Vulnerability Management Security Analyst
University of Notre Dame · Notre Dame, IN · 1 mo ago
On-siteInformation TechnologyFull-time
Job Description
At the University of Notre Dame, protecting our digital environment and safeguarding our community's data is vital to ensuring the University remains a force for good in the world. To that end, the Office of Information Technology (OIT) is seeking a collaborative and analytical Vulnerability Management Security Analyst to join our information security team.
What You'll Do
- Support the vulnerability management lifecycle through routine scanning, analysis, and validation of security findings.
- Prioritize vulnerabilities based on exploitability, exposure, asset criticality, and data sensitivity.
- Partner with system owners and distributed IT units to coordinate and track remediation progress.
- Monitor, triage, and escalate security events across SIEM, EDR, email, and cloud platforms.
- Aid in incident response by gathering evidence, documenting timelines, and recommending containment.
- Maintain and tune security tools, dashboards, and automated ticketing workflows.
- Contribute to broader security initiatives such as cloud security, identity protection, and risk reviews.
Qualifications
- Minimum Qualifications: Bachelor’s degree in Computer Science, Information Technology, Information Security, or a related field, OR an equivalent combination of education and professional experience.
- Working knowledge of cybersecurity operations, vulnerability management, incident response, security monitoring, enterprise technology, and IT risk management principles.
- Knowledge of vulnerability management practices, including scanning, validation, risk-based prioritization, remediation tracking, exceptions, compensating controls, and remediation verification.
- Strong analytical, problem-solving, documentation, communication, security administration, and stakeholder coordination skills.
- Ability to work in the United States, now or in the future, without visa sponsorship.
Preferred Qualifications
- Experience in higher education or another complex, decentralized organization.
- Familiarity with cybersecurity frameworks and standards such as NIST CSF, CIS Controls, ISO 27001, EDUCAUSE guidance, or MITRE ATT&CK.
- Experience with security operations, vulnerability management, ticketing, or endpoint platforms such as CrowdStrike, ServiceNow, Tenable, Qualys, Rapid7, Microsoft Defender Vulnerability Management, or similar tools.
- Experience supporting vulnerability remediation, phishing investigations, account compromise response, endpoint investigations, cloud security reviews, or security tool administration.
- Experience with scripting, automation, APIs, dashboarding, or data analysis using Python, PowerShell, Bash, SQL, Excel, or similar technologies.
- Relevant certifications such as Security+, CySA+, GSEC, GCIH, GCIA, GMON, SSCP, CISSP, or similar credentials.
Additional Information
Please include a cover letter for full consideration of your application. Salary: up to $95K, commensurate with experience
Deadline to apply (subject to change): Thursday, August 6th, 2026
This position maintains a Hybrid work arrangement (1-2 days remote based on operational needs and team expectations.)