Vulnerability Assessment Analyst
Orangepeople
We are looking for a Vulnerability Assessment Analyst to support the identification, assessment, remediation, and lifecycle management of security vulnerabilities across the enterprise environment. This role will partner with infrastructure, application, cloud, network, and other technology teams to investigate potential vulnerabilities, assess risk and impact, determine appropriate remediation actions, and drive vulnerabilities through resolution.
The ideal candidate will have hands-on experience with vulnerability assessment and management processes, strong technical troubleshooting skills, and the ability to effectively communicate security risks and remediation requirements across technical and business teams.
Key Responsibilities:
- Review and investigate vulnerability alerts, findings, tickets, and security notifications.
- Assess identified vulnerabilities for validity, severity, exploitability, business impact, and remediation priority.
- Identify affected systems or assets and determine appropriate remediation or mitigation actions.
- Partner with infrastructure, application, cloud, network, endpoint, and other technology teams to coordinate remediation.
- Manage vulnerability tickets end-to-end, from initial assessment through remediation, validation, and closure.
- Provide remediation guidance, including patching, configuration changes, upgrades, or compensating controls.
- Track remediation progress and follow up with responsible teams to ensure timely resolution.
- Validate remediation activities and maintain appropriate documentation of findings and resolution.
- Identify recurring vulnerabilities and opportunities to improve security controls and vulnerability management processes.
- Support vulnerability reporting, metrics, risk tracking, and communication with relevant stakeholders.
Required Qualifications:
- Experience in Vulnerability Management, Vulnerability Assessment, Cybersecurity Operations, Security Engineering, or a related security function.
- Hands-on experience with vulnerability scanning or management platforms such as Tenable/Nessus, Qualys, Rapid7 InsightVM, Microsoft Defender Vulnerability Management, or similar tools.
- Strong understanding of CVEs, CVSS, vulnerability prioritization, patching, remediation, and validation processes.
- Working knowledge of Windows/Linux, networking, applications, servers, and/or cloud infrastructure.
- Ability to investigate technical security findings and determine appropriate remediation or mitigation actions.
- Experience with ticketing/workflow platforms such as ServiceNow, Jira, or similar.
- Strong analytical, troubleshooting, communication, and stakeholder-management skills.
- Ability to take ownership of vulnerability findings and drive them through resolution.
Preferred Qualifications:
- Experience with AWS, Azure, or other cloud environments.
- Familiarity with OWASP Top 10, CIS Benchmarks, NIST, or similar security frameworks.
- Experience with scripting or automation using Python, PowerShell, Bash, or similar technologies.
- Familiarity with vulnerability remediation SLAs, risk exceptions, and security compliance processes.
- Relevant security certifications are a plus.
Benefits:
- 401(k).
- Dental Insurance.
- Health insurance.
- Vision insurance.
- We are an equal-opportunity employer and value diversity, equality, inclusion, and respect for people.
- The salary will be determined based on several factors, including, but not limited to, location, relevant education, qualifications, experience, technical skills, and business needs.
Additional Responsibilities:
- Participate in OP monthly team meetings and participate in team-building efforts.
- Contribute to OP technical discussions, peer reviews, etc.
- Contribute content and collaborate via the OP-Wiki/Knowledge Base.
- Provide status reports to OP Account Management as requested.
About us:
At OP, we help you harness the power of technology for maximum impact. A technology consulting and solutions company, we offer advisory and managed services, innovative platforms, and staffing solutions across a wide range of fields including AI, cyber security, enterprise architecture, and beyond. For nearly two decades, we've been challenging the status quo of the consulting industry, serving up fresh, ingenious thinking through a radically lean structure. Together, this strategy delivers unprecedented performance at an unparalleled pace for faster results that propel your business forward.
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vulnerability Assessment Analyst. Be the first to apply!
