SOC Vulnerability Management Program Security Analyst
Listed on 2026-07-21
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Title
Security Analyst II – SOC Vulnerability Management Program (260004WQ)
AgencyExecutive Office of Technology Services and Security
Location200 Arlington Street, Chelsea, Massachusetts 02150, United States
ScheduleFull-time, Monday through Friday, 9AM to 5PM EST. Hybrid model.
The Executive Office of Technology Services and Security (EOTSS) is the lead enterprise technology organization for the Commonwealth of Massachusetts. Charged with driving the ongoing alignment of business and technology across the Commonwealth’s Executive Branch, EOTSS oversees and manages the enterprise technology, digital infrastructure and services, including the Commonwealth Security Operations Center and an enterprise Standard Operating Environment that includes an information security and risk management framework for over 125 state agencies and over 43,000 state employees.
MissionOur Mission: We provide technology leadership across the Commonwealth to enhance the quality of public service and foster positive community outcomes.
Role SummaryThe SOC Vulnerability Management Program Security Analyst II is responsible for providing security vulnerability scanning, reporting, tracking, remediation, and analysis through continuous evaluation and prioritization of exposures. The analyst will assist with the development and implementation of the Enterprise Vulnerability Management Program as a member of the Vulnerability Management team.
Responsibilities- Act as primary point of contact for one or more secretariats and/or agencies, establishing a regular cadence to review status of security posture and drive continuous improvements.
- Conduct vulnerability scans and assessments, analyze the output from automated scanning tools to identify security weaknesses, and maintain continuous visibility.
- Communicate and report vulnerabilities to system owners and stakeholders through formal written reports and informal discussions.
- Maintain threat intelligence knowledge and collect threat indicators from various sources to inform defenses.
- Track and analyze vulnerability metrics over time, compiling data on discovery and remediation status for tracking purposes.
- Assist with prioritization of vulnerabilities on customer assets, rating each based on severity and impact to set remediation timelines.
- Perform other duties and responsibilities as directed by management to address the changing threat landscape.
- Minimum of two (2) years of professional experience in information security or IT security, supporting vulnerability management initiatives.
- Passion for cybersecurity with a strong commitment to continuous learning and professional development.
- Strong understanding of networking concepts, Windows and Linux operating systems, and common security protocols.
- Experience supporting vulnerability management programs, including tools, cloud security solutions, and related technologies.
- Experience coordinating third‑party penetration testing vendors, including engagement scoping, testing coordination, results review, remediation tracking, and reporting.
- Working knowledge of cloud computing platforms (IaaS, PaaS, SaaS) and security principles. Familiarity with AWS and/or Microsoft Azure.
- Knowledge of networking and infrastructure technologies (TCP/IP, DNS, DHCP, subnetting, routing, VLANs, VPNs, packet analysis, Active Directory, Microsoft 365, SSL/TLS).
- Understanding of industry‑standard vulnerability scoring methodologies, including CVSS.
- Experience with enterprise vulnerability management and application security tools such as Tenable One (Vulnerability Management, Cloud Security, Attack Surface Management, Exposure Management) and Veracode.
- Strong analytical, organizational, and problem‑solving skills with exceptional attention to detail.
- Excellent written and verbal communication skills, able to convey technical findings to technical and non‑technical stakeholders.
- Ability to manage multiple priorities, work independently and collaboratively, and adapt quickly in a fast‑paced environment.
- Experience with Veracode SAST, DAST, and Software Composition Analysis (SCA).
- Experience implementing or supporting SOAR platforms.
- Relevant industry…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).