×
Register Here to Apply for Jobs or Post Jobs. X

Cybersecurity Analyst III

Job in Plano, Collin County, Texas, 75086, USA
Listing for: Upbound Group Inc.
Full Time position
Listed on 2026-07-14
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security
Salary/Wage Range or Industry Benchmark: 110000 - 160000 USD Yearly USD 110000.00 160000.00 YEAR
Job Description & How to Apply Below

Cybersecurity Analyst III
Vulnerability Management Specialist
Information Security | Cybersecurity Operations

On-Site, Full-Time

About the Role

This position is the senior technical owner of our enterprise vulnerability management program. The ideal candidate combines deep technical expertise with the communication skills and organizational influence needed to drive risk reduction outcomes across the business. Incident response support is a secondary but meaningful responsibility.

Job Purpose

The Cybersecurity Analyst III — Vulnerability Management Specialist leads our enterprise vulnerability management program across cloud, endpoint, network, and identity environments. This role is responsible for the full vulnerability lifecycle: continuous discovery and scanning, risk-based prioritization, coordinated remediation, validation, and executive reporting.

This is a program leadership role, not simply an analyst seat. The right candidate drives measurable risk reduction by building strong cross-functional relationships, maintaining clear remediation SLAs, and ensuring the organization consistently moves from vulnerability identification to resolution. In addition to owning the VM program, this analyst supports cybersecurity incident response efforts, contributing environmental knowledge and analytical depth when incidents arise.

Key Responsibilities Vulnerability Management Program Leadership (Primary Focus — ~70–80%)
  • Lead the enterprise vulnerability management lifecycle: asset discovery, continuous scanning, risk-based prioritization, remediation coordination, validation, and reporting.
  • Define and maintain SLA/remediation timelines by risk tier and manage escalation paths for items approaching or exceeding thresholds.
  • Partner with infrastructure, cloud, engineering, application, and endpoint teams to ensure vulnerability findings is clearly communicated, ownership is assigned, and remediation is completed on schedule.
  • Translate vulnerability data into business context: deliver clear reporting for technical teams and concise risk summaries for executive audiences that reflect progress, trends, and areas of focus.
  • Prioritize vulnerabilities using risk-based methodologies that incorporate CVSS scores, EPSS, CISA KEV, asset criticality, business impact, and active threat intelligence — not severity scores in isolation.
  • Maintain a formal risk acceptance and exception process, including documentation of business justification, compensating controls, and expiration timelines.
  • Integrate vulnerability findings into ticketing and ITSM workflows (e.g., Service Now, Jira) to ensure every finding has an assigned owner, a due date, and a tracked resolution path.
  • Develop and maintain program KPIs: vulnerability fix rate, mean time to remediate (MTTR), scan coverage, exception aging, and sustained reduction in critical/high exposure.
  • Facilitate regular stakeholder reviews with technology teams to assess remediation progress, surface blockers, and maintain shared accountability for risk outcomes.
  • Continuously refine scanning coverage, tool configurations, and program policies in response to environmental changes and evolving threats.
  • Monitor threat intelligence feeds, vulnerability disclosures, and CISA KEV to identify newly weaponized vulnerabilities that warrant accelerated remediation cycles.
  • Coordinate formal risk acceptance decisions with leadership for findings that cannot be addressed within standard timelines; maintain auditable records of approvals.
Incident Response Support (Secondary Focus — ~20–30%)
  • Support cybersecurity incident response activities including triage, containment, eradication, recovery, and post-incident review.
  • Apply vulnerability landscape knowledge and asset inventory familiarity to provide rapid environmental context during active investigations.
  • Participate in incident post-mortems and incorporate findings into vulnerability management program improvements.
  • Contribute to security documentation including runbooks, playbooks, and vulnerability management procedures.
Cross-Functional Collaboration & Communication
  • Serve as the primary security point of contact for technology teams on vulnerability…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary