Cybersecurity Analyst III
Upbound Group Inc.
Cybersecurity Analyst III Vulnerability Management Specialist Information Security | Cybersecurity Operations On-Site, Full-Time About the Role This position is the senior technical owner of our enterprise vulnerability management program. The ideal candidate combines deep technical expertise with the communication skills and organizational influence needed to drive risk reduction outcomes across the business. Incident response support is a secondary but meaningful responsibility. Job Purpose The Cybersecurity Analyst III — Vulnerability Management Specialist leads our enterprise vulnerability management program across cloud, endpoint, network, and identity environments. This role is responsible for the full vulnerability lifecycle: continuous discovery and scanning, risk-based prioritization, coordinated remediation, validation, and executive reporting. This is a program leadership role, not simply an analyst seat. The right candidate drives measurable risk reduction by building strong cross-functional relationships, maintaining clear remediation SLAs, and ensuring the organization consistently moves from vulnerability identification to resolution. In addition to owning the VM program, this analyst supports cybersecurity incident response efforts, contributing environmental knowledge and analytical depth when incidents arise. Key Responsibilities Vulnerability Management Program Leadership (Primary Focus — ~70–80%) Lead the enterprise vulnerability management lifecycle: asset discovery, continuous scanning, risk-based prioritization, remediation coordination, validation, and reporting. Define and maintain SLA/remediation timelines by risk tier and manage escalation paths for items approaching or exceeding thresholds. Partner with infrastructure, cloud, engineering, application, and endpoint teams to ensure vulnerability findings is clearly communicated, ownership is assigned, and remediation is completed on schedule. Translate vulnerability data into business context: deliver clear reporting for technical teams and concise risk summaries for executive audiences that reflect progress, trends, and areas of focus. Prioritize vulnerabilities using risk-based methodologies that incorporate CVSS scores, EPSS, CISA KEV, asset criticality, business impact, and active threat intelligence — not severity scores in isolation. Maintain a formal risk acceptance and exception process, including documentation of business justification, compensating controls, and expiration timelines. Integrate vulnerability findings into ticketing and ITSM workflows (e.g., ServiceNow, Jira) to ensure every finding has an assigned owner, a due date, and a tracked resolution path. Develop and maintain program KPIs: vulnerability fix rate, mean time to remediate (MTTR), scan coverage, exception aging, and sustained reduction in critical/high exposure. Facilitate regular stakeholder reviews with technology teams to assess remediation progress, surface blockers, and maintain shared accountability for risk outcomes. Continuously refine scanning coverage, tool configurations, and program policies in response to environmental changes and evolving threats. Monitor threat intelligence feeds, vulnerability disclosures, and CISA KEV to identify newly weaponized vulnerabilities that warrant accelerated remediation cycles. Coordinate formal risk acceptance decisions with leadership for findings that cannot be addressed within standard timelines; maintain auditable records of approvals. Incident Response Support (Secondary Focus — ~20–30%) Support cybersecurity incident response activities including triage, containment, eradication, recovery, and post-incident review. Apply vulnerability landscape knowledge and asset inventory familiarity to provide rapid environmental context during active investigations. Participate in incident post-mortems and incorporate findings into vulnerability management program improvements. Contribute to security documentation including runbooks, playbooks, and vulnerability management procedures. Cross-Functional Collaboration & Communication Serve as the primary security point of contact for technology teams on vulnerability obligations, remediation expectations, and risk escalation. Advise technology partners on patch management strategies, configuration hardening, and compensating controls. Support internal audit and compliance engagements by demonstrating control effectiveness against SOX, PCI-DSS, and other applicable frameworks. Promote security awareness among technology partners by providing clear context on why remediation requirements exist and how they protect the organization. Who Thrives Here This role is best suited for a security professional who takes ownership seriously — someone who is as focused on getting vulnerabilities fixed as they are on finding them. If you are energized by building relationships, navigating organizational dynamics, and tracking risk metrics over time, you will find this role deeply rewarding. Required Qualifications Vulnerability Management Expertise 5+ years of experience in cybersecurity operations, with at least 3 years in a role focused on enterprise vulnerability management. Hands-on experience with enterprise vulnerability scanning platforms such as Tenable (Nessus / Tenable.io / Tenable.sc), Qualys, or Rapid7 InsightVM. Demonstrated experience owning a vulnerability management program end to end, including SLA development, remediation coordination, and stakeholder accountability. Experience integrating vulnerability findings with ITSM or ticketing platforms (ServiceNow, Jira, or equivalent) to operationalize remediation workflows. Strong command of risk-based vulnerability prioritization frameworks: CVSS, EPSS, CISA KEV, asset criticality, and business impact analysis. Experience developing vulnerability metrics, executive dashboards, and program performance reporting. Familiarity with vulnerability lifecycle management practices: risk acceptance, exception handling, compensating controls, and SLA governance. Stakeholder Engagement & Cross-Functional Influence Proven ability to drive remediation outcomes through technology teams (infrastructure, cloud, engineering, application) using influence, communication, and structured accountability — without direct management authority. Strong written and verbal communication skills with the ability to tailor messaging for technical and non-technical audiences alike. Experience facilitating recurring stakeholder forums such as remediation review meetings, and maintaining follow-through on commitments via escalation when needed. Demonstrated ability to build credibility and collaborative relationships across peer teams. Technical Depth Solid understanding of cloud security in AWS and/or Azure environments, including cloud-native security tooling and logging architectures. Familiarity with endpoint protection, network monitoring, intrusion detection, and IAM platforms. Working knowledge of core network protocols (TCP/IP, DNS, SMTP, etc.). Experience with SIEM platforms and security log analysis. Familiarity with the MITRE ATT&CK framework and how adversary TTPs inform vulnerability prioritization. Foundational knowledge of incident response concepts and practices sufficient to contribute meaningfully when called upon. Preferred Qualifications Relevant certifications: CISSP, GPEN, GWAPT, CompTIA Security+, Tenable Certified, Qualys Certified, or equivalent. Familiarity with SOX and PCI-DSS compliance requirements as they relate to vulnerability and patch management. Experience with exposure management methodologies such as Continuous Threat Exposure Management (CTEM) and attack surface management. Familiarity with SOAR platforms or automation tools used to streamline vulnerability-to-ticket workflows. Experience with Microsoft Defender suite, Rapid7, or comparable enterprise security platforms. Exposure to penetration testing or adversary emulation methodologies to inform vulnerability prioritization. Familiarity with AI-assisted attack techniques and their implications for vulnerability exploit timelines. What Success Looks Like All critical and high vulnerabilities tracked in integrated workflows with clear ownership and due dates Consistent remediation within defined SLA timelines across technology teams Measurable, sustained reduction in mean time to remediate (MTTR) for critical and high findings Reliable executive reporting cadence with meaningful risk trend data Comprehensive scan coverage across endpoint, cloud, network, and identity environments Additional Information This position requires on-site presence five days per week (Monday – Friday). Sponsorship Applicants must be authorized to work for ANY employer in the U.S. We are unable to sponsor or take over sponsorship of an employment visa at this time. You will join a collaborative and growing Cybersecurity Operations team where your leadership of the vulnerability management program directly shapes the organization’s security posture. This is a high-visibility role with broad cross-functional reach, real ownership, and the opportunity to make a measurable difference. If you are looking for a position where your work has clear, demonstrable impact on risk reduction, we want to hear from you. #J-18808-Ljbffr Upbound Group Inc.
- Scrum Master III Technology Operations and Engineering, Digital Business Operations Who We Are At Upbound Group, we are committed to elevating financial opportunity for all through innovative, inclusive, and technology-driven financial solutions that address the evolving...SuggestedLocal areaWork visaMonday to Friday
$95k - $110k
...export control laws, including ITAR. Candidates must be eligible to access such information. GENERAL PURPOSE OF THE JOB : The Cybersecurity Specialist positions purpose is to protect the organization’s digital assets, networks, and data from cyberattacks, theft, or...SuggestedWork experience placementRelocation package- ...Requirements ~ Bachelor's Degree or Equivalent experience ~2+ years Experience with installing, configuring, and using cybersecurity software for securing data. Knowledge of NetApp, Varonis and Trend Micro Server Protect is a bonus. ~ Exceptional understanding...Suggested
- Get notified about new Information Technology Security Analyst jobs in United States . 1,000+ Information Technology Security Analyst Jobs in United States Information Systems Security Officer (ISSO) Information Systems Security Officer (ISSO) Information Systems Security...Suggested
- US Citizens & Permanent Residents ONLY Job Title: Business Analyst III Job Location (Onsite, NO REMOTE): Cary, NC or Carrolton, TX Responsibilities: A Business Analyst III takes a more proactive role in analyzing business needs and translating them into effective technology...SuggestedPermanent employmentWork experience placementRemote work
$48 - $50 per hour
...World Report (Private Companies List, 2024-2025) One of the Largest IT Staffing Firms in the US – Ranked #3 by Staffing Industry Analysts (SIA, 2024) One of the Largest Staffing Firms in the US – Ranked #13 by Staffing Industry Analysts (SIA, 2024; includes Innova...Hourly payFull timeContract workTemporary workWork experience placementWork at officeImmediate startRemote workWorldwideFlexible hours- Overview The Infosys Financial Services unit is a global leader in driving digital transformation for financial institutions. We specialize in leveraging advanced technologies such as AI, cloud, and data‑led innovation to help our clients accelerate growth and unlock business...Temporary workRelocation
- ...The Field CISO serves as a trusted cybersecurity advisor to CyberOne customers, partnering with executive stakeholders to align cybersecurity strategies with business objectives, risk management priorities, and organizational goals. This role provides strategic guidance...Casual workWork at officeRemote workAfternoon shift
- ...Toyota Financial Services (TFS) Technology team is looking for a highly motivated person to fill a role as an Application Security Analyst. Your responsibilities will be to ensure the security of company software applications, web services, and APIs. You will work closely...Relocation packageEarly shift
- Overview Title: Application Security Analyst Duration: 12 Months Location: Plano, TX Pay Rate: $65/hr on W2 (H4, USC, GC, TN) Hybrid... ...Highlight Top 3-5 skills. Bachelor’s degree in Computer Science, Cybersecurity, or related field. 8+ years of experience in DevOps, Security...Remote workShift work
$106.58k - $177.63k
...alignment with organizational security policies and industry standards. The GRC Security Compliance Specialist works closely with cybersecurity, infrastructure, cloud, application, risk, audit, and business teams to validate control effectiveness, identify gaps, and drive...Full timeTemporary workWork at officeLocal areaRemote workFlexible hours- Upbound Group Inc. is hiring an Associate Enterprise Security Architect in Plano, Texas. This role focuses on developing and maintaining enterprise security architecture standards while collaborating closely with various IT and security teams. The ideal candidate should...
- ...Dental and Vision insurance, 401K retirement savings plan, Life Insurance, Disability Insurance. Job Description Job Title : Security Analyst Duration : 9 months (high possibility of extension) Description: Security Analyst works to protect data and system integrity from...Permanent employmentRemote work
- Senior Implementation Consultant Homecare Homebase is searching for a Senior Implementation Consultant who will act as an integral part of the clinical projects to ensure a successful implementation of Homecare Homebase's home health and hospice software. This person...Work experience placementRemote work
- ...of evolving Internet threats to ensure the security of Dell Services Client networks Participate in knowledge sharing with other analysts and develop customer solutions efficiently Coordinate or participate in individual or team projects to ensure quality support for...Work experience placementLocal areaRemote workAll shiftsShift work
- ...and access layers. Responsibilities include planning, designing, and engineering regional multi‑state networks with Layer I, II, and III, as well as carrier‑class MPLS, L2VPN, and L3VPN services. The role involves evaluating and validating new equipment and software releases...Local areaNight shift
$45.9k - $102.1k
At HCSC, our employees are the cornerstone of our business and the foundation to our success. We empower employees with curated development plans that foster growth and promote rewarding, fulfilling careers. Join HCSC and be part of a purpose-driven company that will invest...Full timeInternshipWork at officeRemote workFlexible hours- ...conversations. Tyler Technology is seeking a detail‑oriented QA Analyst with a focus on web accessibility. In this role, you’ll ensure... ...Manager to join our team! Tyler Technologies is looking for Cybersecurity Interns to join our team this summer! The Cybersecurity Intern...Summer workInternshipSummer internshipLive inWork at officeLocal areaRemote workTrial period
- The Vulnerability Management Team is the core function of Toyota Motor North America and is tasked with continually improving the security posture of Toyota Motor North America through the analysis of vulnerability and threat data, responding appropriately to the result...
- Responsibilities Your primary work will involve using our SIEM platform to fully investigate network security events, documenting your investigations in writing via a ticketing system, communicating with stakeholders, and resolving any identified issues. Gather and analyze...Work experience placement
- ...Province: Texas City: Richardson General Overview Functional Area: OPS - Operations Career Stream: SUP - Operations Support Role: Analyst SAP Short Name: ANA Job Title: Security Analyst Job Code: ANA-OPS-SEC Job Level: Band 07 Direct/Indirect Indicator: Indirect...Local area
- Security Consultant IAM and PAM Lead At least 8 to 10 years of experience in following areas: Identity & Access Management with implementation, development, and production support (ForgeRock OpenAM). IAM and SailPoint IIQ / IDN architecture, design, development...
$18.5 per hour
Starting Hourly Rate / Salario por Hora Inicial: $18.50 USD per hour ALL ABOUT TARGET Working at Target means helping all families discover the joy of everyday life. We bring that vision to life through our values and culture. Learn more about Target here. [ ...Hourly payLocal areaFlexible hoursShift workNight shift- Enterprise Architect Role Summary The Enterprise Architect shapes and governs the enterprise technology landscape of Upbound that involves Fintech, Specialty Financing, and Retail business to enable strategy, accelerate product delivery, and reduce complexity and risk. ...Work visa
- Minimum bachelor’s degree qualification, with strong quantitative background (STEM education background (Science, Technology, Engineering & Mathematics) AND/OR an MBA preferred) Deep knowledge of cloud architecture platforms (AWS, Azure) Familiarity with data center or ...
$58.29k - $100k
...challenges of translating business needs into technical reality. Potential team members with prior job titles ranging from business analyst, systems analyst, requirements engineer, process analyst, product manager, product owner, enterprise analyst, business architect,...Local areaRemote work- ...Pepper is seeking an Associate Security Analyst who is responsible for supporting the organization... ...of experience in IT/network security/cybersecurity. Basic understanding of information risk... ...Operations Center (SOC) Analyst III (Level 3) Addison, TX $130,000.00-$135,0...Full timeContract workWork experience placementLocal area
- Overview The Infosys Financial Services unit is a global leader in driving digital transformation for financial institutions. We specialize in leveraging advanced technologies such as AI, cloud, and data‑led innovation to help our clients accelerate growth and unlock business...Temporary workRelocation
$10k
Overview It's an exciting time to join Fisher Investments! We're continuing to invest in the future of our firm's technology and information security. Our business is growing internationally, which emphasizes the need to build an unparalleled global team that inspires future...Work at officeWork from home$30 - $40 per hour
...SOC 2 Type II certified MSP/ISP seeking a motivated Security Analyst I to join our security team. In this role, you'll be on the front... ...platform Minimum Qualifications: Understanding of cybersecurity principles, including threat and vulnerability management, risk...Night shift
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity Analyst III. Be the first to apply!
- cybersecurity software engineer Plano, TX
- cybersecurity certificate Plano, TX
- senior cybersecurity engineer Plano, TX
- cybersecurity administrator Plano, TX
- cyber security Plano, TX
- cyber security sales Plano, TX
- IT cyber security Plano, TX
- cybersecurity Plano, TX
- cybersecurity specialist Plano, TX
- remote cyber security Plano, TX




