Vulnerability Management Program Security Analyst
Chelsea, Suffolk County, Massachusetts, 02150, USA
Listed on 2026-07-23
-
IT/Tech
Cybersecurity, Information Security & Data Protection
The Executive Office of Technology Services and Security (EOTSS) is the lead enterprise technology organization for the Commonwealth of Massachusetts. Charged with driving the ongoing alignment of business and technology across the Commonwealth’s Executive Branch, EOTSS oversees and manages the enterprise technology, digital infrastructure and services, as well as the Commonwealth Security Operations Center and an enterprise Standard Operating Environment that includes an information security and risk management framework for over 125 state agencies and over 43,000 state employees.
We directly serve our constituents by providing digital services and tools that enable taxpayers, drivers, businesses, visitors, families and other citizens to do business with the Commonwealth in a way that makes every interaction with government easier, faster, and more secure.
Our Mission: We provide technology leadership across the Commonwealth to enhance the quality of public service and foster positive community outcomes.
EOTSS is seeking to hire a SOC Vulnerability Management Program Security Analyst II to join the Security Operations Team
. This is an exciting opportunity for an IT professional to join an exceptionally skilled team and contribute to critical statewide initiatives. The SOC VMP Security Analyst II is responsible for providing security vulnerability scanning, reporting, tracking, remediation, and analysis through continuous evaluation and prioritization of exposures. The successful candidate will have working knowledge of application, network, and operating system security frameworks and best practices.
The incumbent of this role will assist with the development and implementation of the Enterprise Vulnerability Management Program as a member of the Vulnerability Management team.
The primary work location for this role will be at 200 Arlington Street Chelsea, Massachusetts 02150
. The work schedule for this position is Monday through Friday, 9AM to 5PM EST
. This position is expected to follow a hybrid model of reporting to work that combines in-office workdays and work from home days as needed.
All offers of employment into this position are conditional and subject to passing: a Massachusetts Criminal Background Check (CORI); a security clearance (fingerprinting) consistent with IRS and/or public safety requirements; and security training.
Responsibilities:- Act as primary point of contact for one or more secretariats and/or agencies by establishing a regular cadence to review status of security posture while driving continuous improvements in security practices.
- Conduct vulnerability scans and assessments of the environment by analyzing the output from automated scanning tools to identify security weaknesses. The goal is to maintain continuous visibility into the security posture and proactively detect new vulnerabilities as soon as they appear, ensuring the organization stays one step ahead of potential threats.
- Communicate and report vulnerabilities by notifying system owners and other stakeholders through both formal written reports and informal discussions. This ensures that all parties are aware of the risks and the steps being taken to mitigate them, fostering essential collaboration and accountability across the organization.
- Maintain threat intelligence knowledge as well as the threat landscape by collecting and cataloging threat indicators from various sources. Understanding the latest threats and attack methods allowing technology stakeholders to be more proactive in its defenses, anticipating which new vulnerabilities might be targeted and focusing remediation efforts accordingly.
- Track and analyze vulnerability metrics over time by compiling data on their discovery and remediation status for tracking purposes. This quantitative data provides a way to measure the effectiveness of the vulnerability management program, demonstrating progress and helping to identify long-term security trends.
- Assist with prioritization of vulnerabilities on customer assets. This involves rating each vulnerability based on its severity and potential impact to set a clear remediation timeline, ensuring that the most critical risks are addressed first and resources are used efficiently.
- Other duties and responsibilities, as directed by management to address the changing threat landscape.
- Minimum of two (2) years of professional experience in information security or IT security, providing technical guidance across systems, networks, and applications in support of vulnerability management initiatives.
- Passion for cybersecurity with a strong commitment to continuous learning and professional development.
- Strong understanding of networking concepts, Windows and Linux operating systems, and common security protocols.
- Experience supporting vulnerability management programs, including vulnerability assessment tools, cloud security solutions, and related technologies.
- Experience coordinating with…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).