Information Security Analyst [Vulnerability Management]
MillenniumSoft Inc · San Diego, CA · 4 wk ago
Information TechnologyFull-time
Location: San Diego, CA or Franklin Lakes, NJ (Remote OK)
Duration: 12+ months, 40 hours/week (8am–5pm), W2 contract (US Citizens or Green Card holders only)
About the Role
The Information Security Analyst will support the Threat & Vulnerability team within Security Operations, focusing on the identification and proactive mitigation of cyber threats. This role involves risk prioritization, threat assessment, and cross-functional collaboration to address enterprise, manufacturing, and product risks. You will provide fact-based reports to various organizational levels in a fast-paced environment and set your own work direction.
Responsibilities
- Report and communicate vulnerabilities to determine objectives, scope, analysis, and response actions.
- Partner with stakeholders to document the lifecycle of vulnerabilities and recommend mitigation strategies.
- Collaborate on patch validation, remediation planning, and compensating controls for open vulnerabilities.
- Monitor, track, respond, and report on security requirements, driving timely remediation with responsible parties.
- Analyze cyber threats and process tasks to mitigate risk, including reviewing intelligence feeds and applying technical controls.
- Recognize and analyze emerging threats specific to the organization.
- Provide written reports on findings, emphasizing business impact and potential risks.
- Support risk reporting and escalation to cross-functional teams cooperatively.
- Communicate incidents and vulnerabilities to stakeholders following internal policies and ensure remediation follow-up.
- Maintain documentation for internal processes and procedures.
- Participate in after-hours incidents when required.
- Assist with additional projects as needed.
Requirements
- Bachelor’s degree (Computer Science or technical discipline preferred).
- Minimum of 2 years of experience in incident response, monitoring/detection, vulnerability management, or threat intelligence.
- Strong communication and project management skills.
- Working knowledge of crisis management, incident response, NIST cybersecurity standards, and FDA cybersecurity guidance.
- Experience with intrusion detection systems and identifying host/network-based intrusions.
- Detail-oriented with the ability to assess documents for accuracy and consistency.
- Strong interpersonal skills and ability to influence others effectively.
- Experience with healthcare vulnerability scoring and threat modeling (preferred).
- Familiarity with intelligence tools and applications.
Skills
- Vulnerability Management
- Threat Intelligence
- Security Operations
- Incident Response
- Risk Prioritization
- Cross-functional Collaboration
- Analytical and Reporting Skills
Preferred Qualifications
- Certifications: CERT-Certified Computer Security Incident Handler, CISSP, or HCISSP.
- In-depth knowledge of Windows, IoS, and Linux operating systems.
Physical Demands & Work Environment
- Use of computer and phone.
- Ability to travel globally.
- Office and remote work environments.