Security Vulnerability Management Analyst
Job in
New York, New York County, New York, 10261, USA
Listed on 2026-02-21
Listing for:
TEKsystems
Full Time
position Listed on 2026-02-21
Job specializations:
-
IT/Tech
Cybersecurity, Information Security, IT Consultant, Network Security
Job Description & How to Apply Below
- HYBRID IN NYC
Our client is looking for a Security Vulnerability Management Analyst that will perform vulnerability scans, assess vulnerabilities identified and prioritize their remediation; help review and enhance the current vulnerability management program. This position will interface between various Information Technology teams and this individual must be able to articulate the vulnerabilities and remediations to the stakeholders. Additionally this individual should also be able to translate the IT security requirements and constraints of the business into technical control requirements and specifications, help in coordinating the IT organization's technical activities to implement and manage security.
The Security Vulnerability Management Analyst is part of the Enterprise Information Technology Services, Information Security and Risk Management team and will work at an enterprise level to ensure a consistent delivery of information security and risk management services with focus on vulnerability management. This individual will act as a subject matter expert in vulnerability management.
Top Skills' Details
- 10 years of IT experience, with at least 7 years dedicated to IT/Cyber Security, including Solution Design.
- 3-5+ yrs. Experience with vulnerability scanning tools, preferably Rapid7, Experience with vulnerability and patch assessment and strong knowledge of vulnerability scoring systems (CVSS/CMSS), and security frameworks like OWASP (Open Web Application Security Project), MITRE ATT&CK, Good understanding of Windows and Linux patching
- 3-5 yrs. Excellent writing and communication skills in order to communicate findings and remediation status and Knowledge of encryption algorithms, known vulnerabilities from alerts, advisories, errata and bulletins.
- Perform vulnerability scans across enterprise including the corporate data centers
- Assess vulnerabilities identified by infrastructure and application scan, penetration testing, etc
- Prioritize remediation of vulnerabilities discovered along with remediation timeline(s)
- Assist in providing support, planning and execution of remediation of vulnerabilities
- Track and document vulnerabilities, create and maintain vulnerability management report(s)
- Attend regular team meetings and facilitate meetings between stakeholders, project leaders, and the Information Technology teams on remediation of vulnerabilities
- Assess vulnerabilities in cloud, containerized, and Dev Ops environments
- Help improve and automate existing vulnerability management program
- Stay current with vulnerability information across all the products in environment, maintain knowledge of the threat landscape
- Assist in integrating vulnerability management system with third party solutions like Service Now and other available products as and when needed
- Work with various stakeholders to identify information asset owners
- Assist in identification of emerging security technologies that can maintain or improve security posture, and implement them as and when required
- Actively engage in security architecture solutioning
- Keep informed on current threats and industry regulations
- Attend regular team, management, and project meetings and provide both verbal and written reports to the Leadership Team as required.
- Develop a strong working relationship with the security engineering team to develop and implement controls and configurations aligned with security policies and legal, regulatory and audit requirements
- Experience with vulnerability scanning tools, preferably Rapid7
- Experience with vulnerability and patch assessment
- Strong knowledge of vulnerability scoring systems (CVSS/CMSS), and security frameworks like OWASP (Open Web Application Security Project), MITRE ATT&CK
- Good understanding of Windows and Linux patching
- Excellent writing and communication skills in order to communicate findings and remediation status
- Knowledge of network and operating system security
- Knowledge of encryption algorithms, known vulnerabilities from alerts, advisories, errata and bulletins
- Utilize/understand the use of open source tools such as Nmap, Shodan, and Metasploit to identify and confirm…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×