Threat & Vulnerability Management Analyst
Harris County · Houston, TX · 6 days ago
Business DevelopmentFull-time
Job Responsibilities
- Conduct continuous vulnerability scanning of servers, workstations, network devices, cloud resources, and applications to identify security weaknesses.
- Analyze and prioritize vulnerabilities based on risk, exploitability, asset criticality, CVSS scores, and threat intelligence.
- Cookordination remediation efforts with infrastructure, application, cloud, and endpoint teams to ensure vulnerabilities are addressed within established service-level objectives (SLOs).
- Validate remediation activities by performing research and verifying that vulnerabilities have been successfully mitigated or remediated.
- Monitor threat intelligence feeds, CISA advisories, vendor security bulletins, and zero-day vulnerabilities to assess organizational exposure.
- Develop and maintain vulnerability management dashboards, metrics, and executive reports that track remediation progress, risk trends, compliance, and key performance indicators.
- Investigate Security Operations Center (SOC) alerts to validate potential threats, determine scope and impact, and identify indicators of compromise (IOCs).
- Investigate security events and anomalies to identify root causes, affected assets, attack vectors, and recommended remediation actions.
- Support incident response by triaging SOC alerts, collecting evidence, documenting findings, and escalating confirmed security incidents in accordance with established procedures.
- Correlate SOC alerts with vulnerability and asset data to determine whether identified security weaknesses contributed to the observed activity and recommend mitigation measures.
- Maintain and optimize Threat and Vulnerability Management tools (e.g., Microsoft Defender Vulnerability Management, Rapid7), including scan configurations, asset inventories, and reporting.
Requirements
- Education: High School Diploma or GED.
- Experience: 2–5 years of experience in IT, cybersecurity or systems analysis.
- Knowledge, Skills, And Abilities: Proficiency in using SIEM tools, firewalls, intrusion detection/prevention systems, and vulnerability scanners; familiarity with operating systems (Windows, Linux) and networking protocols; understanding of regulatory frameworks and compliance requirements; strong analytical, communication, and documentation skills.