Vulnerability Management Analyst

Tech Economy

Ciudad de México

Híbrido

MXN 600.000 - 900.000

Jornada completa

Hace 6 días
Sé de los primeros/as/es en solicitar esta vacante

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Descripción de la vacante

Bain & Company in Mexico City offers a hybrid role as Vulnerability Management Analyst within its Cyber Operations team. You will mature our vulnerability and exposure program across servers, endpoints, and multi-cloud workloads.

You will lead CTEM, set remediation standards, and mentor junior analysts while partnering with IT and engineering to translate findings into actionable risk insights for leadership.

Formación

  • 3–5 years hands-on in vulnerability or security operations.
  • Deep understanding of vulnerability lifecycle and SLA governance.
  • Hands-on with Qualys VMDR, Wiz and Tanium for deployment and reporting.
  • Experience with CVSS, EPSS, KEV and threat intelligence.
  • Strong data and reporting skills including Excel/BI tooling.
  • Proven ability to communicate to engineers and leadership.

Responsabilidades

  • Own and mature the end-to-end vulnerability management lifecycle.
  • Administer core exposure tooling stack: Qualys VMDR, Wiz, Tanium.
  • Lead CTEM scoping, prioritization, validation, and mobilization.
  • Prioritize vulnerabilities using CVSS, EPSS, KEV and threat intel.
  • Enforce SLAs and drive accountability across teams.
  • Coordinate with threat intel to surface risks for leadership.
  • Define risk-acceptance standards and maintain audit docs.
  • Build dashboards and executive reports on exposure and aging.
  • Mentor junior analysts and act as escalation point.
  • Advise on secure configuration and program maturity.

Conocimientos

Vulnerability management
CTEM
English communication
Threat intelligence
Data reporting
Multi-cloud environments

Herramientas

Qualys VMDR
Wiz
Tanium

Descripción del empleo

What Makes Us a Great Place To Work

We are proud to be consistently recognized as one of the world’s best places to work. We are currently the top ranked consulting firm on Glassdoor’s Best Places to Work list and have earned the #1 overall spot a record seven times. Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment. We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally.

Who You’ll Work With

You’ll join our Cyber Operations team within Bain’s Technology Services Group (TSG), working closely with IT, infrastructure, cloud, and engineering teams across a large and diverse global environment.

WHERE YOU’LL FIT WITHIN THE TEAM

As a Vulnerability Management Analyst, you’ll operate and drive the day-to-day maturity of our vulnerability and exposure management program across a large, diverse global environment spanning servers, endpoints, network devices, containers, and multi-cloud workloads.

You’ll run our core tooling stack hands-on — Qualys Vulnerability Management, Detection and Response (VMDR) for host and application scanning, Wiz for cloud and container posture, and Tanium for endpoint visibility and remediation.

You’ll also lead a Continuous Threat Exposure Management (CTEM) program that turns findings from these tools into a single, risk-prioritized view of real exposure. Working closely with IT, infrastructure, cloud, and engineering teams, you’ll set remediation standards, drive accountability, guide junior analysts, and brief leadership on exposure and risk trends.

Location and working model: Mexico City, Mexico. This role follows a hybrid working model and requires you to work from Bain’s Polanco office at least two days per week.

What You’ll Do
  • Own and continuously mature the end-to-end vulnerability management lifecycle across the enterprise, including asset discovery, scanning, detection, validation, prioritization, remediation governance, rescanning, and closure verification.
  • Operate and administer the core exposure tooling stack hands-on — Qualys VMDR for host and application scanning, Wiz for cloud and container posture, and Tanium for endpoint visibility and remediation — including deployment, configuration, tuning, integration, and scanner, agent, and sensor health.
  • Lead the Continuous Threat Exposure Management (CTEM) program, running the scoping, discovery, prioritization, validation, and mobilization cycles and correlating findings across host, cloud, and endpoint sources into a single de-duplicated, risk-ranked view of exposure.
  • Prioritize vulnerabilities using the Common Vulnerability Scoring System (CVSS) combined with exploitability signals, including the Exploit Prediction Scoring System (EPSS) and CISA Known Exploited Vulnerabilities (KEV), threat intelligence, and asset and business criticality — focusing remediation on what is exploitable and material.
  • Set and enforce remediation service-level agreements (SLAs) and drive accountability with IT, infrastructure, cloud, and engineering teams, translating findings into clear, actionable work and escalating aged or high‑risk exposures.
  • Partner with threat intelligence to correlate external threat activity with internal findings, translate emerging threats into targeted validation and remediation, and surface material risks for escalation.
  • Define exception and risk‑acceptance standards, review and adjudicate requests, and maintain defensible documentation to support audits, compliance, and leadership reporting.
  • Build and automate dashboards, metrics, and executive reporting on exposure, scan coverage, vulnerability aging, and SLA adherence using native tool reporting, Excel, including pivot tables, and query or business intelligence tooling.
  • Mentor junior analysts, set standards for triage, documentation, and reporting quality, and act as the escalation point for complex or contested findings.
  • Advise on secure configuration, hardening, and overall program maturity, and communicate findings and recommendations clearly to audiences ranging from engineers to senior stakeholders.
About You
Required Qualifications
  • Experience: You have 3–5 years of hands‑on experience in vulnerability management, exposure management, or closely related security operations, including time in a lead capacity.
  • Lifecycle and governance: You have a deep understanding of the vulnerability management lifecycle, risk‑based remediation, and SLA governance across large, complex environments.
  • Tooling — hands‑on: You have direct, hands‑on experience operating and administering Qualys VMDR, Wiz, and Tanium, including deployment, configuration, tuning, integration, and reporting. Hands‑on depth with all three is required.
  • CTEM: You have demonstrated experience running or materially contributing to a Continuous Threat Exposure Management program across its scoping, discovery, prioritization, validation, and mobilization phases.
  • Risk prioritization: You are proficient in CVSS analysis combined with exploitability signals, including EPSS and CISA KEV, and threat‑intelligence‑driven, risk‑based prioritization.
  • Data and reporting: You have strong data and reporting skills, including Excel and pivot tables, native tool reporting, and ideally query or business intelligence tooling, enabling you to produce both technical and executive‑level metrics.
  • Environment breadth: You have proven experience securing large, diverse environments spanning Windows, Linux, network devices, endpoints, containers, and multi‑cloud workloads.
  • Threat awareness: You have strong working knowledge of threat intelligence sources and the ability to correlate external threat data with internal findings to drive prioritization.
  • Communication and leadership: You have excellent written, verbal, and presentation skills, with the ability to influence remediation owners, brief senior leadership, and mentor junior analysts.
  • English: Advanced English proficiency is required, with the ability to communicate effectively in professional and technical environments.
Preferred / Nice‑to‑Have
  • Cloud and container security: Working knowledge of cloud security posture management (CSPM), cloud‑native application protection platforms (CNAPP), and container/Kubernetes security concepts, ideally through Wiz or an equivalent platform.
  • Benchmarking: Working knowledge of CIS Benchmarks and secure configuration and hardening standards.
  • Automation: Exposure to scripting or automation, such as Python, PowerShell, tool APIs, or Power Query, to integrate tooling and streamline reporting or remediation workflows.
  • Integrations: Experience integrating vulnerability and exposure tooling with IT service management (ITSM) platforms, such as ServiceNow, to automate remediation workflows.
Certifications

One or more relevant certifications are preferred, or a willingness to obtain them:

  • Qualys VMDR Certification
  • Wiz Certified or equivalent cloud security/CNAPP certification
  • GIAC certification, such as GEVA or GCED, or Certified Ethical Hacker (CEH)
  • CISSP, Tanium, or CompTIA Security+, or progress toward these certifications
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Vulnerability Management Analyst
Vulnerability Management Analyst

Bain & Company • Ciudad de México

Híbrido
MXN 600.000 - 900.000
Cyber Security Operations & Incident Response Specialist
Cyber Security Operations & Incident Response Specialist

Tech Economy • Ciudad de México

Híbrido
MXN 600.000 - 900.000
Cyber Security Operations & Incident Response Specialist
Cyber Security Operations & Incident Response Specialist

Bain & Company • Ciudad de México

Híbrido
MXN 450.000 - 700.000
Vulnerability Management Lead - CTEM & Cloud Security
Vulnerability Management Lead - CTEM & Cloud Security

Bain & Company • Ciudad de México

Híbrido
MXN 600.000 - 900.000
Senior Vulnerability & CTEM Analyst
Senior Vulnerability & CTEM Analyst

Tech Economy • Ciudad de México

Híbrido
MXN 600.000 - 900.000
Consultor de Gestión de Vulnerabilidades
Consultor de Gestión de Vulnerabilidades

Scitum S.A. de C.V. • San Jerónimo

Híbrido
MXN 60.000 - 100.000
Vulnerability Management
Vulnerability Management

HCLTech • Región Centro

Presencial
MXN 450.000 - 650.000
Premium coverage
Savings fund 13%
Insurance (Dental, Vision, Auto)
+2
Cloud Vulnerability Management Analyst
Cloud Vulnerability Management Analyst

Rockwell Automation • Monterrey

Presencial
MXN 931.000 - 1.677.000
Mindfulness programs with Calm membership
Volunteer paid time off after 6 months
Volunteer and donation matching programs
+2
Vulnerability Risk & Compliance Manager
Vulnerability Risk & Compliance Manager

W3Global • México

Híbrido
MXN 500.000 - 900.000
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

A2MAC1 - Decode the future • Santiago de Querétaro

Presencial
MXN 700.000 - 1.100.000
Biweekly pay
IMSS
Christmas bonus
+6