About the job Cybersecurity Vulnerability Management Specialist
Cybersecurity Vulnerability Management Specialist
Position Overview
We are seeking a Cybersecurity Vulnerability Management Specialist to identify, assess, prioritize, and remediate security vulnerabilities across our enterprise infrastructure and applications, utilizing advanced scanning tools and implementing comprehensive vulnerability management programs to maintain organizational security posture.
Key Responsibilities
Vulnerability Assessment & Management
- Conduct comprehensive vulnerability assessments using automated scanning tools including InsightVM, Nessus, and Qualys
- Perform manual security testing and penetration testing to identify complex vulnerabilities
- Analyze vulnerability scan results, false positives, and prioritize remediation based on risk scoring
- Track vulnerability lifecycle from discovery through remediation and verification
- Maintain vulnerability databases and generate executive-level security metrics and dashboards
Risk Analysis & Prioritization
Evaluate vulnerability severity using CVSS scoring and business impact assessmentsCorrelate vulnerability data with threat intelligence to identify active exploitation risksConduct risk assessments considering asset criticality, environmental factors, and exposure levelsDevelop vulnerability treatment strategies including remediation, mitigation, and acceptance decisionsCreate risk-based remediation roadmaps and timeline recommendationsRemediation & Patch Management
Collaborate with IT teams to develop and implement remediation strategies and patch deployment schedulesCoordinate emergency patching for critical vulnerabilities and zero-day exploitsValidate remediation effectiveness through re-scanning and verification proceduresManage patch testing procedures and rollback plans for critical systemsImplement compensating controls and temporary mitigations for systems that cannot be immediately patchedReporting & Compliance
Generate comprehensive vulnerability reports for technical teams, management, and audit purposesCreate security metrics and KPIs to measure vulnerability management program effectivenessSupport compliance audits and regulatory requirements (SOX, PCI-DSS, HIPAA, ISO 27001)Maintain vulnerability management documentation and standard operating proceduresPresent security posture updates to executive leadership and risk committeesRequired Qualifications
Technical Skills
6+ years experience in vulnerability management and cybersecurity operationsExpert proficiency with vulnerability scanning tools (InsightVM, Nessus, Qualys, OpenVAS)Strong knowledge of common vulnerabilities (OWASP Top 10, CVE database, CWE framework)Experience with patch management systems and automated remediation toolsUnderstanding of network security, web application security, and infrastructure hardeningProficiency in scripting languages (Python, PowerShell) for automation and data analysisSecurity Skills
Strong understanding of risk assessment methodologies and vulnerability prioritization frameworksExperience with penetration testing tools and manual security assessment techniquesKnowledge of security frameworks (NIST, ISO 27001, CIS Controls) and compliance requirementsUnderstanding of threat intelligence integration and attack vector analysisPreferred Qualifications
Bachelor's degree in Cybersecurity, Information Technology, or related fieldSecurity certifications (CISSP, CISM, CEH, GCIH, GIAC)Experience with cloud security assessments (AWS, Azure, GCP)Background in DevSecOps and secure software development lifecycle integrationKnowledge of security orchestration and automated response (SOAR) platforms