Vulnerability & Patch Management Analyst

QUANTEAM - North America (RAINBOW PARTNERS Group)

New York (NY)

On-site

USD 85,000 - 115,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

QUANTEAM - North America (RAINBOW PARTNERS Group) is seeking a Vulnerability & Patch Management Analyst to join their New York team. The successful candidate will manage the end-to-end VPM program, working closely with network teams and IT stakeholders in a global financial institution.

This role requires hands-on experience in vulnerability management and strong skills in data analysis and reporting. Responsibilities include driving lifecycle management, producing insightful reports, and collaborating with various teams to ensure compliance.

Qualifications

  • Hands-on experience in vulnerability and patch management roles.
  • Knowledge of POAM management in a regulated environment.
  • Experience with SIEM platforms for security event analysis.

Responsibilities

  • Drive the full vulnerability and patch management lifecycle across infrastructure.
  • Produce Excel-based data analysis and visualizations for monitoring.
  • Collaborate with teams for timely patch acquisition and deployment.

Skills

Vulnerability management
Patch management
Data analysis and reporting
Communication skills
Knowledge of security and audit frameworks

Tools

Qualys
Splunk
Excel

Job description

As the founding entity of RAINBOW PARTNERS, Quanteam is a consulting firm specialized in Banking, Finance, and Financial Services. Through our core human values – proximity, teamwork, diversity, excellence – our 1000 expert consultants, hailing from 35 different nationalities, collaborate across 13 international offices: Paris, Lyon, New York, Montreal, London, Brussels, Luxembourg, Geneva, Lisbon, Porto, Casablanca, Madrid and Singapore.

Context

We are seeking an experienced Vulnerability & Patch Management Analyst to join our team in New York. Our client, a global financial institution with operations across the Americas and Europe, is seeking a Vulnerability & Patch Management Analyst to own and drive its end-to-end VPM program across the Americas IT landscape. The successful candidate will sit within the Patch Management workstream and collaborate closely with network teams, IT stakeholders, the Second Line of Defense, and Head Office to strengthen the firm’s security posture in a fast‑moving, regulated environment.

Responsibilities
Vulnerability & Patch Management
  • Drive the full VPM lifecycle—identification, risk‑based prioritization, and remediation across all infrastructure, systems, applications, and SDLC.
  • Assess vulnerability impact and risk levels across asset classes to inform strategic remediation decisions.
  • Manage SLA compliance for patch deployments; develop and execute follow‑up plans for breaches.
  • Coordinate with IT and network teams across the Americas to ensure timely vendor patch acquisition and deployment, including end‑to‑end remediation follow‑up.
  • Scripting and automation via Qualys Groovy scripts and VMDR tagging; dashboard querying using Qualys and Splunk SPL.
  • Participate in vulnerability assessments and track software/system update cycles.
Reporting & Analytics
  • Produce Excel‑based data analysis and visualizations (pivot tables, charts, dashboards) within the Patch Management workstream.
  • Design and maintain KPIs and KRIs to measure program effectiveness; present findings to leadership and key stakeholders.
  • Deliver PowerPoint presentations on vulnerability posture, remediation progress, and risk metrics to non‑technical leadership.
  • Build and maintain security dashboards in Qualys and Splunk for real‑time visibility into the firm’s vulnerability landscape.
  • Deliver consistent, high‑quality reporting to senior stakeholders across IT, Compliance, and the Second Line of Defense.
Governance & Compliance
  • Collaborate with the Second Line of Defense and external auditors; maintain POAM (Plans of Action & Milestones) documentation.
  • Design, enhance, and document VPM procedures, processes, and run books.
  • Provide backup support for cybersecurity incidents, projects, and audit remediation as needed.
  • Stay current on industry threats, emerging vulnerabilities, and evolving best practices.
Profile
  • Proven hands‑on experience in vulnerability management, patch management, or a closely related security role.
  • Working knowledge of POAM (Plans of Action & Milestones) management in a regulated environment.
  • Familiarity with vulnerability scanning tools (e.g., Qualys, Tenable/Nessus, Rapid7).
  • Experience with SIEM platforms (e.g., Splunk, Microsoft Sentinel) for security event analysis.
  • Strong reporting and data analysis skills—PowerBI and Advanced Excel/PowerQuery required.
  • Knowledge of security and IT audit frameworks: NIST, FFIEC handbooks, and related standards.
  • Excellent communication skills with the ability to present risk posture clearly to non‑technical leadership.
  • Ability to work cross‑functionally with IT teams, compliance, and audit functions.
  • Financial services or banking experience strongly preferred.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vulnerability & Patch Management Analyst - Risk & Remediation
Vulnerability & Patch Management Analyst - Risk & Remediation

QUANTEAM - North America (RAINBOW PARTNERS Group) • New York (NY)

On-site
USD 85,000 - 115,000
Patching Engineer
Patching Engineer

GDT - General Datatech • Fort Worth (TX)

On-site
USD 80,000 - 110,000
Vulnerability Management and Security Engineering
Vulnerability Management and Security Engineering

RennerBrown • New York (NY)

On-site
USD 140,000 - 190,000
Vulnerability Management Manager
Vulnerability Management Manager

Considine Search • New York (NY)

On-site
USD 200,000 - 215,000
Principal Vulnerability Management Consultant
Principal Vulnerability Management Consultant

The Judge Group • Chicago (IL)

Hybrid
USD 130,000 - 170,000
Manager, Vulnerability Management
Manager, Vulnerability Management

Optimum • Norwalk (CT)

On-site
USD 133,000 - 220,000
Senior Vulnerability Analyst
Senior Vulnerability Analyst

PRI Global • O’Fallon (MO)

On-site
USD 110,000 - 160,000
Vulnerability Engineer
Vulnerability Engineer

CBTS • United States

On-site
USD 80,000 - 85,000
Vulnerability Management SME/Product Analyst
Vulnerability Management SME/Product Analyst

Capgemini • New York (NY)

Hybrid
USD 140,000 - 180,000
Healthcare
401k
Paid time off
Security Operations Vice President - Vulnerability Management
Security Operations Vice President - Vulnerability Management

JPMorgan Chase & Co. • Plano (TX)

On-site
USD 90,000 - 110,000