Endpoint Security Analyst 5515

Tier4 Group

Washington (District of Columbia)

On-site

USD 110,000 - 140,000

Full time

11 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Tier4 Group is seeking a mid-level Endpoint Cybersecurity Vulnerability Remediation Analyst to identify, analyse and remediate vulnerabilities across enterprise endpoints. You will bridge Cybersecurity and IT Operations, validating findings from CrowdStrike Falcon and coordinating patching across Windows, Linux and MacOS environments.

The role requires hands-on vulnerability management experience, strong troubleshooting, and the ability to automate remediation using PowerShell and enterprise

Qualifications

  • 3–5 years in cybersecurity, vulnerability management, endpoint management, Windows administration or related IT discipline.
  • Hands-on experience remediating vulnerabilities in enterprise environments.
  • Experience with vulnerability management or endpoint security platforms such as CrowdStrike Falcon.
  • Strong knowledge of Windows 10/11 and Windows Server environments.
  • Experience with Microsoft Intune or comparable endpoint management platforms.
  • Experience deploying operating system and third‑party patches.

Responsibilities

  • Review vulnerability reports and exposure data from CrowdStrike Falcon and related tools.
  • Analyse open vulnerabilities affecting Windows, Linux and MacOS workstations and servers.
  • Validate findings to determine affected systems, software versions and remediation options.
  • Prioritise remediation based on CVSS, exploitation, asset criticality, business impact, age and OLAs.
  • Take ownership of assigned vulnerabilities from identification through remediation.
  • Deploy and coordinate security patches for Windows, Linux and MacOS devices using Intune, SCCM and related tools.
  • Develop automation to improve remediation at scale and create reusable procedures.

Skills

Vulnerability mgmt
CrowdStrike Falcon
Windows admin
Intune
Patch management
Automation
Root cause analysis
ITIL familiarity

Tools

PowerShell
SCCM
Patch My PC
Intune Remediations
Azure Update Manager

Job description

The Endpoint Cybersecurity Vulnerability Remediation Analyst is responsible for identifying, analysing, prioritising, and remediating cybersecurity vulnerabilities across enterprise workstation and server environments.

This position serves as a key operational link between Cybersecurity and IT Operations, with a strong focus on converting vulnerability findings into measurable remediation results. The analyst will regularly review vulnerability and exposure data from CrowdStrike Falcon, validate findings, determine appropriate remediation actions, and work directly with endpoint, server, application and infrastructure teams to ensure vulnerabilities are resolved within established Operational Level Agreements (OLAs).

This is a hands-on, mid-level technical position requiring strong troubleshooting, vulnerability management, Windows administration, patching and automation skills.

Key Responsibilities
Vulnerability Analysis & Prioritization
  • Review vulnerability reports, dashboards and exposure data generated through CrowdStrike Falcon and related cybersecurity tools.
  • Analyse open vulnerabilities affecting enterprise Windows, Linux and MacOS workstations and servers.
  • Validate vulnerability findings to determine affected systems, software versions, available patches, configuration changes and other remediation options.
  • Prioritise remediation based on:
    • CVSS severity
    • Active or known exploitation
    • Asset criticality
    • Business impact
    • Age of the vulnerability
    • Established organisational OLAs
  • Identify vulnerabilities that require immediate escalation due to active exploitation or significant organisational risk.
  • Distinguish between vulnerabilities requiring operating system patches, application updates, configuration changes, software removal or compensating controls.
Vulnerability Remediation
  • Take direct ownership of assigned vulnerabilities from identification through successful remediation.
  • Deploy and coordinate security patches for Windows workstations and servers, Linux servers and MacOS devices.
  • Use Microsoft Intune, Azure Update Manager, SCCM, Patch My PC, PowerShell and other enterprise management tools to deploy and automate remediation.
  • Work with server administrators and infrastructure teams when remediation requires server patching, configuration changes, application upgrades or maintenance windows.
  • Troubleshoot failed patches and unsuccessful remediation attempts.
  • Develop remediation solutions for vulnerabilities where traditional patching is not available.
  • Remove or upgrade obsolete, unsupported and vulnerable software when appropriate.
  • Validate that remediation actions have successfully eliminated or mitigated the identified vulnerability.
  • Ensure remediation activities minimise disruption to business operations.
OLA & Vulnerability Backlog Management
  • Monitor vulnerability ageing and ensure assigned vulnerabilities are remediated within established OLAs.
  • Maintain visibility into vulnerabilities approaching or exceeding OLA thresholds.
  • Proactively elevate vulnerabilities that are at risk of missing remediation targets.
  • Investigate vulnerabilities that remain open after remediation attempts and determine the root cause.
  • Assist with reducing the organisation's existing vulnerability backlog.
  • Identify recurring vulnerabilities and recommend systemic solutions rather than repeatedly addressing individual systems.
  • Track remediation progress and provide accurate status information to Cybersecurity and IT leadership.
  • Support exception and risk-acceptance processes when vulnerabilities cannot be remediated within established timeframes.
  • Develop PowerShell scripts and other automation to improve vulnerability remediation at scale.
  • Automate repetitive activities such as software detection, version validation, application removal, patch deployment, configuration changes and remediation verification.
  • Develop Intune remediation scripts and deployment packages where appropriate.
  • Identify opportunities to move from manual remediation to automated and policy-driven remediation.
  • Analyse recurring vulnerability trends and recommend improvements to endpoint and server configuration standards.
  • Create reusable remediation procedures for commonly identified vulnerabilities.
Reporting & Metrics

Assist with tracking and reporting key vulnerability‑management metrics, including:

  • Critical and high vulnerabilities
  • Vulnerabilities by workstation/server
  • Vulnerabilities by application or technology
  • Vulnerabilities within OLA
  • Vulnerability backlog
  • Average vulnerability age
  • Mean Time to Remediate (MTTR)
  • Remediation success rate
  • Reopened or recurring vulnerabilities
  • Vulnerability reduction trends

Provide technical explanations for vulnerabilities that remain unresolved and recommend corrective actions.

Documentation
  • Maintain clear documentation of vulnerability remediation procedures.
  • Document root causes and resolutions for complex or recurring vulnerabilities.
  • Develop knowledge articles and technical procedures that can be reused by Service Desk, Infrastructure and Cybersecurity teams.
  • Maintain documentation for automated remediation scripts and deployment packages.
  • Document exceptions, dependencies, remediation failures and required follow‑up activities.
Required Qualifications
  • 3–5 years of experience in cybersecurity, vulnerability management, endpoint management, Windows administration, systems administration or a related IT discipline.
  • Hands‑on experience remediating vulnerabilities in enterprise environments.
  • Experience working with vulnerability management or endpoint security platforms such as CrowdStrike Falcon.
  • Strong knowledge of Windows 10/11 and Windows Server environments.
  • Experience with Microsoft Intune or comparable endpoint management platforms.
  • Experience deploying operating system and third‑party application patches.
  • Working knowledge of Microsoft Entra ID and enterprise endpoint management.
  • Understanding of:
Understanding of:
  • CVE and CVSS
  • Vulnerability severity and risk prioritisation
  • Patch management
  • Zero‑day and actively exploited vulnerabilities
  • Compensating controls
  • Risk acceptance and vulnerability exceptions
  • Strong troubleshooting and root‑cause‑analysis skills.
  • Ability to manage multiple remediation efforts while meeting established OLAs.
Preferred Qualifications
  • Experience with CrowdStrike Falcon Exposure Management / Spotlight.
  • Experience with Microsoft Intune Remediations.
  • Experience automating software deployment and vulnerability remediation.
  • Experience with enterprise server patching processes.
  • Familiarity with vulnerability and security frameworks such as NIST, CIS Controls and CISA Known Exploited Vulnerabilities (KEV).
  • Experience working within an ITIL‑based IT Service Management environment.
  • Experience integrating vulnerability remediation with an ITSM platform.
  • Security certifications such as Security+, CySA+, SSCP, GSEC or equivalent are preferred but not required.
The successful candidate should demonstrate:
  • Ownership – Takes responsibility for vulnerabilities through verified closure rather than simply identifying or assigning issues.
  • Technical Problem Solving – Can determine why a vulnerability exists and identify the most effective remediation.
  • Automation Mindset – Looks for opportunities to remediate hundreds of systems rather than addressing devices individually.
  • Risk Awareness – Understands that vulnerability severity alone does not determine business risk.
  • Urgency – Recognises when active exploitation or critical exposure requires accelerated remediation.
  • Collaboration – Works effectively across Cybersecurity, Service Desk, Infrastructure, Endpoint Engineering and application teams.
  • Continuous Improvement – Identifies systemic improvements that prevent vulnerabilities from repeatedly returning.
Measures of Success

Performance for this position will be measured primarily by risk reduction and remediation effectiveness, including:

  • Percentage of Critical and High vulnerabilities remediated within OLA
  • Reduction in vulnerability backlog
  • Reduction in vulnerabilities exceeding OLA
  • Mean Time to Remediate (MTTR)
  • First‑attempt remediation success rate
  • Percentage of remediation activities automated
  • Accuracy and completeness of remediation documentation
Primary Objective

Drive measurable reduction of cybersecurity risk by ensuring workstation and server vulnerabilities are prioritised, remediated, validated and closed within established OLAs.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Corporate Vice President - Manager of Enterprise Vulnerability & Remediation
Corporate Vice President - Manager of Enterprise Vulnerability & Remediation

New York Life • New York (NY)

On-site
USD 147,500 - 211,000
Network Vulnerability Management Lead
Network Vulnerability Management Lead

CACI Ltd • New York (NY)

Hybrid
USD 120,000 - 170,000
Vulnerability Management Engineer
Vulnerability Management Engineer

WideNet Consulting Group • Seattle (WA)

Hybrid
USD 103,000 - 117,000
Vulnerability Management Engineer
Vulnerability Management Engineer

Jobtailor • Washington

On-site
USD 110,000 - 150,000
Endpoint Vulnerability Remediation Expert
Endpoint Vulnerability Remediation Expert

Tier4 Group • Washington

On-site
USD 110,000 - 140,000
Senior Cybersecurity Patch & Endpoint Management Engineer
Senior Cybersecurity Patch & Endpoint Management Engineer

Tier4 Group • Atlanta (GA)

On-site
USD 120,000 - 180,000
Senior Security Manager - Vulnerability Management
Senior Security Manager - Vulnerability Management

Alter Domus • Chicago (IL)

On-site
USD 140,000 - 190,000
Endpoint Management & Remediation Engineer
Endpoint Management & Remediation Engineer

Veriipro • Washington

Hybrid
USD 110,000 - 140,000
Infrastructure Vulnerability Management Lead
Infrastructure Vulnerability Management Lead

VOLTO Consulting • Dallas (TX)

On-site
USD 90,000 - 130,000
Vulnerability Management Engineer
Vulnerability Management Engineer

Jobtailor • Philadelphia

On-site
USD 100,000 - 140,000