the Office of Policy and Strategy (P&S) within the Office of the Director of National Intelligence...For contractorsWork at office
$65.1k - $108.5k
...Risk Solutions serves as a trusted partner in the assessment and management of risk. Within our government vertical, the organization's... ...pressing challenges. About the role: As an Identity Data Analyst, you will use modern tools and technologies to support due...Full timeFor contractorsLocal area$180k
...Bethesda, Maryland Type: Contract Job #3492 Title: IT PMO Analyst Location: Bethesda, MD Compensation Range: $180k... ...include: Performs as a project lead, experience in managing project schedule and performance. Directly contributes to...Contract workFor contractors$90k - $120k
...Lynch Consultants is seeking a Senior Data Analyst to support the Department of the Air Force (DAF) in the National Capital Region... ...integrated financial automation capability that connects Financial Management (FM) data sources, automates key workflows, and enables...Interim roleFlexible hours3 days per week- ...Investment Manager Data Analyst Investment manager data forms the backbone of the investment process at Cambridge Associates. Data Operations... ..., and support decision-making processes. Partner with IT staff to research and resolve technical issues, ensuring seamless...
- ...Aalis Management Consulting is an 8(a) certified Service-Disabled Veteran-Owned Small Business... ...of Acquisition & Procurement Support, (IT) Financial Management, Program Management... ...Visit us at Title: SeniorTrade Data Analyst Client: Federal Agency Ability to...Monday to Friday3 days per week
- ...Overview K.L. Scott & Associates (KLSA) is a mission-driven management and technology consulting firm that partners with public-... ...solutions. Position Overview We are seeking a Senior Data Analyst with at least 10 years of experience to support a federal...
- ...Metadata / Data Governance Analyst Imagineeer is seeking a Metadata / Data Governance Analyst to enforce metadata standards, implement... ...role focuses on establishing and sustaining robust metadata management processes, ensuring compliance with federal standards, and...Local areaWork from homeFlexible hours
- ...Dexian Government Solutions is recruiting for a Sr. Business Analyst to support our contract at the USPSOIG in Arlington,... ...Services include Software Development, Systems Integration, Data Management, Project Management, Operations & Maintenance, Cybersecurity,...Contract workPart time
$103.95k - $240.35k
...has provided specialized engineering, acquisition, and program management services to the Federal Aviation Administration (FAA), playing... ...technology. Description Noblis is seeking Aviation Data Analysts to support the Federal Aviation Administration (FAA) Air...Permanent employmentFull timeContract workPart timeWork experience placementWork at officeLocal areaRemote workWorldwideShift work$59k - $63k
...Lynch Consultants is seeking a Junior Data Analyst to support the Department of the Air Force (DAF) financial reporting and data analytics... ...and process improvement activities tied to federal financial management and operational performance. The selected candidate will...Flexible hours$82.5k - $128.93k
...Responsibilities Noblis is seeking an experienced Data Management and Automation Analyst to work in dynamic mission-oriented environment within Bethesda, Maryland. Job Responsibilities: Improving operational efficiency by designing and implementing automated...Full timeContract workPart timeLocal areaRemote work- ...STE - Senior Data Analyst Washington, DC (USA) - Washington, DC Overview Position Type Full Time Education Level None Travel... ...Senior Data Analyst will conduct activities to plan, execute, manage, and analyze throughout all phases of HQ USAF wargames including...Full timeContract work
- ...Senior Data Analyst CTP is a privately held small business based in Herndon, VA. We provide program management services for government and private clients and deliver technical assistance programs in over 80 countries around the world. CTP provides specific solutions...Contract workTemporary workWork at officeRemote workFlexible hours
- ...Data Analyst Washington, D.C. Company Overview K.L. Scott & Associates (KLSA) is a mission-driven management and technology consulting firm that partners with public-sector organizations to modernize operations, strengthen data and AI capabilities, and deliver...
- ...Position Title Epic Health Information Exchange Analyst Job Description Summary Located in Arlington, Virginia, VHC Health... ...multiple roles throughout the development, implementation, management, and on-going support of Virginia Hospital Center's...Flexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Analyst IT Vulnerability Management. Be the first to apply!
- analyst asset management Washington DC
- origination analyst Washington DC
- design analyst Washington DC
- category analyst Washington DC
- junior analyst Washington DC
- crime analyst Washington DC
- law enforcement response team analyst Washington DC
- meditech analyst Washington DC
- facility analyst Washington DC
- proposal analyst Washington DC


