Senior Vulnerability Management Analyst
Core
Lead enterprise vulnerability programs across SDLC, external attack surface, and internal infrastructure, driving end-to-end lifecycle management from discovery to remediation validation.
Role type
Senior Vulnerability Management Analyst
Builds
Secure development workflows, hardened cloud/network configurations, and reduced external attack surface
Domain
Financial Services / Cybersecurity
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
vulnerability lifecycle management, risk triage, threat modeling, secure configuration, SAST/DAST/IAST/SBOM practices, cloud hardening, penetration testing coordination, CVSS scoring, asset criticality assessment
Preferred skills
KEV catalog operationalization, threat-intel integrations, automation platforms
Technologies
SAST, DAST, IAST, SBOM, CI/CD pipelines, cloud environments, OS environments
Responsibilities
Lead vulnerability prioritization using CVSS and exploit intel; Partner with engineering to remove remediation blockers; Own complex vulnerability investigations; Mentor junior analysts; Provide remediation guidance and secure configuration recommendations; Help with pen test pre-work; Manage findings intake and track to closure; Lead lessons learned and control improvements; Lead continuous reduction of external attack surface; Partner with Cloud/SRE to harden configurations; Partner with engineering to mature secure build pipelines; Guide threat modeling and secure coding practices; Review architecture for high-risk components
Seniority
Senior, hands-on IC with mentorship